缪斯,Meta推出的全新个人AI代理,需要赢得你的信任

内容来源:https://www.wired.com/story/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it/
内容总结:
Meta于本周二正式发布其全新个人AI代理产品Muse,用户可通过即时通讯方式与其互动,在安全的云端环境中自动完成各类数字任务。该公司宣称,Muse从设计之初便将安全与隐私保障“内嵌于系统核心”。
即日起,iOS及安卓用户可通过专属Muse应用或访问Muse.ai网站使用该服务,同时也可在WhatsApp中直接向Muse发送消息进行交互。Meta还透露,其AI眼镜用户不久后也将能体验该代理。Muse基础功能免费开放,但若需处理大量自动化数字任务,用户则需订阅Meta旗下的AI付费套餐。
此举被视为Meta在竞争激烈的AI代理领域的最新布局,意在挑战诸如OpenClaw、Instinct等已广受关注的同类产品。Muse由Meta超级智能实验室研发,该部门是CEO马克·扎克伯格约一年前为追赶OpenAI和Anthropic而组建,并以高额薪酬吸引顶尖研究人员加盟。该实验室坚信,AI代理将深刻改变普通用户的上网方式及对Meta产品的使用体验。
据《连线》杂志早前报道,Muse此前已在Meta内部以代号“Hatch”进行测试,员工利用其自主操作第三方应用及代为浏览网页。Meta在官方博客中表示,Muse易于上手,旨在实现“零学习成本”。用户可用自然语言发出指令,代理即可独立完成发送邮件、预订行程,甚至代为出售车辆等任务。
此外,Muse还具备代用户进行在线购物的能力,其支付环节由Stripe设计的专用支付基建完成。该支付工具名为Link,可生成一次性卡号,避免代理在网络上使用用户的真实财务信息。Meta称,Muse是首个获得Link代理购物保护政策覆盖的AI代理,享有免手续费退货保障。
尽管Meta在个人代理领域入局较晚,但其试图通过强化安全与隐私功能来突出差异化。Muse首发即采用名为“Secure VM”的全新架构,旨在为每位用户的活动构建隔离的“虚拟机”环境,防止来自网络或第三方集成的不可信数据与代理中可执行用户指令的部分发生交叉。
个人AI代理的运作高度依赖用户信任,而这恰是Meta多年来屡受诟病的环节。为吸引用户尝试Muse并授权其接入第三方应用服务,Meta正竭力证明自身具备妥善处理用户数据的能力。Meta超级智能实验室消费产品工程副总裁戴维·辛格尔顿强调,构建此类可访问大量个人数据的系统,责任重大,因此团队刻意进行了审慎设计。
他介绍,系统内置名为“哨兵”的监控机制,可实时监测所有从虚拟机流出的数据,并依据用户或系统预设的授权策略进行匹配,或在必要时弹出人工确认对话框,请求用户批准即将执行的操作。辛格尔顿特别指出,这些确认提示会直接呈现给用户,而非经由模型过滤,以防提示注入等攻击。
尽管Secure VM旨在维护用户安全与隐私,但它并非绝对封闭的“保险箱”。辛格尔顿承认,虽然政策禁止Meta访问用户Muse数据,但技术上仍存在可能。用户可选择退出,拒绝将其数据用于AI训练。
从隐私角度看,Secure VM的架构值得关注,或可为行业树立AI代理新标准。未来,Meta还将推出“Confidential VM”版本,该版本运行于“可信执行环境”中,访问密钥由用户本地设备自主管理,从而确保除用户本人外,包括Meta在内的任何他方均无法访问其代理虚拟机。这一功能是Meta与Signal创始人莫西·马林斯派克合作的成果,后者近年来亦开发了专注隐私保护的AI平台Confer。
《连线》杂志看到了描述Confidential VM的技术白皮书预印稿。除架构上实现用户掌控密钥外,Meta还将授权特定安全公司访问该虚拟机源码,进行定期审计与隐私保证验证。同时,Meta将公开Confidential VM的二进制文件及透明日志,以便用户核验其与Muse连接的有效性与完整性。
辛格尔顿强调,Muse Secure VM已通过Meta内部人类与AI红队的广泛测试及私有漏洞赏金计划审核。即日起,Meta还将Muse纳入其公开漏洞赏金范围,有效漏洞报告的最高奖金可达30万美元,其中针对单名用户的成功提示注入攻击最高可获13万美元奖励。
中文翻译:
Meta周二宣布发布Muse,这是一款个人AI代理,用户可以通过发消息让其在安全的云环境中自动化完成数字任务,同时依赖Meta所称“从设计之初就内置其中”的安全与隐私保障。
Meta表示,Muse今天起面向iOS和Android用户推出,用户可通过专门的Muse应用以及网站Muse.ai使用。该公司还表示,用户可以直接在WhatsApp中给Muse发消息与该代理互动。Meta称,其AI眼镜的用户很快也将能够与Muse代理互动。Meta表示,用户可以免费试用Muse,但想要自动化完成大量数字任务的用户则需要购买该公司的一款AI订阅套餐。
Muse是Meta与OpenClaw和Instinct等病毒式传播的AI代理竞争的最新尝试,后者同样允许用户通过发消息来自动化完成数字任务。Muse是Meta超级智能实验室的产品,该AI部门是CEO马克·扎克伯格大约一年前为追赶OpenAI和Anthropic而成立的,为此向部分研究人员提供了令人咋舌的薪酬方案。该部门的建立基于一个信念,即AI代理将改变普通用户使用互联网的方式,也将改变Meta自身产品的使用方式。
《连线》杂志此前报道,Meta一直在内部以代号“Hatch”测试Muse,员工一直在使用它来自主操作第三方应用并代表自己浏览网页。
Meta在一篇博文中声称,任何人都可以开箱即用地使用Muse,该产品的设计宗旨是“无需学习成本”。该公司表示,用户可以用自然语言向Muse发出指令,代理将自主完成发送电子邮件、预订旅行,甚至代表用户出售汽车等任务。
Muse还能够代表用户进行购物,使用Stripe设计的特殊支付基础设施完成结账。该支付工具名为Link,由Stripe推出,会生成一次性卡号,这样代理就不会在互联网上到处输入用户的真实财务信息。Meta表示,Muse是首个获得Link针对代理的购物保护条款覆盖的AI代理,该条款保证免手续费退货。
Meta在个人代理的发布上姗姗来迟,但似乎正试图通过聚焦于Muse的安全与隐私功能来实现差异化。该代理上线时面向所有用户采用了名为Secure VM的架构,旨在将每个用户的活动隔离在所谓的虚拟机中,使来自网络和任何集成的不可信数据与代理中实际能够代表用户采取行动的部分保持分离。
个人AI代理需要用户的高度信任,而这一点恰恰是Meta多年来一直面临重大挑战的领域。为了让用户尝试Muse——并允许该代理与用户的第三方应用和服务集成——Meta正试图说服人们相信,该公司能够负责任地处理他们的数据。
“我们深知,如果要构建一个能够访问大量个人数据来源的产品,我们必须对其高度负责,因此我们非常审慎地设计了这套系统,”Meta超级智能实验室消费品工程副总裁戴维·辛格尔顿表示。“我们构建了所谓的Sentinel(哨兵),它实际上负责监控一切从虚拟机中流出的数据,要么将其与现有策略进行匹配——用户或系统已授权该行为——要么弹出一个人在回路中的对话框,请你批准它将要执行的操作。”
辛格尔顿指出,这些人工确认提示直接发送给用户,不经过模型过滤,以防提示注入等攻击。
虽然Secure VM旨在维护用户的安全与隐私,但它并非真正意义上的密封箱。辛格尔顿指出,虽然政策禁止Meta访问用户的Muse数据,但从技术上讲仍然是可能的。用户可以选择不允许将自己的数据用于训练。
从隐私角度来看,Secure VM的架构值得关注,哪怕只是因为它可能为AI代理树立新的行业标准。最终,Meta还将推出Muse“Confidential VM”(机密虚拟机),其设计使每个虚拟机运行在“可信执行环境”中,用户在自己的设备上本地管理自己的访问密钥。这样一来,包括Meta在内的任何其他方都无法访问该用户的代理虚拟机。
Confidential VM是Meta与Moxie Marlinspike合作的一部分,后者是端到端加密通讯应用Signal的创始人,近年来还开发了注重隐私的AI平台Confer。
《连线》杂志看到了描述Confidential VM的技术白皮书预印稿。除了构建使用户掌控自己访问密钥的系统架构外,Meta还向选定的安全公司开放Confidential VM源代码,以便定期审计和验证其隐私保障。Meta还将发布Confidential VM二进制文件(机器可读的指令文件)和透明日志,使用户能够验证其与Muse连接的有效性和完整性。
辛格尔顿强调,Muse Secure VM已经过广泛审查,包括Meta的人类和代理红色团队测试,以及公司的私下漏洞赏金计划。现在Meta还将Muse纳入了其公开赏金计划的范围内,有效漏洞报告的最高奖金为30万美元,其中成功对单个用户实施提示注入攻击的奖金最高为13万美元。
评论
返回顶部
英文来源:
Meta announced Tuesday the release of Muse, a personal AI agent that people can message to automate digital tasks in a secure cloud environment, all while relying on security and privacy that the company says is “built into it” from the start.
Meta says Muse is rolling out today for iOS and Android users in a dedicated Muse app, as well as the website Muse.ai. The company also says users can directly message Muse in WhatsApp to interact with the agent. Meta says users of its AI glasses will soon be able to interact with its Muse agent as well. Meta says people can try out Muse for free, but users who want to automate lots of digital tasks will need one of the company’s AI subscription plans.
Muse is Meta’s latest attempt to compete with viral AI agents such as OpenClaw and Instinct, which users can message with to automate digital tasks. Muse is a product of Meta Superintelligence Labs, the AI unit CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic, offering some researchers eye-popping compensation packages to join. The unit was built on the belief that AI agents will transform how everyday users navigate the internet, as well as Meta’s products.
WIRED previously reported that Meta has been testing Muse internally under the codename “Hatch,” and that employees have been using it to autonomously operate third-party applications and browse the web on their behalf.
Meta claims in a blog post that anyone can use Muse out of the box, and that the product was designed “so there’s no learning curve.” The company says users can prompt Muse in natural language, and the agent will work on its own to send emails, book travel, or even help sell a car on a user’s behalf.
Muse is also capable of making purchases on behalf of users, checking out using special payment infrastructure designed by Stripe. The payment tool, which Stripe calls Link, issues a single-use card number so that agents aren’t going around entering a person’s real financial information across the internet. Meta says Muse is the first AI agent covered by Link’s purchase protections for agents, which guarantees no-fee returns.
Meta is late to release a personal agent, but it seems to be seeking to differentiate itself by focusing on security and privacy features for Muse. The agent is debuting with an architecture for all users dubbed Secure VM, which is meant to isolate each user’s activity in a so-called virtual machine to keep untrusted data from the web and any integrations separate from the part of the agent that can actually take action on a user’s behalf.
A personal AI agent requires a lot of user trust, something Meta in particular has struggled with significantly over the years. To get users to try out Muse—and allow the agent to be integrated with users’ third-party apps and services—Meta is attempting to convince people that they can trust the company to handle their data appropriately.
“We know it’s really important, if we’re going to build a product like this that can access a lot of sources of personal data, that we’re really responsible with that, so we’ve designed this system very deliberately,” says David Singleton, Meta Superintelligence Lab’s vice president of engineering for consumer products. “And we’ve built what we call the Sentinel that actually looks out for everything that’s moving out of the VM and either matches it to an existing policy where the user or the system has given permission for that to happen or presents a human-in-the-loop dialog to ask you to approve the action it’s going to take.”
Singleton notes that these check-in prompts for humans come directly to the user and aren’t filtered through the model, to protect against attacks like prompt injections.
While Secure VM is built to maintain user security and privacy, it is not a truly locked box. Singleton notes that while Meta is barred by policy from accessing user Muse data, it would still be technically possible. Users can opt out of allowing their data to be used for training.
The architecture of Secure VM is noteworthy from a privacy standpoint, if only as a way to set a new industry standard for AI agents. Eventually, Meta will also offer Muse “Confidential VM,” designed so each VM runs in a “trusted execution environment” and users manage their own access keys locally on their devices. This way no one else, including Meta, can access that user’s agent VM.
Confidential VM comes as part of Meta’s work with Moxie Marlinspike, creator of the end-to-end encrypted messaging app Signal who also developed the privacy-focused AI platform Confer in recent years.
WIRED viewed an advance draft of a technical white paper describing Confidential VM. In addition to structuring the system so the user controls their access keys, Meta is also giving select security firms access to the Confidential VM source to regularly audit and verify its privacy guarantees. Meta will also publish the Confidential VM binaries (machine-readable instruction files) and a transparency log, so users can verify the validity and integrity of their connection to Muse.
Singleton emphasizes that Muse Secure VM has already been extensively vetted, including by Meta’s human and agentic red teams as well as through the company’s private bug bounty. And now Meta is adding Muse to the scope of its public bounty as well, with payouts up to $300,000 for valid vulnerability findings, including up to $130,000 for successful prompt injection attacks that affect a single user.
Comments
Back to top
文章标题:缪斯,Meta推出的全新个人AI代理,需要赢得你的信任
文章链接:https://news.qimuai.cn/?post=5010
本站文章均为原创,未经授权请勿用于任何商业用途