메뉴
BL
TechCrunch AI 6일 전

미국 오픈소스 AI 연구소 "중국 모델, 본질적으로 위험하지 않아"

IMP
7/10
핵심 요약

중국산 오픈 웨이트 AI 모델이 성능과 인기를 얻으며 미국 내에서 금지 움직임이 나오고 있지만, 미국 오픈소스 AI 스타업인 Arcee의 최고기술경영자(CTO)는 중국 모델이 다른 오픈소스 소프트웨어보다 더 위험하지 않다고 반박했습니다. 기업이 자체 데이터센터에서 모델을 운영할 경우 외부에서 접근할 방법이 없으며, 보안 검수를 거치면 백도어나 악성 코드가 실행될 가능성도 극히 희박하다고 설명했습니다. 오히려 미국은 중국 모델을 배척할 것이 아니라 훌륭한 오픈소스 생태계를 육성하고 더 나은 모델을 개발하는 방식으로 경쟁해야 한다고 강조했습니다.

번역된 본문

중국의 오픈 웨이트(Open-weight) AI 모델들이 성능과 인기를 얻으면서 이에 대해 어떤 조치를 취해야 하는지에 대한 논쟁이 다시 한번 과열 양상을 보이고 있습니다. 트럼프 행정부가 이를 금지하려 할 수도 있다는 이야기가 나돌고 있습니다(비록 아직은 실행에 옮기지는 않았지만). 동시에, 자체 폐쇄형 모델을 만드는 기업들, 특히 OpenAI와 Anthropic은 이에 대해 점점 더 우려를 나타내고 있습니다. Moonshot AI의 Kimi K3나 Alibaba의 Qwen과 같은 오픈 웨이트 모델은 미국 대형 연구소들의 폐쇄형 모델에 비해 극히 일부의 토큰 비용만으로 추론(Inference) 기능을 제공합니다. 두려운 것은 이 모델들이 일종의 위협이 될 수 있다는 점입니다. 물론 이들은 대형 폐쇄형 AI 연구소들의 수익률을 위협하고 있습니다. 하지만 자체 데이터센터에서 이 모델을 운영하는 기업들이 중국 해커들의 침투 경로가 될 수 있다는 두려움에 굴복해야 할까요?

미국 기업들에 중국 모델의 대안이 될 자체 오픈 모델을 구축하고 있는 Arcee의 최고기술책임자(CTO)인 Lucas Atkins는 "아니다"라고 말합니다. 만약 어떤 스타트업이 중국 모델 금지 조치의 혜택을 입는다면, Arcee일 것입니다. 그러나 Atkins는 중국의 오픈 모델이 기업이 사용할 수 있는 다른 어떤 오픈소스 소프트웨어보다 더 위험하지 않다고 말합니다. 그는 실제로 이 모델들이 자신의 회사에게도 이점을 제공한다고 덧붙입니다.

그는 "많은 사람들이 이를 중국 소프트웨어 프로그램과 비슷하다고 봅니다. 마치 악의적인 행위자가 단순히 명령을 내릴 수 있는 특정 의도(x, y, z)로 코딩된 것처럼 말이죠"라고 말했습니다. 그는 이어서 "그것은 근본적으로 이 모델들이 훈련되는 방식이 아닙니다. Arcee나 Alibaba가 모델을 만들어 누군가 자신의 환경에서 실행하게 하더라도, 당사가 그것에 전혀 접근할 수 있는 방법은 없습니다"라고 설명했습니다.

이 모델들 대부분은 이른바 '오픈 웨이트'이며 엄밀히 말해 완전한 오픈소스 소프트웨어는 아니지만, Hugging Face와 같은 오픈소스 사이트에서 다운로드한 소스 코드(실제로 서버에서 실행되는 부분)는 대부분 비슷하게 공개되어 검토할 수 있습니다. (사용할 수 없는 부분은 모델을 훈련하는 데 사용된 방법과 데이터입니다.) 대규모 조직은 모든 모델 코어를 자체 보안 테스트 및 검사 프로세스에 통과시켜야 하며, 특정 용도에 맞게 모델을 사후 훈련(Post-train)시키고 편향성, 유해성, 환각 현상(Hallucination), 특정 주제에 대한 민감도와 같은 영역을 검토할 것입니다. 따라서 사용자가 프롬프트를 보내기 전에 기업은 모델을 다루고, 최적화하고, 이해하게 됩니다.

코딩에 사용되는 모델이 작성하는 코드에 악의적인 백도어를 심어놓을 수도 있을까요? 다시 말하지만, 이론적으로는 가능하지만 이를 달성하기 위해서는 아주 복잡하고 고도의 기교가 필요합니다. 모델 훈련에 매진하고 있는 Atkins는 "충분히 정교한 행위자가 어떤 상황에서도 완벽한 코딩 모델을 훈련시킬 수 없을 이유가 없지만, 특정 유형의 코드베이스가 제시되면... 숨겨진 훈련이 작동하도록 만들 수 있을 것입니다"라고 추측했습니다. 하지만 그는 "내가 어떻게 그것을 해낼 수 있을지 모르겠다"고 덧붙였습니다. 대형 언어 모델(LLM)은 본질적으로 창의적이기 때문에, 사전에 계획된 완벽한 맥락과 프롬프트에 대해 최신 모델이 악성코드를 내뱉도록 할 확률은 매우 낮습니다. 기업이 그 코드를 실제로 사용할 확률은 더더욱 희박합니다.

미래에 그런 일이 일어날 수 있을까요? 그건 아무도 모릅니다. 하지만 기업들은 자체 AI 앱을 모델에 구애받지 않고(Model-agnostic) 여러 모델을 사용하도록 구축하고 있습니다. 따라서 오늘날 중국 모델이 가격 대비 최고의 성능을 가지고 있더라도, 기업들이 영원히 그것만 사용해야 하는 상황에 갇히지는 않을 것입니다.

Atkins는 "중국 모델을 금지하는 방법에 대한 논의 대신, 미국에서 어떻게 좋고 개방적인 생태계를 조성할 수 있는지에 대한 논의가 이루어져야 한다고 생각합니다"라고 말합니다. Arcee 역시 중국 모델에서 이점을 얻고 있습니다. 이 스타트업은 모델이 개방되어 있기 때문에 "그 모델들이 좋은 성능을 보여줌으로써 혜택을 얻습니다. 우리는 그들이 무엇을 했는지 배울 수 있습니다. 우리는 그 위에 구축할 수 있습니다. 그리고 그들은 우리가 하는 일을 배울 수 있습니다"라고 그는 말했습니다. 그는 "우리는 그 모델을 구축하는 사람들, 개별 연구원들에게 엄청난 존경을 보냅니다"라고 덧붙였습니다.

결국 중국 모델과 경쟁하는 방법은 "더 나은 모델을 출시하는 것"이라고 Atkins는 말합니다. "우리는 그들에게 더 나은 모델을 제공해야 합니다."

원문 보기
원문 보기 (영어)
As Chinese open-weight AI models grow in capability and popularity , arguments about what should be done about them have once again reached a fever pitch. There's talk that the Trump administration might try to ban them (though it hasn't yet acted on the idea). Meanwhile, proprietary model makers, particularly OpenAI and Anthropic, appear increasingly concerned about them. Open-weight models such as Moonshot AI's Kimi K3 or Alibaba's Qwen offer inference at a fraction of the token cost of closed-source models from these large U.S. labs. The fear is that they also pose some sort of threat. Certainly, they threaten the profit margins of the large proprietary AI labs. But should enterprises running these models in their own data centers succumb to the fear that they could be a vector for Chinese hackers? No, says Lucas Atkins, the CTO of Arcee , which is building open models to give U.S. companies a homegrown alternative to Chinese models. If any startup would benefit from a ban on Chinese models, Arcee would. But Atkins says China's open models are no more dangerous than any other open-source software a company may use. In fact, he says, they even offer benefits even to his own company. "A lot of people view this as similar to a Chinese software program. Like, it was coded with these x, y, z intentions" that a bad actor could simply command, he said. "That is fundamentally not how these models are trained. There is really not any way for an Arcee, or an Alibaba, to make a model, have someone run it in their own environment and for us have any access to it whatsoever," he explained. While most of these models are what's known as "open weight," and are not really fully open-source software, the source code (the part that will actually run on servers), if it is downloaded from open-source sites like Hugging Face, is similarly largely visible and reviewable. (What isn't available is the methods and data used to train the models.) Large organizations should put any model core through their security testing and inspection processes, and they will also often post-train the models for their specific uses, and can examine areas like bias, toxicity, hallucinations, sensitivity to certain topics. So they work with, optimize, and understand the models before people start sending them prompts. Could a model that is used for coding somehow throw malicious backdoors into the code it writes? Again, while that's theoretically possible, it would require acrobatic feats to accomplish. "There's no reason that a sophisticated enough actor couldn't train a model to be a completely amazing coding model in every circumstance, but when presented with a certain type of code base … some hidden training would kick in," Atkins, who spends his days training models, postulated. But he adds: "I don't know how you would do this." Because large language models are by nature creative, the odds are slim of getting a contemporary model to spit out malware in response to a preplanned perfect storm of context and prompt. Even slimmer are the chances that any enterprise would then use that code. Could it happen in the future? That's anyone's guess. But enterprises are also building their AI apps to be model-agnostic and to use multiple models. So even if Chinese models are the best for the price today, enterprises won't be locked into using them forever. "I think instead of the conversation being about how to ban Chinese models, it should be about how do we foster a good, open ecosystem here in the U.S.," Atkins says. Arcee also gains advantages from Chinese models. Because they are open, the startup "benefits from those models being good because we can learn what they did. We can build on top of them. Then they can learn what we do," he says. "We have tremendous respect for the people building those models, the individual researchers." Ultimately, the way to compete with Chinese models "is to release a model that is better," says Atkins. "We need to give them something to talk about." Topics AI , chinese ai , Startups , TC When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Julie Bort Venture Editor Julie Bort is the Startups/Venture Desk editor for TechCrunch. You can contact or verify outreach from Julie by emailing julie.bort@techcrunch.com or via @Julie188 on X. View Bio October 13 - 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y! REGISTER NOW Most Popular Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents Amanda Silberling Light made a flip phone — it's colorful and it's cheap Amanda Silberling AI music generator Suno breach affects 55M users, per Have I Been Pwned Zack Whittaker Anthropic's landmark $1.5B copyright settlement is approved Kirsten Korosec Google is working on a new AI chip designed to make Gemini more efficient Lucas Ropek Judge pauses $110B Paramount-Warner Bros. merger Aisha Malik Coca-Cola suspended production at its Fairlife dairy after a ransomware attack Zack Whittaker