Brief IA

Claude Mythos from Anthropic Challenges AES Encryption in the Lab

🤖 Models & LLM·Tom Levy·

Claude Mythos from Anthropic Challenges AES Encryption in the Lab

Claude Mythos from Anthropic Challenges AES Encryption in the Lab
Key Takeaways
1Researchers at Anthropic used Claude Mythos to attack a reduced version of AES encryption.
2This version of AES is not used in production, so data security is not at risk.
3The study shows that advanced AIs can identify mathematical flaws in encryption algorithms.
💡Why it mattersThis advancement highlights the potential of AIs to uncover previously unknown vulnerabilities in digital security systems.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Claude Mythos from Anthropic Challenges AES Encryption in the Lab

Claude Mythos, Anthropic's AI specialized in cybersecurity, has already demonstrated its ability to find security flaws in software code, such as operating systems and browsers. Today, it has been revealed that this powerful AI is also capable of uncovering mathematical vulnerabilities at the level of the encryption algorithms upon which our digital lives depend. In a post published this week, Anthropic announced that by using Mythos, its researchers have successfully found a new way to attack AES with a "reduced number of rounds."

Your Data is Not at Risk

AES is the most widely used symmetric encryption and serves as a cornerstone of our digital security. Nevertheless, Anthropic reassures the public. While these research findings are significant, they do not affect the security of your data. The "reduced number of rounds" AES that Anthropic attacked is actually a simplified version of the encryption method. Reduced-round encryptions are not used in production systems but allow researchers to better understand attack techniques that could, in the future, be generalized to all encryption, and help estimate security levels by studying simpler sub-problems.

  • These research advancements are significant but have no practical impact on current systems.
  • HAWK is a proposed scheme that has not yet been deployed, and the attack on the discovered AES concerns a weaker version and does not compromise the full encryption.

In comparison to previous attacks, Claude Mythos was able to bypass the reduced version of AES 200 to 800 times faster. Anthropic's new work primarily aims to demonstrate that cutting-edge AI models can be used to identify weaknesses in encryption systems. Anthropic emphasizes that Claude Mythos has enabled testing the resilience of algorithms to enhance trust and ultimately make systems safer.

Claude Mythos Has Also Weakened a System Designed for the Post-Quantum World

The fact that Anthropic's AI has discovered a new attack method against AES is a notable achievement. Used for decades, this algorithm has been scrutinized more thoroughly than almost any other encryption algorithm. In addition to this discovery, Claude Mythos has also significantly weakened another system called HAWK, which was designed to withstand quantum computers.

  • The signature scheme is HAWK, which is supposed to be robust even against hypothetical quantum computers.
  • HAWK has survived two years of expert reviews, but in 60 hours, Mythos found an unknown attack that halved the strength of the scheme's key.

However, just like the attack on a reduced version of AES, this discovery does not affect the security of your data. Indeed, HAWK is a "candidate" signature scheme for the post-quantum world and is therefore not yet deployed on the systems we use.

A System That Was Supposed to Be Indestructible

HAWK has already passed two validation stages by experts as part of a selection organized by the National Institute of Standards and Technology (a U.S. government agency). Yet, as reported by Anthropic, Claude Mythos managed, in 60 hours, to improve the best-known attack against this system, thereby halving its main asset.

Anthropic explains that it would now be necessary to "double the size of HAWK keys to achieve the same level of security." However, if this is done, the advantages of HAWK for post-quantum signing would be eliminated. This discovery only concerns a candidate system, without affecting other signature systems considered for the post-quantum world.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.