Skip to content

US Department of Commerce Tests Kimi K3: Rushes to Announce "US Still Leads" Without Completing Test

Jul 24, 19:28

According to Dynamic Insight monitoring, the AI Standards and Innovation Center under the U.S. Department of Commerce, in collaboration with the UK AI Security Institute, tested Kimi K3's network attack capabilities. The Department of Commerce's official account emphasized the "U.S. still leads" aspect, but the value of this evaluation report is limited as it was not a completely symmetrical peer review.

Due to hosting environment restrictions, Kimi K3 only participated in partial testing. The report's estimation of its overall network capabilities mainly came from a vulnerability exploitation benchmark consisting of 41 tasks. Other models underwent more comprehensive testing, hence Kimi K3's estimation has a wider margin of error.

In this vulnerability exploitation test, Kimi K3 scored around 32%, higher than GLM-5.2 at 24%, but significantly lower than the average level of around 76% for the leading U.S. model. The U.S. models do have a significant lead in this aspect, but a single benchmark cannot represent the entire network attack capability.

Kimi K3 also demonstrated practical autonomous attack capabilities. After gaining initial network access, it completed an average of 17 steps in a simulated attack chain of 32 steps. Out of 10 attempts, it successfully breached the network in full once. The average for cutting-edge U.S. models is 28.5 steps.

The report also found that Kimi K3's security barrier did not prevent it from developing vulnerabilities or executing attacks. The report itself repeatedly emphasized the limited scope of the testing, yet the U.S. Department of Commerce's external messaging only highlighted the "U.S. still leads" aspect, showing a clear policy promotion bias.

View source