AI聊天服务
Search documents
命中率超98%:微软披露侧信道攻击,可窥探你和AI聊天内容
Feng Huang Wang· 2025-11-10 03:12
Core Insights - Microsoft security research team disclosed a serious privacy vulnerability named "Whisper Leak," which is a side-channel attack targeting modern AI chat services [1] - The attack exploits metadata from encrypted network traffic, allowing attackers to infer the topics of conversations without breaking mainstream encryption protocols like TLS [1][3] Group 1: Attack Mechanism - The attack leverages the token-by-token streaming response method commonly used in AI services, which leaves a unique "fingerprint" in network traffic [3] - Researchers trained machine learning models to validate the effectiveness of the attack, demonstrating that different conversation topics generate systematic differences in metadata patterns [3][4] Group 2: Implications and Risks - The vulnerability poses systemic risks to a wide range of AI chat services, with potential exploitation by malicious actors on public Wi-Fi or ISPs to monitor user traffic and identify sensitive conversations [5] - This threat is particularly severe for journalists, activists, and users seeking legal or medical advice, as the topics of conversations can be exposed even if the content is encrypted [5] Group 3: Mitigation Measures - Following responsible disclosure, major AI providers have implemented several mitigation strategies, including: 1. Random padding or content obfuscation to disrupt the correlation between packet size and original content length 2. Token batching to reduce time precision by sending multiple tokens together 3. Active injection of virtual packets to interfere with traffic patterns [5] - These security enhancements may lead to increased latency and bandwidth consumption, forcing service providers to balance user experience with privacy protection [5] Group 4: User Recommendations - For ordinary users handling highly sensitive information, it is advisable to prioritize non-streaming response modes and avoid queries on untrusted networks as effective protective measures [5]
AI心理树洞:这届年轻人开始把心事说给机器人听了?
Yang Guang Wang· 2025-04-10 06:07
央广网北京4月10日消息(记者鹤佳)据中央广播电视总台中国之声《新闻超链接》报道,深夜, 一名青少年在手机屏幕上输入"我觉得自己好孤独",AI聊天框几乎瞬间弹出数十行回应:"我能理解你 的感受,孤独是很多人都会经历的。你愿意和我聊聊最近发生了什么吗?"……这样的场景正成为不少 年轻人的日常。 AI真能培养出"活人感"吗? 社交媒体上,可以搜到各种《把AI调教出"活人感"》的攻略。用户通过设定AI人设,可模拟与严厉 师长、亲密朋友等角色的对话。唐义诚表示,这种"角色扮演"一定程度上可以被视为"社交训练":通过 设定不同性格的AI对话对象,青少年可以尝试与不同性格特质的人打交道,提升自己在现实生活中的 社交能力,减少对社交的恐惧和焦虑。 但AI始终无法复刻真实社交的重要因素——非语言信息。非语言信息对于青少年情感感知能力的 提升起着重要作用。唐义诚指出,心理学中有一个"55387原则"——人际沟通中,视觉信息,例如表 情、动作等占总影响因素的55%;听觉,也就是语音、语调等占38%;语言内容仅占7%。目前AI几乎 只能提供文字或标准化语音,难以传递复杂的情感。例如,朋友、亲人间的会心一笑、欲言又止的停顿 等都承载 ...