Svmuu News: The AI Standards and Innovation Center, under the U.S. Department of Commerce, in collaboration with the UK’s AI Safety Institute, conducted tests on the Kimi K3’s cyberattack capabilities and emphasized that “the U.S. remains in the lead.”
However, the validity of this assessment is disputed due to limitations in the scope of testing. Because of constraints in the hosting environment, Kimi K3 participated in only a portion of the tests; its overall cyber capabilities were estimated primarily based on 41 exploit benchmarks, whereas other models underwent more comprehensive testing, resulting in a wider margin of error for Kimi K3’s results.
In the exploit testing, Kimi K3 scored approximately 32%, higher than GLM-5.2’s 24%, but lower than the average of about 76% achieved by leading U.S. models. In simulated attack chain tests, Kimi K3 completed an average of 17 out of 32 steps in an attack chain and successfully breached the network once out of 10 attempts, while leading U.S. models completed an average of 28.5 steps.
The report notes that Kimi K3 has demonstrated a certain degree of autonomous attack capability, and its security safeguards did not prevent the model from developing vulnerabilities or executing attacks. However, the report also emphasizes that the scope of the testing was limited.