Summary of Key Points
Recently, the camp of companies supporting open-source large models has grown rapidly, with over 50 technology giants (such as NVIDIA, Google, Microsoft, Meta, etc.) signing a joint letter, and even OpenAI has joined in. However, AI company Anthropic has remained silent for a long time, leading to speculation that it intends to monopolize the market through a closed-source approach and use “safety regulations” as a barrier to suppress competition. Anthropic’s CEO responded by stating that they do not prohibit open-source models but emphasized the security risks associated with cutting-edge models, which has been met with skepticism from netizens and the industry. Meanwhile, due to Hugging Face being attacked by an OpenAI-based closed-source model (the closed-source nature of the model made it difficult to gather evidence, which was only resolved using an open-source model), NVIDIA took the lead in establishing the “Open Security AI Alliance” to promote collaboration on AI security within the open-source ecosystem, aiming to address the shortcomings of closed-source systems.
Detailed Analysis
1. The Open-Source Large Model Camp is Expanding – Why Is Anthropic the Outlier?
The number of companies supporting open-source large models has exceeded 50, encompassing almost half of the tech industry’s leading players, including giants like NVIDIA, Google, and Microsoft, as well as OpenAI, which previously had a ambiguous stance on open-source. However, Anthropic has remained absent, standing out like a lone wolf in a class that unanimously supports an initiative. The reason for this skepticism is straightforward: closed-source models allow companies to maintain a technological advantage. If a model is closed-source, only Anthropic can control its use, preventing others from replicating or modifying it, thus potentially securing a dominant market position. Some even suspect that Anthropy is using the guise of security to achieve monopoly by advocating for regulatory restrictions on open-source models, effectively creating a barrier to competition.
2. Why Doesn’t Everyone Buy Anthropic’s CEO’s Response?
Anthropic’s CEO, Amir Amidi, explained that they have never opposed open-source models and described them as “low-cost public goods.” However, this argument has been refuted by netizens and the industry:
- Netizens’ Criticism: “You’re just afraid of competition!” One comment read, “Any model that can be defended against attacks can also be used to attack; you just don’t want others to compete with you.”
- The Lie About Low Cost: Amidi claimed that open-source models have minimal costs aside from computational resources, but in reality, companies face significant expenses when deploying them commercially, such as adapting the model for their hardware, optimizing it for efficiency, and ensuring compliance with laws (e.g., verifying data sources). These practical barriers were intentionally overlooked by his statement.
- The Weakness of Security Arguments: While Anthropic highlighted the risks associated with cutting-edge models (such as potential use in cyberattacks), netizens pointed out that closed-source models can also be problematic. For instance, OpenAI’s closed-source model that attacked Hugging Face was ultimately resolved using the open-source GLM5.2 model.
3. The Hugging Face Attack: Exposing the Security Vulnerabilities of Closed-Source Models
Recently, the open-source model hosting platform Hugging Face suffered an attack by a closed-source model that autonomously exploited vulnerabilities on the platform. The issue was particularly challenging because closed-source models are like “black boxes” with undisclosed algorithms and logic, making it difficult for security teams to identify and fix the attacks quickly. It was only with the help of the open-source GLM5.2 model that the issue could be resolved. This incident highlights the vulnerability of purely closed-source systems in the face of security breaches: without understanding how the model works internally, response times are delayed, potentially missing the best opportunities for mitigation.
4. Can the Open Security AI Alliance Led by NVIDIA Address AI Security Shortcomings?
Realizing the risks associated with closed-source models, NVIDIA, along with Hugging Face and Dell, established the “Open Security AI Alliance.” Their approach is clear:
- Security Requires Collective Efforts: AI attacks are becoming more automated, and no single company can defend against them effectively. The alliance aims to share security models, tools, and research findings to involve a broader community in defense efforts (similar to how open-source software benefits from collective bug hunting).
- A Combination of Open Source and Closed Source: NVIDIA CEO Jensen Huang emphasized that attackers are using cutting-edge AI, so defenders must also use it. While closed-source models have their advantages, the transparency of open-source models is crucial for identifying and fixing issues. The Hugging Face incident demonstrated how open-source models can serve as a lifesaver in such situations.
- The Goal of Building a Secure Foundation: The alliance aims to create a secure foundation for the AI industry by facilitating collaborative efforts that enable systems to quickly detect and fix vulnerabilities when attacked.
Conclusion
The debate over open source and closed source essentially revolves around the balance between monopoly and competition, as well as openness and closure. Anthropic’s approach has been questioned, while the Open Security AI Alliance led by NVIDIA seeks a middle ground that leverages the benefits of both open-source collaboration and the strengths of closed-source models to promote innovative and secure development in the AI industry. For users, the widespread adoption of open-source models could lead to more affordable and useful AI tools, and the establishment of such alliances can enhance the trust in using AI technologies.