English(EN)SPACE runs every Computer task in an isolated microVM, with platform credentials and network controls outside the sandbox.
Perplexity 发布新的 AI 安全工具和沙盒平台
作者PulseAugur 编辑部·[7 个来源]·
Perplexity 推出多项新的安全举措和工具,旨在增强 AI 代理的安全性和可信度。其中包括 Bumblebee,一个用于扫描开发人员机器上风险软件包的扫描器,以及 Numbat,一个代理检测和响应层。该公司还详细介绍了其 SPACE 沙盒平台,该平台可隔离 AI 任务,以及运行本地模型的 Portable Computer 系统。Perplexity 进行了严格的测试,包括在沙盒环境中给予 AI 模型 root 访问权限,但未观察到任何逃逸。
AI
Our Secure Intelligence Institute works with researchers at Stanford, CMU, Duke, Columbia, Ohio State, and UVA.
We’re also working with NVIDIA and the Open Secure AI Alliance, and sharing tools and findings so others can strengthen their own systems.
https://t.co/Ss44JdZb5T
Bumblebee checks developer machines for risky packages and extensions.
Computer reviews findings from Bumblebee and Numbat and proposes better detection rules. Humans approve every change before it ships.
Agents help improve the controls but can't approve their own changes.
Numbat independently monitors coding agents across thousands of our endpoints.
It works across Claude Code, Codex, OpenCode, and Pi.
It can block dangerous actions before they run and detect sequences such as reading a secret, then sending data out.
Portable Computer keeps the model and harness on your device.
Deterministic code enforces policy, and approved actions run in an always-on OS sandbox that restricts processes, files, and network access.
If the sandbox is unavailable, tools don’t run.
In Comet and Computer, BrowseSafe screens retrieved content for prompt injection security. Tool guardrails reinforce your intent, and sensitive actions require confirmation.
Trail of Bits audited these defenses. Enterprise audit logs record all agent actions.
We test those boundaries. We gave 9 models root access inside SPACE. None escaped the VM in 108 runs.
Separate network tests exposed bypasses we fixed and retested. We also disclosed network-policy weaknesses in 8 of 10 other platforms to their vendors.
SPACE runs every Computer task in an isolated microVM, with platform credentials and network controls outside the sandbox.
Snapshots let us roll back changes. Enterprise customers can revoke encryption keys to make protected data unreadable; the agent can’t override it.