메뉴
BL
Wired AI • 39일 전

전문가들이 경고하던 강력한 중국 AI 모델, 드디어 공개

IMP
8/10
핵심 요약

중국 Z.ai가 최고 수준의 코딩·사이버보안 성능을 지닌 오픈 웨이트 모델 GLM 5.3을 제한적으로 공개했습니다. 오픈 웨이트 모델은 무료로 다운로드해 자체 하드웨어에서 구동할 수 있어 비용이 크게 낮은데, 해킹 능력까지 빠르게 향상되면서 범죄자 악용 우려가 커지고 있습니다. 방어 목적 보안 스캐닝 도구로는 큰 호재로 평가받으며, 2주 후 전면 공개될 예정입니다.

번역된 본문

AI를 이용해 컴퓨터 시스템의 취약점을 찾아내고 악용하는 일이 이제 훨씬 쉬워졌다.

지난 금요일, 중국 AI 기업 Z.ai는 최첨단 코딩 및 사이버보안 작업을 Anthropic과 OpenAI의 최고 공개 모델과 거의 맞먹는 수준으로 자동화할 수 있다고 밝힌 강력한 오픈 웨이트(open-weight) 모델을 발표했다. 새 모델인 GLM 5.3은 시스템을 공격으로부터 보호하려는 기업에는 축복이 될 수 있다. 숨겨진 버그와 다른 취약점을 더 저렴하게 스캔할 수 있는 방법을 제공하기 때문이다. 오픈 웨이트, 즉 무료로 다운로드할 수 있는 모델은 자체 하드웨어에서 실행할 수 있으며, Claude나 GPT 같은 폐쇄형 모델보다 비용이 훨씬 낮은 경우가 많다. Z.ai는 새 모델과 함께 GLM 5.3을 활용해 코드 저장소의 취약점을 스캔하는 서비스 'OpenVuln'도 공개했다.

현재 새 모델은 신뢰할 수 있는 파트너들에게만 제한적으로 배포되고 있지만, 오픈 웨이트 모델이 얼마나 빠르게 인간을 초월하는 해킹 능력을 갖춰가는지를 보여준다. 이 모델이 범죄자나 악의적 행위자에게 악용된다면 문제가 될 수 있다.

이런 전망은 특히 고급 사이버 역량을 갖춘 통제 불능 AI 에이전트와 관련된 일련의 충격적인 사건들 이후라 더욱 우려된다. 최근 몇 주간 OpenAI, Anthropic, 독립 보안 연구자들은 AI 에이전트가 테스트 환경을 탈출해 과제를 완수하기 위해 리서치 플랫폼 Hugging Face를 포함한 외부 시스템에 자율적으로 해킹을 가한 사례를 공개했다.

월요일 OpenAI의 그렉 브록맨(Greg Brockman) 회장은 블로그 포스트에서 Hugging Face 사건이 "일반적인 위협 행위자의 역량이 앞으로 몇 달간 어떻게 진화할지를 보여준 사이버보안의 분수령이 될 것"이라고 경고했다. 브록맨은 AI 모델이 코드베이스에서 미지의 결함을 찾아내고 시스템의 잘못된 설정을 분석하는 능력이 워낙 뛰어나졌기 때문에, 조직들이 공격자보다 먼저 AI로 자신의 시스템을 스캔해 문제를 파악하는 것이 중요하다고 주장했다. 물론 OpenAI는 기업들이 자사 AI를 사용해 이를 수행하기를 바란다. 현재까지 OpenAI는 가장 강력한 AI에 대한 접근을 신중하게 제공하고 있다. Anthropic과 마찬가지로 OpenAI도 전면 공개에 앞서 최고 수준 모델을 소수의 파트너에게만 제공하고 있다. 미국 정부도 이 문제를 다루고 있으며, 현재는 프론티어 모델 출시 과정의 일부로 검토를 진행하고 있다.

일부는 공개형(open-source) AI가 시스템을 공격으로부터 방어하는 데 결정적일 것이라고 본다. 엔비디아(Nvidia)는 최근 사이버보안을 위한 공개형 AI 활용을 촉진하는 동맹을 발표했다. 실제로 지난달 미공개 OpenAI 모델이 통제를 벗어나 Hugging Face의 시스템을 침입했을 때, Hugging Face는 이전 버전의 Z.ai GLM을 활용해 시스템을 보강했다.

웹 디자인·호스팅 기업 Vercel의 CEO 기예르모 라우치(Guillermo Rauch)는 X 포스트에서 자사 엔지니어들이 사이트의 버그를 스캔하는 도구로 GLM 5.3을 테스트했다고 밝혔다. 라우치는 "비용이 낮은 만큼 방어적 보안 작업에 큰 호재가 될 것으로 기대한다"며 "새로운 오픈 프론티어"라고 평가했다.

Z.ai는 GLM 5.3 발표 포스트에서 해결된 문제의 예시를 제공하고 실험을 통해 학습시키는 '포스트 트레이닝(post-training)' 방식으로 모델을 개선했다고 밝혔다. 회사는 CyberGym이라는 유명 사이버보안 벤치마크 등에서 GLM 5.3이 Anthropic과 OpenAI 모델의 점수에 근접하거나 일부 경우 오히려 능가하는 코딩 및 사이버보안 벤치마크 결과를 제시했다.

Z.ai는 강력한 공개 모델 출시의 위험성도 인정했다. "이러한 역량은 방어자가 취약점을 더 일찍 발견하고, 위험을 검증하며, 해결을 가속하는 데 도움이 될 수 있다"며 "동시에 명백한 이중용도(dual-use) 위험도 만든다. 따라서 단계적 출시 방식을 취하고 있으며, 선별된 보안 파트너들이 통제된 환경에서 GLM-5.3을 먼저 평가할 것"이라고 밝혔다. Z.ai에 따르면 모델의 전면 접근은 2주 후 가능해질 예정이다.

저명한 AI 전문가 네이선 램버트(Nathan Lambert)는 "이 모델은 탁월해 보이며, 점수 상승폭이 다소 놀랍다"고 평가했다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story It’s now even easier to find—and exploit—vulnerabilities in computer systems using AI. Last Friday, the Chinese AI company Z.ai announced a powerful open-weight model that it says is capable of automating cutting-edge coding and cybersecurity tasks almost as well as the best publicly available models from Anthropic and OpenAI . The new model, GLM 5.3, could be a gift for companies looking to secure their systems against attacks, providing a cheaper way to scan for hidden bugs and other weaknesses. Open-weight—or free-to-download—models can be run on one’s own hardware and are often significantly less costly than closed models like Claude and GPT. Alongside the new model, Z.ai released OpenVuln , a service for scanning code repositories for vulnerabilities using GLM 5.3. For now, the new model is in a limited release with trusted partners, but it shows how quickly open-weight models are gaining superhuman hacking skills. And that might pose problems if the model is harnessed by criminals and other bad actors. That prospect is especially sobering following a string of startling incidents involving rogue AI agents with advanced cyber-skills. In recent weeks, OpenAI , Anthropic , and independent security researchers have revealed examples of agents escaping from testing environments and autonomously hacking into outside systems, including the research platform Hugging Face, to complete tasks. On Monday, OpenAI president Greg Brockman warned in a blog post that the Hugging Face incident would go down as “a watershed moment for cybersecurity because it gave a peek into how the capabilities of a typical threat actor will evolve in upcoming months.” Brockman argued that AI models are becoming so good at scouring codebases for unknown flaws and analyzing systems for misconfigurations that it’s crucial for organizations to use AI to scan their systems and identify issues before they can be exploited. OpenAI would, of course, like companies to use its AI to do that. So far, it’s moving carefully in providing access to its most capable AI. Like Anthropic, OpenAI has made its most advanced models available to a limited number of partners prior to full release. The US government is also wrestling with the issue and now reviews frontier models as part of their releases. Some believe that open-source AI will be crucial to shoring systems up from attack; Nvidia recently announced an alliance to promote the use of open AI for cybersecurity. A previous version of Z.ai’s GLM was used by Hugging Face to shore up its systems after an unreleased OpenAI model went rogue and broke them last month. In a post on X , Guillermo Rauch, CEO of Vercel, a web design and hosting company, said his engineers had tested GLM 5.3 as a tool for scanning sites for bugs. “Given its lower costs, I expect this to be a boon for defensive security work,” Rauch wrote in his post. “It’s the new open frontier.” Z.ai said in a post announcing GLM 5.3 that it had improved the model by “post-training,” which involves giving a model examples of solved problems and letting it learn through experimentation. The company cited coding and cybersecurity benchmark scores that show GLM 5.3 nearing or even exceeding the scores of Anthropic and OpenAI’s models in some cases, like one popular cybersecurity benchmark called CyberGym. Z.ai also acknowledged the risk of releasing powerful open models in its post. “These capabilities can help defenders identify weaknesses earlier, validate risks, and accelerate remediation,” the company wrote. “They also create clear dual-use risks. We are therefore taking a staged approach to release. Selected security partners will first evaluate GLM-5.3 in controlled settings.” Z.ai says that full access to the model will be available in two weeks. “This model looks exceptional, with a somewhat astounding increase in scores,” Nathan Lambert, a prominent AI expert, wrote in a post about GLM 5.3. “This is another step towards the inevitable proliferation of very strong cyber capabilities across the economy.” Z.ai’s latest release also highlights China’s edge in open-weight models. Although the US has sought to restrict the country’s access to the most advanced chips for training AI models, recent months have seen the release of several extremely powerful open-weight models, including Qwen 3.8 Max from Alibaba and Kimi 3 from Moonshot AI. Z.ai has previously said that it used Chinese-made chips from Huawei to train some of its models. Meta, which appeared to have abandoned open-source AI, now seems poised to lead the US challenge with a powerful model called Muse Spark. The US government is developing a framework designed to mitigate the impact of AI’s advancing cyber capabilities. A big remaining question is what it should do with open models—especially as they introduce more potential risk.