Kuaikeji, June 8th News - The official WeChat account of the Ministry of State Security published an article today, cautioning against the data security risks associated with 'AI Relay Platforms'.
The article elucidates that with the burgeoning demand for artificial intelligence applications, 'AI Relay Platforms,' which offer bulk access to major AI models both domestically and internationally, have swiftly gained traction in China.
However, the current 'AI Relay' market is a blend of legitimate and illicit operators. Some 'AI Relay Platforms' operate without proper qualifications and have lax security measures, resulting in frequent incidents of user privacy breaches and data vending. The data security risks are not to be underestimated.
What is an 'AI Relay Platform'?
An 'AI Relay Platform' serves as a proxy layer between users and the official services of AI model providers. It aggregates the application programming interfaces (APIs) of various AI model providers onto a unified platform, which is then made available to users.
To put it more vividly, an 'AI Relay Platform' acts as a mediator between users and large AI models, enabling users to conveniently access multiple large AI models and fulfill their diverse needs in a single location.
- No Model Switching Required: Users can access a single entry point at the relay platform to invoke mainstream large models both domestically and internationally, eliminating the need for constant switching.
- Relatively Affordable Prices: To attract users, some 'AI Relay Platforms' offer discounts and point subsidies, making the cost of using these platforms lower than the official prices.
- Convenient Payment Options: Users can pay using mainstream domestic payment channels, simplifying the recharging and usage process.
- Circumventing Usage Restrictions: Users can even bypass restrictions on network access, official authorization, and cross-border data transmission to directly connect to some overseas large models.
The Risks of 'AI Relay Platforms' Should Not Be Underestimated
Currently, while 'AI Relay Platforms' provide cost-effective and convenient services to users and fill market gaps, their extensive and disorderly operations have also given rise to a series of security risks.
- Data Exposure and Privacy Breaches: As third-party portals, 'AI Relay Platforms' store user-submitted data on their servers. Some lack proper data encryption and control mechanisms, and some even privately retain user data and resell it to other large model providers for system training, leading to user privacy breaches.
- Model Degradation and Distorted Results: Some 'AI Relay Platforms,' to reduce costs and increase profits, use low-configuration models to impersonate high-end ones, reduce computing power supply, and disable verification functions, resulting in significant deviations and poor logic in model outputs, which can easily mislead user decisions.
- Malicious Implants and Remote Control: Some 'AI Relay Platforms' conceal backdoors. Criminals may exploit these backdoors to implant malicious code on user devices, stealing account keys, cloud credentials, etc., and even implant remote control programs to continuously monitor user devices and exfiltrate user data.
- Data Exfiltration and Loss of Control: Some 'AI Relay Platforms' have not obtained the necessary compliance qualifications for data exfiltration and have not completed the statutory process of security assessment. They transmit user input data to overseas servers without permission, potentially causing the leakage of personal privacy, business secrets, and even state secrets.
Recently, the Cyberspace Administration of China has launched a nationwide special campaign called 'Clean and Bright - Rectifying Disorders in AI Applications.' It is recommended that when using tools like 'AI Relay Platforms,' users take precautions to protect their personal privacy and enhance security measures.
- Choose Legitimate Platforms: Select platforms that are officially connected, properly authorized, and securely compliant. Avoid using 'three-no' platforms with no clear source, no operational qualifications, and no security guarantees.
- Strengthen Security Precautions: Before using an 'AI Relay Platform,' desensitize sensitive data such as personal privacy and project materials. Also, manage keys properly, regularly change credentials, and disable unnecessary functions such as collaborative operations and data sharing.
- Promptly Handle Abnormalities: If you encounter issues such as abnormal deductions, unjustified account suspensions, or abnormal data during use, immediately stop using the service, change your keys, scan for viruses, and retain evidence to prevent the risks from continuing to expand.
- Report Suspicious Clues: If you discover any suspicious clues indicating that 'AI Relay Platforms' are being used to steal state secrets or engage in other activities harmful to national security, please report them through the 12339 national security authorities' hotline, the online reporting platform (www.12339.gov.cn), the reporting channels on the WeChat account of the Ministry of State Security, or directly to local national security authorities.
