As the global political and tech spheres persist in deliberating the governance of large-scale artificial intelligence systems, open-source and open-weight models are swiftly catching up with the technological prowess of industry frontrunners. Nevertheless, this progression also unveils growing security concerns. By publicly sharing their code and weight files, open-source models reduce entry barriers, promoting technological innovation and democratization. However, they concurrently encounter risks such as malicious exploitation, supply chain security threats, and backdoor assaults at the weight level. For example, following the weight leakage of Meta's Llama model, numerous variants surfaced without undergoing security evaluations, with some even capable of circumventing the original safety filtering mechanisms. Furthermore, disclosures by the National Security Ministry unveiled that certain organizations directly employed open-source frameworks to construct interconnected large models, inadvertently granting attackers unauthorized access to internal networks, culminating in data breaches and security vulnerabilities. In the face of these challenges, nations and international organizations globally are actively seeking effective regulatory approaches to harmonize innovation and security, ensuring the robust and orderly advancement of artificial intelligence technology.
