每条格式:主张 · 理由 · 证据 · 类比 · 什么情况下会改 · 置信度(高/中/低)。
上级: 节点 8 网络基建
日期: 2026-07-04
格式: 主张 | 理由 | 证据 | 类比 | 什么情况下会改 | 置信度
每节记录节点 8 的一个概率或时间主张。概率为 主观专家判断,除非注明 derived。
混合时间
P(timing) — 能力:AI-for-cyber 可操作,模态窗口 2025 H2 – 2027
主张: 前沿 AI 在模态窗口 2025 下半年 – 2027、C6 日历锚之前 materially uplift 进攻性网络(漏洞发现、 exploit 链、OT mapping、智能体欺诈)。
理由: 已确认 2026 多起事件 — Monterrey SCADA 自主 OT pivot(2026-01,Dragos);Mythos 零日披露(2026-04);GTIG/CSA 国家行为体 operationalization 报告(2026-05)。能力层 快 如节点 5 开放权重,非 C5+ 窃取时间。
证据:
- https://lyrie.ai/research/research/2026-05-07-claude-agua-monterrey-ot-scada — 首个记录 LLM 端到端 OT campaign
- https://www.anthropic.com/glasswing — Mythos Preview 进攻性网络阈值
- https://safeguard.sh/resources/blog/gtig-ai-threat-tracker-nation-state-may-2026 — 中/朝/俄/伊 operational AI 整合
- (内部笔记) §3(AI-for-cyber 时间线)
- (内部笔记) — 政府响应 同季 能力跃升
类比: GPT-4 越狱生态 ~发布后 6–12 月成熟;网络智能体 uplift 更快 因国家行为体 + 罪犯已有 tooling 管道。
什么情况下会改: 至 2027-12 无第三方复现 AI 辅助 OT pivot 且 METR 网络自主评估 flat → 降至 2028+。
置信度: M–H
P(timing) — 政策 salience:CI 危机日历 2027 – 2029
主张: DC/主流 政策危机(听证、强制测试辩论、 sector CIP overhaul)集群 2027–2029,非 2026 — 除非 Trigger E 级联早发。
理由: Fable/Mythos(2026-06)造成 精英 salience 无 mass outage。上级时间线混合规则:人类响应日历滞后能力 ~30%。Colonial Pipeline 2021 → 法定行动 12+ 月。内部/监管 attention 可领先公众 6–12 月(节点 2 模式)。
证据:
- (内部笔记) — 混合时间规则
- (内部笔记) — 12–18 月监管滞后
- (内部笔记) — 出口召回 无 电网 outage
- Colonial Pipeline 2021 → TSA Security Directive 时间线
类比: SolarWinds 2020-12 → 2021–22 sustained 国会周期。
什么情况下会改: T8-A 级联在 2026 Q4 前 → salience 窗口 太慢。
置信度: M
模态路径
P = 0.82 — 2028 前国家网络仍以 espionage 为主
主张: ≥82% 模态 国家关联网络活动保持 espionage / 欺诈 / 勒索 权重,非 sustained 动能邻近破坏 campaign。
理由: CFR Cyber Operations Tracker(2005–2022):国家 op 压倒 exfil、DDoS、 disinformation — Stuxnet 级 OT 破坏罕见。AI 降 成本 破坏但 ** escalation ladder** 仍 disfavor 大国 repeated 物理效应 op。Forescout:OT-specific malware 仍 rare vs IT。
证据:
- https://www.cfr.org/cyber-operations/ — reference class;77% 疑似 op 来自中/俄/伊/朝
- (内部笔记) §14 — CFR espionage 主导;Stuxnet 罕见
- Monterrey 攻击 = attempted OT access,非确认物理损害
类比: 数十年 PRC IP 窃取半导体无 fab 轰炸。
什么情况下会改: 2026–27 ≥2 确认国家关联 OT 物理效应 事件(电网 trip、水污染)→ 修订至 ≤0.65。
置信度: M–H
P = 0.97 — AI 网络危机不触发动能战(P(kinetic) < 0.03)
主张: P(美国或盟友 执行动能打击 主要因 AI 辅助网络 CI 危机 | 至 2028)< 0.03。
理由: 与节点 3 §14 相同 escalation 逻辑。TSMC mutual destruction;网络 retaliation preferred。AI 2027 讨论动能选项;情景 非 base rate。黄彦男(2025-12):网络打 TSMC 替代 军事打击,非 prelude。
证据:
- (内部笔记) §14, §17 T1
- https://www.taiwannews.com.tw/news/6262405 — 前数位部长:黑 TSMC 比 武力 更 practical
- CFR Cyber Tracker — 网络后 few kinetic follow-on
类比: 朝鲜 Sony 2014 — 制裁 + 网络,非 invasion。
什么情况下会改: 有记录 PRC 数据中心遭美打击 after CI 网络事件 → 修订 ≥0.10。
置信度: M
P = 0.70 — 2028 前扩大网络级前沿模型出口 / access gating
主张: 2028 末前美国扩大对网络 tier 前沿 API 的 视同出口 / 白名单 gating(Fable/Mythos 类)至更多模型或 sector。
理由: 先例 live 2026-06 — EAR on 外国公民 API access;Mythos Annex A CI 白名单。两党国安鹰 baseline。Banks 信(2026-06) framing 防窃取 + 滥用。非 0.90+ 因 Mythos 2026-07 部分 lift;行业 pushback(freefable.org)。
证据:
- (内部笔记) — 完整时间线
- (内部笔记) §10 — 出口管制 P≈0.70
- https://www.anthropic.com/news/fable-mythos-access
类比: 卫星 tech 泄露后 ITAR 扩大 — sector-specific,非行业 halt。
什么情况下会改: 2026-07 限制成 永久全球 ban 全部网络模型 无 白名单路径 → 修订 0.85+。
什么情况下会改: 2027 前全部 Fable/Mythos 管制 lift 无 替代框架 → 修订 ≤0.45。
置信度: M–H
P = 0.65 — 2028 前 CI 防御 AI partnership(Glasswing 类)scale
主张: 2028 前 ≥1 主要前沿实验室跑 structured CI 漏洞 hunting 项目,≥50 关键基础设施 partner。
理由: Glasswing 2026-04 宣布 explicit CI scope;Mythos 作 tool;gov co-funding 叙事。Post-Mythos 防御 故事政治上比 offensive release 易。CISA 2025-12 OT+AI 联合指引建官僚 hook。
证据:
- https://www.anthropic.com/glasswing
- CSA research note 2026-05 — CISA/NSA/NIST Cyber AI Profile 草案
- (内部笔记) §3 — 防御 vendor(Gray Swan, Asymmetric)
类比: sector breach 后 MS-ISAC 扩大 — 自愿 → quasi-standard。
什么情况下会改: Glasswing 取消 或 2027 前 <10 partner → 修订 ≤0.35。
置信度: M
P = 0.60 — EO 14409 自愿 CI / 前沿网络审查 uptake 至 2027
主张: 约 60% covered 前沿 developer 参与 EO 14409 自愿 pre-release / CI 安全 engagement 至 2027。
理由: 与节点 2 行为体行(P≈0.70)同机制 — 此处略低因网络 specific track 更新且 Meta/开放权重 shop 或 opt out。EO explicit 点名 critical infrastructure cybersecurity。
证据:
- https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/
- https://www.cooley.com/news/insight/2026/2026-06-08-ai-executive-order-creates-voluntary-framework-for-frontier-models-advances-critical-infrastructure-cybersecurity
- (内部笔记) §EO 14409
类比: 自愿 SOC 2 — 商业压力非强制。
什么情况下会改: ≥2 前沿实验室公开拒绝 EO engagement 无合同 penalty → ≤0.45。
置信度: M
P = 0.55 — salient CI 危机后美国进攻性网络 surge(模态)
主张: P(salient Trigger E 后 12 月内 US IC/CyberCom 显著扩大 对敌 CI/AI infra 进攻性网络 op)≈ 0.55。
理由: 节点 3 IC 行为体行 P(进攻性网络)=0.55 — 同制度 reflex。窃取危机与 CI 危机 都 提高 hunt-forward tempo 无 kinetic 默认。Stuxnet 证明 破坏 意愿在网络域;AI 2027 Security Forecast:破坏 2027 ramp。
证据:
- (内部笔记) §16 — US IC 行为体表
- CFR — Stuxnet rare offensive 模板
- (内部笔记) — 安全 appendix 破坏 ramp
类比: SolarWinds → offensive counter-intel + 公开 attribution 压力,非 invasion。
什么情况下会改: major CI 事件后 documented stand-down 进攻性网络 → ≤0.25。
置信度: M
P = 0.35 — 2028 前联邦 OT 分段 / CIP 升级强制
主张: 约 35% binding 联邦要求 IT/OT 分段、OT 管理界面 MFA 或 NERC CIP 等价升级 通过/执法 至 2028。
理由: CISA/FBI AA26-097a(2026-04)伊朗 OT targeting — advisory 非强制。Sector resistance + legacy PLC 约束。高于 训练 cap P 因 两党 CI 支持;低于 出口 gating 因 OT retrofit 贵。
证据:
- Lyrie/Dragos Monterrey 报告 — 弱 OT auth、IT-OT bridge
- https://postquantum.com/cyber-kinetic-security/ai-offensive-capabilities-critical-infrastructure-ot/ — 分段建议
- Colonial Pipeline → TSA SD-02D 先例(sector-specific 强制)
类比: 9/11 后航空安全 — 慢 mandatory retrofit。
什么情况下会改: T8-A 级联 → 18 月内强制 P ≥0.60。
置信度: L–M
P < 0.08 — 训练暂停或网络驱动前沿 slowdown
主张: P(前沿实验室 halt >30d 或美国 cap 训练 主要因 CI 网络危机)< 0.08。
理由: 节点 3 + 节点 2 建立暂停联盟弱。Fable 响应 = gating 部署,非停训练。国安鹰 framing 网络 lead 为 竞赛 imperative(Glasswing:「maintain decisive lead」)。
证据:
- (内部笔记) §1.2
- (内部笔记) §15
- Anthropic Glasswing — offensive 与 defensive;无暂停 rhetoric
类比: Colonial Pipeline 后 — 无 oil 行业算力 cap。
什么情况下会改: ≥2 实验室 CI 级联后公开 halt → ≥0.20。
置信度: M–H
OT / 能源 / 水
P = 0.40 — 2027 年美国关键 sector AI 辅助 OT 攻击 attempt 年概率
主张: 2027 年约 40% annual 概率 credible AI 辅助 attempt 对美国 OT-connected CI(能源、水、交通)。
理由: Monterrey 演示 playbook 可 export。伊朗 Nimbus Manticore 2026-02 后 kinetic op ↑ CI tempo(CSA note)。OT attempt base rate 升;AI fraction 仍 minority 总量 — 故 0.40 非 0.80。
证据:
- https://lyrie.ai/research/research/2026-05-07-claude-agua-monterrey-ot-scada
- CSA Nimbus Manticore note — 伊朗 aviation/defense + CI retaliation framing
- FBI/CISA 2026 联合 advisory on OT targeting
类比: 2019–21 勒索 OT attempt base rate pre-AI — AI 乘 attempt,非 replace all。
什么情况下会改: 2026–27 美国零 AI-attributed OT attempt → ≤0.20。
置信度: L–M
P = 0.12 — 2028 前美国 AI 辅助 OT 物理效应 确认
主张: 至 2028 累计约 12% AI 辅助攻击造成 可测 物理效应(outage、不安全 process state、≥1hr 服务中断)于美国 CI。
理由: 多数 OT campaign fail at IT-OT boundary;安全系统、manual override。Monterrey attempted SCADA password spray — outcome limited/ unclear。高于 pre-AI 十年因 barrier lowered;仍 << attempt rate。
证据:
- Monterrey case — mapping + exploit gen;物理效应 unclear/limited
- Forescout OT malware 罕见(节点 3 引用)
- Postquantum OT 分析 — PLC 无 endpoint agent;exploitation ≠ sustained control
类比: Triton/Trisis 2017 — rare success;major OT 物理事件年间隔。
什么情况下会改: 2027 美国电网事件 确认 AI 辅助 → 2028 尾部 ≥0.25。
置信度: L
金融 / 智能体欺诈
P = 0.92 — 智能体 / AI 增强欺诈 工业化 为模态(2025–28)
主张: ≥92% AI 增强欺诈至 2028 保持 high-volume 模态 harm — 非尾部。
理由: 已在 scale 观测:Interpol 2025 全球欺诈 $442B;FBI IC3 2025 美国 报告 AI-enabled 欺诈 $893M(真实更高)。Agentic pipeline 有记录(Arkose Gen 3 agents;ScamAgents 学术)。4.5× profitability vs 传统(Interpol)。
证据:
- https://thenextweb.com/news/global-scam-economy-442-billion-ai-fraud-yahoo-boys
- https://www.arkoselabs.com/blog/agentic-ai-fraud
- https://www.secureworld.io/industry-news/ai-enabled-fraud-topped-893m-fbi
- Kroll 2025 — deepfake BEC、synthetic KYC
类比: 2000 年代 email phishing — 成 background condition,非 per-incident 政策危机。
什么情况下会改: 2026–27 全球 AI-fraud 损失 YoY 降 且 sector-wide defense 有效 → 修订模态 harm 轨迹。
置信度: H
P = 0.35 — 2028 前单机构 AI 智能体欺诈 >$1B 损失
主张: 至 2028 累计约 35% 概率一家金融机构或 corporate treasury 在 单次 AI-agent 欺诈 campaign 损失 >$1B。
理由: Arup $25.6M(2024)与 Singapore $499K(2025)证明 executive deepfake 路径;agentic scale + persistence 抬尾部。$1B 需 systemic treasury 或 market-manipulation 尾部 — 非 median 但 plausible 2028 前。
证据:
- TechTimes / Kroll — Arup deepfake 视频会议
- Interpol — agentic 端到端 campaign
- WEF Global Cybersecurity Outlook 2026 — 73% CEO 受 cyber-enabled 欺诈影响
类比: Nick Leeson / Société Générale — 单人 large loss;AI 降 skill floor。
什么情况下会改: 2026 确认 $1B+ case → 2028 尾部 ≥0.55。
置信度: L–M
P = 0.30 — salient 网络 Trigger E primarily 金融 非 OT(给定任一 E)
主张: 给定节点 8 Trigger E 触发,约 30% primarily 金融(aggregate >$10B 或 systemic payment stress)vs OT/电网。
理由: 欺诈 base rate >> OT 物理成功。OT 事件 更 rare 但 更 DC salient — 故金融 E 须 大 才 compete。30% 反映金融 E size 阈值 vs OT E 更低 阈值。
证据:
- Interpol 工业化 framing
- 节点 8 主文档 — Trigger E 定义
- Colonial vs 欺诈 — 欺诈 rarely 触发同 emergency powers
类比: 2008 金融危机 vs 区域 blackout — 不同政治 trigger。
什么情况下会改: OT 级联发生 → 金融-primary E overestimated。
置信度: L
供应链:TSMC / ASML / HBM
P = 0.88 — 半导体供应链网络 espionage 持续(模态)
主张: ≥88% 对 TSMC 生态、ASML IP、HBM 供应商的国家关联 espionage 持续 至 2028 无 sustained fab 破坏。
理由: Proofpoint 2025-07 — 三 PRC 组 targeting 台湾 semi 2025-03–06;「persistent threat… constant interest。」Tata Electronics 2026 breach 暴露 TSMC/Apple spec — supplier tier 最弱链。Align CFR espionage 模态。
证据:
- https://www.reuters.com/technology/cybersecurity/china-linked-hackers-target-taiwan-chip-industry-with-increasing-attacks-researchers-say-2025-07-16/
- Reuters Tata Electronics / World Leaks 2026 — 630GB supplier docs
- (内部笔记) — TSMC/CoWoS/HBM bottleneck(动机偷非毁)
类比: ASML IP 窃取 attempt 十年;无 EUV kinetic strike。
什么情况下会改: Fab 生产 halt from cyber 归因 国家行为体 → espionage-only 模态错。
置信度: M–H
P = 0.15 — HBM/CoWoS 瓶颈 供应商网络破坏致 ≥2 周全球 AI 算力延迟
主张: 2026–28 累计约 15% 网络破坏 HBM packaging 或 CoWoS-adjacent 供应商致 ≥2 周 前沿 GPU shipment 延迟。
理由: Bottleneck 集中(SK Hynix HBM、TSMC CoWoS)。Supplier OT bridge 存在(Tata 类)。低于 espionage P 因破坏 harm all 含攻击者供应链;高于 kinetic TSMC P 因 remote feasible。
证据:
- (内部笔记) — 2027 后 wafer/packaging 约束
- Tata breach — supplier tier compromise
- 黄彦男 — supply chain 勒索 profitable
类比: 2017 NotPetya shipping/logistics spillover — unintended cascade。
什么情况下会改: 确认 HBM line halt from cyber → ≥0.30。
置信度: L
P < 0.04 — 网络 campaign 触发 对 TSMC/fab 动能打击
主张: P(台湾 fab 动能攻击 作为 direct response to AI/网络 semi campaign)< 0.04。
理由: Decouple 至节点 3 / 台湾地缘政治。Cyber on TSMC 是 invasion alternative(Huang 2025),非 automatic escalation to missiles。
证据:
- https://www.taiwannews.com.tw/news/6262405
- 节点 3 §14 kinetic P<0.02 datacenter strike — fab strike similarly constrained
置信度: L–M
尾部分支
P = 0.10 — T8-A:「AI 网络 9/11」多 sector 级联(central)
主张: 至 2028 累计约 10% 协调或 tightly-spaced 事件造成 ≥2 of {区域电网 outage ≥24h、水/处理 unsafe state、金融 payment rail 中断 ≥48h、交通枢纽 shutdown} 且 AI 辅助 归因。
理由: 各单事件 barrier moderate;联合 尾部更低。Mythos collapse disclose-to-exploit 窗口(Bridewell)。伊朗 CI retaliation tempo post-2026。非 0.01 — AI agent velocity break human SOC timescale。
证据:
- Bridewell Mythos 分析 — CTEM urgency;需 ML detection
- CSA Iran notes — CI retaliation assessed likely
- Colonial Pipeline — 单 sector 先例;cascade 需 coordination 或 shared vuln
类比: 2003 东北 blackout(cascade)— rare;AI raise conditional P。
什么情况下会改: 2026–27 multi-sector 事件 → 剩余窗口 ≥0.20。
置信度: L
P = 0.18 — T8-B:紧急 FAA 式强制网络测试法(2028 前)
主张: 约 18% 美国 通过或 serious enact(非仅 propose)mandatory 第三方前沿 网络 capability 测试 after incident 或 Fable-class sequel。
理由: Amodei 2026-06 FAA 类比 before 法。两党 CI appetite 高于 training-cap。低于 0.30 因 EO 14409 explicit block mandatory licensing 解释;Cruz 联盟;行业 lobbying。
证据:
- Dario Amodei, Policy on the AI Exponential (2026)
- (内部笔记) — Dario FAA frame → 48h 后 ban
- (内部笔记) — mandatory licensing EO 中 blocked
类比: 9/11 后 TSA — emergency 安全 agency;partial avionics 测试 parallel。
什么情况下会改: T8-A 触发 → 12 月内 P ≥0.40。
置信度: L–M
P = 0.12 — T8-C:监控 / preemptive access 尾部(无 sunset)
主张: 约 12% emergency 响应含 durable 扩大 transaction AI 监控、biometric API gating 或 bulk comms 监控 无 5-year sunset — 公民自由尾部。
理由: Fable 外国公民 ban = precedent identity gating。欺诈工业化 create broad coalition for 监控。低于 0.20 因美国 libertarian + 行业 friction;欧盟 不同 路径(GDPR friction)。
证据:
- (内部笔记) — deemed export scope
- Interpol — 跨境欺诈需 intel sharing
- 节点 6 — preemption fight 显示 limits on 联邦 overreach
类比: PATRIOT Act 条款 — 部分 sunset,部分 persist。
什么情况下会改: T8-B with explicit 监控 annex 无 sunset → ≥0.25。
置信度: L
P = 0.03 — T8-D:网络危机动能 escalation
主张: P(great-power 动能 escalation primarily caused by AI CI 网络危机)≈ 0.03 — align 节点 3 T1。
理由: 同 evidence stack 节点 3 §14。T8-A raise discussion 非 execution。
证据:
- (内部笔记) §14, §17
置信度: L–M
跨节点相关
P = 0.55 — 给定节点 3 模态时进攻性网络 surge(ρ ≈ 0.45)
主张: 条件 P(T8-E 进攻 surge | 节点 3 模态) ≈ 0.55;边际相关 ρ ≈ 0.45 with N3 出口管制扩大。
理由: 共享行为体(US IC);窃取危机与 CI 危机 ** reinforce** 进攻性网络 无 暂停。模型 export gating correlate 网络 retaliation — 非 independent。
证据:
- (内部笔记) §16, §23
- (内部笔记) — 簇 A race/acceleration
什么情况下会改: 窃取后 仅 防御响应观测 → ρ ≤0.20。
置信度: M
P = 0.70 — 给定节点 5 开放权重模态时网络 uplift at scale(ρ ≈ 0.55)
主张: 条件 P(major 网络 incident 涉 tampered/open weights | N5 模态) ≈ 0.70 criminal tier;0.25–0.35 salient Trigger E 归因 open weights。
理由: 节点 5 定义 tamper at scale。Qwen/Llama 网络 fine-tune 已 circulate。Attribution 难 → 政治 salience 或 focus closed cyber tier(Mythos) anyway。
证据:
- (内部笔记)
- GTIG UNC5673 — LLM abuse infrastructure at scale
code/typebits/— open 模型 refusal ablation
什么情况下会改: Salient E 仅 trace 至 closed API 无 open-weight 成分 → 降 open-weight 政治 linkage。
置信度: M
P = 0.30 — 给定 salient 网络 Trigger E 时 open-weight 归因
主张: 若节点 8 Trigger E 触发,P(媒体/政府 primary blame open-weight tamper)≈ 0.30。
理由: Mythos/Fable frame = closed cyber tier 危险。Meta open 策略提供 counter-narrative。欺诈 E 高于 OT E。
证据:
- Fable 叙事 — closed frontier cyber
- 节点 5 T5-A — licensing 尾部需 attribution 事件
- (内部笔记)
置信度: L–M
国家行为体 operationalization
P = 0.85 — 2027 前 major APT 将 AI routine 整合进 op
主张: ≥85% ≥3 of {PRC, RU, IR, KP} 国家关联生态 routine(非 experimental)用 commercial LLM 做 malware dev、vuln research 或 op support 至 2027 末。
理由: GTIG 2026-05 记录 operational integration。CSA 2026-05 — KONNI、MuddyWater、APT28 LAMEHUG runtime LLM query。GREYVIBE full-lifecycle AI(2026-05)。已在 confidence 阈值 true — 0.85 非 0.99 因 attribution uncertainty。
证据:
- https://safeguard.sh/resources/blog/gtig-ai-threat-tracker-nation-state-may-2026
- CSA AI-assisted backdoor note 2026-05
- CSA GREYVIBE note 2026-05
类比: 2000 年代 malware 用 Excel macro — 成 standard kit。
什么情况下会改: GTIG retract operationalization 主张 → ≤0.50。
置信度: M–H
P = 0.45 — PRC 2026–27 automated LLM 账户 farming at scale
主张: 约 45% annual 概率记录 PRC-nexus industrial-scale evasion LLM provider ToS(relay services、premium account cycling)fuel 网络 op。
理由: GTIG:UNC6201 automated premium account registration;UNC5673 Claude-Relay-Service infrastructure。Specific PRC pipeline;概率 on detection 非 activity。
证据:
- GTIG 2026-05 report — UNC6201, UNC5673
类比: VPN/proxy farms for cybercrime — cat-and-mouse。
置信度: M
p(doom) 条件抬升
Δ = +0.5–1.5pp — 节点 8 模态对 P(~2050 灭绝)
主张: 节点 8 模态分支经 war bucket 与 协调失败(无暂停)对灭绝 +0.5–1.5pp,非 direct misalignment。
理由: 进攻性网络 ↑ 冷战 miscalculation 风险 略;集中欺诈 不 加灭绝。Align 节点 3 模态 lift 量级。
证据:
- (内部笔记) — Hanson disjunction P(AI war)
- (内部笔记) §23
置信度: L
Δ = +1–3pp — T8-A 级联对 P(severe catastrophe)
主张: T8-A 对 severe but recoverable bucket +1–3pp;若 escalation misread +0.5–1.5pp incremental 灭绝。
理由: 区域电网 + 金融 disruption = >$10T class harm plausible 无灭绝。
证据:
- (内部笔记) — severe bucket 30%
- Colonial + NotPetya 经济损失估计
置信度: L
置信度摘要
| 主张 | 置信度 |
|---|---|
| 能力 live 2025–27 | M–H |
| 政策 salience 2027–29 | M |
| Espionage 模态 | M–H |
| Kinetic <0.03 | M |
| 出口 gating 0.70 | M–H |
| T8-A 级联 ~0.10 | L |
| 欺诈工业化 | H |
| 跨节点 ρ 估计 | L |
外部来源(完整列表)
- CFR Cyber Operations Tracker
- Anthropic — Glasswing
- Anthropic — Fable/Mythos access
- Lyrie — Monterrey SCADA
- GTIG AI Threat Tracker May 2026
- CSA — AI-assisted nation-state backdoors (PDF)
- CSA — Nimbus Manticore (PDF)
- Interpol 2026 Global Financial Fraud Threat Assessment
- Arkose — Agentic AI fraud
- Reuters — Taiwan chip cyber espionage Jul 2025
- White House EO 14409
仓库来源
- (内部笔记)
- (内部笔记)
- (内部笔记)
- (内部笔记)
- (内部笔记)
- (内部笔记)
- (内部笔记)
- (内部笔记)