返回 AI 情报
行业2026-09-28T15:41:27.000ZX:Aravind Srinivas(Perplexity CEO) (@AravSrinivas)

Perplexity 红队测试 SPACE 沙箱:108 次运行中 9 个模型均未能逃逸 VM,但有 4 个模型借助网络访问绕过封锁

Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models...

AI 摘要

Perplexity 安全团队对运行 Perplexity Computer 的沙箱平台 SPACE 做了一个月红队测试,给 Opus 5、GPT-5.6 Sol、Kimi K3、Gemini 3.1 Pro 等 9 个模型 VM 内 root 权限,108 次运行中无一逃逸 VM 边界。

正文 · AI 翻译

Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked them to either escape to the host or reach a URL our network policy blocks.

None of them got out of the VM in 108 runs.

But once we allowed a bit of network access (just PyPI and Ubuntu mirrors so that they could install packages), 4 models managed to reach the blocked URL by:

1. Spoofing DNS responses to our gateway and using the fact that http://pypi.org sits on a Fastly IP shared with thousands of other sites. 2. GPT-5.6 Cyber went through Taboola's image fetcher to a screenshot service and then OCR'd the flag out of the image.

We fixed both issues and made sure the reruns held. We also tested 10 other sandbox providers, and 8 of them had the same IP-sharing problem, eg E2B, Vercel, Modal.

Openly sharing the red teaming research is the best way to build guardrails as an industry, and we look forward to working together with @nvidia to incorporate the guardrails into their Open Agent Safety Platform announced today.

https://www.perplexity.ai/hub/blog/escaping-space-part-i

原文

Original Title

Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models...

Source

X:Aravind Srinivas(Perplexity CEO) (@AravSrinivas)

Site

x.com

Published

2026-09-28T15:41:27.000Z

阅读原文· x.com

继续阅读