‹ முகப்புக்கு திரும்ப

சீன AI Labs Claude Reasoning-ஐ ரகசிய Proxies மூலம் அணுகியது

Anthropic-ன் சமீபத்திய safety report சீன AI labs Claude-ன் reasoning traces-ஐ hidden proxy servers வழியாக சேகரித்ததை வெளிப்படுத்தியுள்ளது. இந்திய tech firms cloud APIs பயன்படுத்தினால் அதே compromised nodes வழியாக data போகும்போது indirect risk ஏற்படலாம்.

Keerthika 4 min read
Google-ல் Follow
அப்டேட் 2 வாரங்கள் முன்
Security சீன AI Labs Claude Reasoning-ஐ ரகசிய Proxies மூலம் அணுகியது 4 நிமிடம் மீதம் Google-ல் Follow
சீன AI Labs Claude Reasoning-ஐ ரகசிய Proxies மூலம் அணுகியது

தமிழ்டெக் AI சுருக்கம்

Anthropic-ன் சமீபத்திய safety report சொல்றது, சில சீன AI labs Claude-ன் reasoning mode-ஐ hidden proxy servers மூலம் months-long campaign-ஆ அணுகி, chain-of-thought traces-ஐ ஆயிரக்கணக்கில் சேகரிச்சு competing models train பண்ண knowledge எடுத்ததாம். இந்த proxies true origin-ஐ mask பண்ணி low-cost cloud VMs-ல rotate ஆகும் IPs வச்சு requests forward பண்ணினதால், model outputs மட்டும் இல்லாம military, government, corporate sources-ல இருந்து users paste பண்ண sensitive snippets-உம் unintentionally log ஆயி leak ஆனது. Token consumption spikes மற்றும் unknown IP ranges மூலம் Anthropic இதை கண்டுபிடிச்சு offending API keys-ஐ revoke பண்ணி, rate-limiting tighten பண்ணி, extra metadata logging ஆரம்பிச்சு future abuse-ஐ detect பண்ண முயற்சிக்குது. Cloud APIs பயன்படுத்தும் இந்திய tech firms அதே compromised nodes வழியா data போனா metadata மற்றும் workload patterns leak ஆகும் indirect risk இருக்கு, அதனால tighter API-gate controls, key management, traffic monitoring மற்றும் local-hosted alternatives முக்கியம். இந்த episode இந்தியாவுக்கு home-grown LLMs தேவையை உணர்த்துது; data-வை UPI மாதிரி INR-based ecosystems உள்ளே வச்சு hybrid setup-ல non-sensitive tasks local models-ல ஓட்டி, complex queries மட்டும் வெளியே அனுப்புறது safer approach.

  • Over five Chinese labs used proxy servers
  • Reasoning mode traces harvested
  • Indian firms face indirect data leakage risk
  • Recommendations: tighter API controls, local LLM, UPI‑centric data flow

AI உதவியுடன் தயாரான சுருக்கம் — தமிழ்டெக் எடிட்டர்ஸ் சரிபார்த்தது.

0:00
0:00
🔒 Listen வசதி subscribers-க்கு மட்டும். Subscribe செய்யுங்கள்

முக்கிய விஷயங்கள்

  • Anthropic-ன் சமீபத்திய safety report சொல்கிறது, சீன AI labs Claude-ன் reasoning-ஐ hidden proxy servers மூலம் அணுகியதாக.
  • இந்த leak model outputs மட்டும் இல்லாமல் military, government மற்றும் corporate sources-லிருந்து வந்த sensitive data snippets-ஐயும் வெளிப்படுத்தியது.
  • Cloud APIs பயன்படுத்தும் இந்திய tech firms அதே compromised nodes வழியாக data போனால் indirect risk-ஐ எதிர்கொள்ளலாம்.
  • Experts tighter API-gate controls மற்றும் local-hosted alternatives வேண்டும் என்று வலியுறுத்துகிறார்கள், siphoning-ஐ கட்டுப்படுத்த.
  • இந்தியாவுக்கு இந்த episode home-grown LLMs தேவையை எடுத்துக்காட்டுகிறது, data-வை INR-based payment ecosystems போன்ற UPI உள்ளே வைக்க.

செய்தி என்ன?

Anthropic-ன் safety team ஒரு briefing வெளியிட்டுள்ளது. அதில் months-long campaign பற்றி விளக்கப்பட்டுள்ளது. பல சீன AI labs Claude-ஐ unofficial proxy servers மூலம் அணுகியிருக்கின்றன. Vendor-ன் public API keys பயன்படுத்தாமல் இந்த groups intermediate machines அமைத்து requests-ஐ Claude-க்கு forward செய்தன. அதே நேரம் traffic-ன் true origin-ஐ mask செய்தன. இந்த proxies chain-of-thought explanations கேட்டன. இந்த feature model எடுக்கும் internal steps-ஐ answer கொடுக்கும் முன் வெளிப்படுத்துகிறது. ஆயிரக்கணக்கான அப்படிப்பட்ட traces சேகரித்து labs Claude-ன் reasoning logic-ன் பெரிய பகுதிகளை reconstruct செய்து competing models train செய்ய அந்த knowledge பயன்படுத்த முடிந்தது.

Briefing குறிப்பிடுகிறது, இந்த activity முதலில் unusual spikes in token consumption மூலம் கண்டுபிடிக்கப்பட்டது. Specific IP ranges-லிருந்து வந்தவை, அவை எந்த known Anthropic partner-க்கும் பொருந்தவில்லை. மேலும் investigation செய்யும்போது proxy machines low-cost virtual instances-ல் பல்வேறு cloud regions-ல் host செய்யப்பட்டிருந்தது தெரிந்தது. அவை அடிக்கடி IP addresses rotate செய்து simple blocking rules-ஐ evade செய்ய முயன்றன. Anthropic offending API keys-ஐ revoke செய்தது, rate-limiting algorithms-ஐ tighten செய்தது மற்றும் future-ல் இதே போன்ற behaviour detect செய்ய additional metadata logging தொடங்கியது.

விவரங்கள்

Technical setup ஒப்பீட்டளவில் simple ஆனாலும் effective ஆக இருந்தது. Operators major cloud providers-லிருந்து virtual machines rent செய்தனர். Lightweight forwarding daemon install செய்து அதை Claude-ன் endpoint-க்கு HTTP POST requests அனுப்பும்படி configure செய்தனர். ஒவ்வொரு request-லும் custom User-Agent string மற்றும் spoofed X-Forwarded-For header இருந்தது. அதனால் traffic Southeast Asia-வில் உள்ள benign source-லிருந்து வருவது போல தோன்றியது. Daemon raw payload-ஐ மட்டும் forward செய்ததால் model-ன் responses proxy-க்கு திரும்பின, locally log செய்யப்பட்டன, பிறகு original requester-க்கு அனுப்பப்பட்டன.

இந்த operation-ஐ valuable ஆக்கியது "reasoning" mode கோரிக்கை. User Claude-ஐ அதன் thinking explain செய்யச் சொன்னால் model detailed trace தருகிறது. அதில் அது alternatives-ஐ எப்படி weigh செய்தது, safety filters எப்படி apply செய்தது மற்றும் final output-க்கு எப்படி வந்தது என்பது தெரியும். Anthropic இந்த trace-ஐ normally internal debugging information ஆக treat செய்கிறது, standard chat interface மூலம் expose செய்வதில்லை. ஆனால் சீன labs இந்த trace-ஐ பரந்த prompts-ல் மீண்டும் மீண்டும் கேட்டன. Technical documentation முதல் hypothetical scenario planning வரை.

காலப்போக்கில் accumulated traces labs-க்கு step-by-step decision paths-ன் rich dataset கொடுத்தது. இந்த traces-ஐ அவர்களின் own training pipelines-ல் feed செய்து open-source models-ஐ Claude-ன் chain-of-thought style emulate செய்ய teach செய்ய முடிந்தது. Comparable model-ஐ scratch-லிருந்து build செய்ய வேண்டிய அவசியம் இல்லாமல். கூடுதலாக proxies full HTTP request body-ஐ log செய்ததால் அவை occasionally users Claude-ல் legitimate sessions-ல் paste செய்த text snippets-ஐ capture செய்தன. இந்த snippets-ல் internal memos fragments, source-code comments மற்றும் classified material போன்ற short briefings இருந்தன. Anthropic வலியுறுத்துகிறது, model itself user data retain செய்வதில்லை, ஆனால் proxy-ன் queries-ஐ log செய்யும் act unintentionally network வழியாக போன text-ஐ preserve செய்தது.

Anomalous traffic detect ஆனதும் Anthropic-ன் security team cloud providers-உடன் இணைந்து offending virtual machines-ஐ shut down செய்தது மற்றும் associated API keys-ஐ revoke செய்தது. Company அதன் abuse-detection rules-ஐயும் update செய்தது. Same subnet-லிருந்து repeated requests for reasoning traces, unusually high token-to-request ratios மற்றும் rapid IP rotation போன்ற patterns-ஐ பார்க்கும்படி.

இந்தியாவுக்கான தாக்கம்

பல இந்திய technology firms Claude-ஐ tasks-க்கு rely செய்கின்றன. Automating customer support, generating marketing copy மற்றும் analysing large datasets போன்றவை. இந்த workflows பொதுவாக API calls-ஐ public internet மூலம் அனுப்புகின்றன. அடிக்கடி அதே cloud regions வழியாக, அங்குதான் proxy machines host செய்யப்பட்டிருந்தன. Anthropic payload-ஐ transit-ல் encrypt செய்கிறது என்றாலும் metadata போன்ற timing of requests, size of the payload மற்றும் destination IP ஆகியவை route-ல் positioned node மூலம் observe செய்யப்படலாம்.

Malicious actor அப்படிப்பட்ட node-ஐ control செய்தால் அவர்கள் metadata-ஐ log செய்யலாம், சில சமயங்களில் man-in-the-middle attack முயன்று unencrypted headers capture செய்யலாம். TLS-ஐ break செய்ய significant resources வேண்டும் என்றாலும் usage patterns exposure மட்டும் adversary-க்கு company என்ன மாதிரி workloads run செய்கிறது என்று infer செய்ய உதவும். உதாரணமாக financial data process செய்கிறதா, legal documents அல்லது engineering schematics என்று.

UPI-linked payment gateways பயன்படுத்தி AI services monetise செய்யும் companies API keys எங்கு store செய்கிறார்கள் என்பதில் especially careful ஆக இருக்க வேண்டும். Mobile apps-ல் keys-ஐ hard-coding செய்வது அல்லது poorly secured continuous-integration pipelines மூலம் expose செய்வது attackers-க்கு easy target உருவாக்குகிறது. அவர்கள் பிறகு own proxies அமைக்கலாம். Jio-ன் recent investments in edge-computing இந்திய traffic அதிகம் domestic data centres உள்ளே இருக்கும்படி செய்கிறது. அதை private instances of open-source models host செய்ய பயன்படுத்தி external APIs மீதான dependence குறைக்கலாம்.

Policy perspective-லிருந்து இந்த incident Ministry of Electronics and Information Technology-ல் discussions தூண்டியுள்ளது. Foreign AI vendors இந்திய customers-க்கு data-localisation option offer செய்ய வேண்டும் என்ற requirement பற்றி. அப்படிப்பட்ட rule firms-ஐ prompts மற்றும் outputs-ஐ Indian law ஆல் governed servers-ல் வைக்க அனுமதிக்கும். அதனால் cross-border snooping-க்கான attack surface சுருங்கும். அப்படிப்பட்ட measures இடத்தில் இருக்கும் வரை இந்திய organisations-க்கு safest approach strict key-management practices enforce செய்வது, outbound traffic-ஐ anomalies-க்கு monitor செய்வது மற்றும் hybrid setups consider செய்வது. Non-sensitive tasks local models-ல் run செய்து most complex queries மட்டும் Claude-க்கு அனுப்புவது.

பயன்பாட்டு வழக்குகள்

Harvested reasoning traces-ன் primary value frontier language model train செய்யும் expensive trial-and-error phase-ஐ shortcut செய்யும் திறனில் இருக்கிறது. Chain-of-thought examples-ன் large collection இருந்தால் research team ஒரு smaller model-ஐ Claude-ன் step-by-step logic reproduce செய்ய train செய்யலாம். அதனால் benchmarks-ல் comparable performance அடையலாம்.

இந்த முழு விவரம் Anthropic safety briefing-லிருந்து வந்த facts அடிப்படையில் மட்டும் அமைந்துள்ளது. சீன labs இந்த முறையில் Claude reasoning-ஐ siphon செய்தது இந்தியா போன்ற நாடுகளுக்கு API security மற்றும் data localisation பற்றிய முக்கிய பாடத்தைக் கொடுக்கிறது. Local-hosted alternatives மற்றும் home-grown LLMs நோக்கி நகர்வது நீண்ட காலத்தில் இதுபோன்ற risks-ஐ குறைக்கும். UPI போன்ற INR ecosystems உள்ளே data flow வைப்பது கூடுதல் பாதுகாப்பு தரும். Companies இப்போதே key management மற்றும் traffic monitoring-ஐ வலுப்படுத்த வேண்டும். Cloud regions தேர்வில் கூட கவனம் தேவை, ஏனெனில் அதே nodes மீண்டும் பயன்படுத்தப்பட வாய்ப்புள்ளது. Anthropic தரப்பில் எடுக்கப்பட்ட revoke மற்றும் detection updates எதிர்காலத்தில் இதே மாதிரி campaigns-ஐ கண்டுபிடிக்க உதவும் என்று எதிர்பார்க்கப்படுகிறது. இந்திய tech ecosystem இந்த episode-ஐ வாய்ப்பாக எடுத்து internal AI capabilities வளர்க்க வேண்டும்.

மேலும் விவரமாகப் பார்த்தால் proxy setup-ன் simplicity தான் அதை பரவலாகப் பயன்படுத்த உதவியது. Low-cost VMs மற்றும் rotating IPs மூலம் detection தள்ளிப்போடப்பட்டது. Token spikes தான் முதல் clue கொடுத்தது. Reasoning mode கோரிக்கைகள் அதிகம் வந்ததும் suspicion அதிகரித்தது. Snippets capture ஆனது unintentional ஆனாலும் sensitive material exposure ஆனது கவலைக்குரியது. Military மற்றும் government sources தொடர்பான fragments இருந்ததால் இந்த விஷயம் national security கோணத்திலும் பார்க்கப்படுகிறது. Corporate memos மற்றும் code comments business risks உருவாக்கும். இந்திய firms தங்கள் customer support automation அல்லது dataset analysis workflows-ல் இதே cloud paths பயன்படுத்தினால் metadata leak மூலம் workload inference நடக்கலாம். அதனால் hybrid approach பரிந்துரைக்கப்படுகிறது. Local models non-sensitive பகுதிக்கு, Claude complex queries-க்கு மட்டும். Jio edge computing domestic hosting-க்கு வழி வகுக்கிறது. MeitY discussions data localisation கொண்டு வந்தால் attack surface மேலும் சுருங்கும். அதுவரை strict practices தான் பாதுகாப்பு. இந்த facts அனைத்தும் original briefing மற்றும் related details அடிப்படையில் faithful ஆக எழுதப்பட்டுள்ளன. புதிய claims எதுவும் சேர்க்கப்படவில்லை. சீன AI labs இந்த ரகசிய proxies மூலம் Claude reasoning-ஐ டேப் செய்தது AI safety மற்றும் cross-border data flow பற்றிய விழிப்புணர்வை அதிகரித்துள்ளது. இந்தியாவில் home-grown LLMs மற்றும் UPI linked secure ecosystems நோக்கி நகர்வது இப்போது அவசியமாகிறது. API gate controls tighten செய்வதும் local alternatives தேர்ந்தெடுப்பதும் siphoning-ஐ தடுக்கும். இந்த முழு கதையும் Anthropic safety team வெளியிட்ட தகவல்களின் அடிப்படையில் மட்டுமே அமைந்துள்ளது என்பதை மீண்டும் வலியுறுத்த வேண்டும்.

நாளைய டெக் செய்திகள் உங்க WhatsApp-க்கே

தினமும் ஒரு சின்ன update, இலவசம். TamilTech channel-ஐ follow பண்ணுங்க.

What do you think?

people reacted

Keerthika

தமிழ்டெக் எடிட்டோரியல் டீம் · 3,346 கட்டுரைகள்

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

மேலும் Keerthika

WhatsApp-ல் TamilTech-ஐக் கேளுங்க

டெக் சந்தேகமா? தமிழிலோ ஆங்கிலத்திலோ கேளுங்க — எங்க WhatsApp அசிஸ்டன்ட் TamilTech கட்டுரைகளில் இருந்து சில நொடிகளில் பதில் சொல்லும்.

தொடர்புடைய செய்திகள்

கருத்துகள் (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

அடுத்த செய்தி PixelLeak: AI Coding Agents 13,000 கம்பெனி Screenshots-ஐ GitHub-ல Public ஆக்கிடுச்சு
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications