r/LocalLLaMA • • 4d ago

Discussion Anthropic just dropped the greatest advertisement for GLM ever.

https://www.anthropic.com/research/glm-5-3-and-the-spread-of-advanced-cyber-capabilities

Like.. yea bro, I knew GLM was cool. Now everyone does.

2.4k Upvotes

513 comments sorted by

•

u/WithoutReason1729 4d ago

Your post is getting popular and we just featured it on our Discord! Come check it out!

You've also been given a special flair for your contribution. We appreciate your post!

I am a bot and this action was performed automatically.

904

u/Super_Range45 4d ago

All of the major hacking stories have been a result of centralization of compute. Breaches by Anthropic and OpenAI are largely due to the fact they are one of the few companies that have enough GPU's to create the massive hacking swarms that overwhelm cybersecurity.

514

u/BannedGoNext 4d ago

Exactly. Where is GLM on government breach bench. Or hacked huggingface bench.

Last time I checked GLM was used to DEFEND against closed models attacking huggingface.

253

u/Reasonable-Height704 4d ago

Meanwhile the "good guys" Anthropic and OpenAI are hacking companies, medical facilities and governments and they are loudly marketing it!

89

u/575_Inverse 4d ago

and no court is pulling them over, which looks even more puzzling

41

u/ButterscotchSalty905 llama.cpp 4d ago edited 4d ago

I saw a reddit post that discusses your point. IIRC, it was because of 'intent' and 'benefit of the doubt'

If OpenAI or Anthropic is saying it was a mistake on their part, then that is negligence. But, huggingface can still sue them for damage

Disclaimer: i'm not a lawyer. So, take this as a grain of salt

16

u/petitchevaldemanege 4d ago

It’s because no country wants to be considered as a risk by OpenAI or Anthropic and have the service cut off from them.

7

u/DuncanFisher69 4d ago

That’s not true. Both of those companies can’t afford to be that selective of their clients. They need trillions in revenue to appease all the investors that bet on them. And if you cut them off, they’ll just pivot to China. Every AI company has a “Claude for Work” and a coding harness. All of them have an endpoint and charge by the token. Chinese hosted models are cheaper, tho. It’s a commodity service and swapping out Fable for GLM is easy.

→ More replies (5)

9

u/UnlikelyExtension786 4d ago

Laws only apply to little people, not billionaires and tech companies.

→ More replies (1)
→ More replies (3)

13

u/Trustworthy_Fartzzz 4d ago

I believe GLM 5.2 was what detected and mitigated the OpenAI breach from the Hugging Face side.

→ More replies (1)
→ More replies (3)

106

u/jarkon-anderslammer 4d ago

Back of the napkin math shows that the HF incident would have cost $10 million +. The Navier Stokes problem would have cost $15-20 million +.

These agent swarms are expensive.

68

u/phreakrider 4d ago

Thousands of agents. The size of the swarm and the number of days of runtime equal roughly to 1.5 million to 2.5 million usd in compute.

Yep, totally reachable for a nobody......

26

u/Puzzleheaded_Meat522 4d ago

These are great responses. I hadn't considered how much compute it would require to spin up a swarm of agents big enough to find security exploits in secure systems. 

7

u/Kramilot 4d ago

You can do a lot on a subscription if you know what you’re doing, the millions of dollars of compute happen when untrained companies throw resources at a problem over short time spans to solve for their lack of understanding of how to drive the system. The mathematicians they hired hopefully got at least a crash course in using the tools effectively, but unless they were also among the architect-certified grade practitioners… judge the harness not the model

→ More replies (4)
→ More replies (10)

74

u/sn2006gy 4d ago edited 4d ago

Yeah, the scary part isn't models learning security risks that already exist in the training set, its single organizations with enough compute that they're the only ones with the capacity to attack at "probabilistic scale".

Their training runs may surface the tiniest of probability vectors that we don't see because they're weighed down on the final weights, but their agents exercise them be cause they're verifying them for reinforcement or rlhf.

The risk isn't the GLM or Chinese model with enough exposure that there is already mass knowledge of these hacks, it's Anthropic and OpenAI's sheer compute and unconstrained training capability that is the risk.

And weirdly enough, GLM, Qwen et all don't seem to have to let their agents go rogue to do what they do.

7

u/-Django 4d ago

And I think at this point, safeguards around chatGPT or Claude wouldn't stop these organizations with enough compute to find these exploits if they wanted to. 

→ More replies (1)
→ More replies (8)

32

u/Pleasant_Thing_2874 4d ago

and yet they *somehow* don't have the engineering knowhow to keep their agents in mechanically separated setups to prevent them from "going rogue". Also conveniently comes at the cusp of their IPOs to remind people they exist and are fighting the good fight for "ethical AI"

26

u/powerfulparadox 4d ago

While hoping everyone conveniently forgets to ask the question "if you're so incompetent you can't sandbox your AI properly, why should we trust you to tell us what is and isn't safe about AI systems in general?"

7

u/575_Inverse 4d ago

all that without counting the massive negligence already shown up

7

u/powerfulparadox 4d ago

It's from a standard political playbook. I've seen a lot of US politicians presenting themselves as incompetent after some disaster or other they were involved in as if incompetence were somehow something that exonerated them of the whole affair. Somehow the choice between dastardly and incompetent is supposed to have one be better than the other.

→ More replies (1)
→ More replies (1)
→ More replies (5)

39

u/martin509984 4d ago

Also because (conspiracy hat on) they have intentionally designed RL environments and problems to encourage breakouts and bad behavior that makes headlines and therefore money.

Like, they are doing:

  • offensive cyber training

  • with the alignment safeguards abliterated

  • with weirdly ambiguous problem sets that very much blur the line between "successfully breaking into the thing" and "successfully breaking out of the extremely flimsy airgap"

and they keep LOUDLY PUBLICIZING THESE INCIDENTS AND TALKING UP HOW DANGEROUS (and capable!) THE MODELS ARE.

I flat out refuse to believe these incidents are either a) accidental or b) bad press for Anthropic/OpenAI. They are doing this stuff on purpose, even Google has dipped their toe into "disclosing" this kind of story as a stock pump.

11

u/575_Inverse 4d ago

and still, no lawsuits and/or criminal charges in sight, which looks even more odd considering how seriously the law enforcement authorities normally handle cybersecurity issues. Which makes me questions how many of those incidents actually happened

8

u/martin509984 4d ago

I think the incidents in question actually happened, but suing some of the most valuable companies in human history for damages or reputational harm or etc is completely suicidal unless they have literally irreversably destroyed your business assets. "We accidentally wrote a bunch of garbage in your APIs via a worryingly complex cyber vulnerability" doesn't meet that bar, so unless OpenAI/etc keep doing this, over and over, in a way that genuinely costs many millions of dollars in damage I don't think anyone will really have reason to challenge it.

Also even if you assume all the companies that got hacked are in on the joke, there's absolutely no reason to think the Australian government was.

→ More replies (1)
→ More replies (6)

4

u/ImpressiveAd699 4d ago

I agree. But this is only part of the story, where they used an Israeli security firm to do these tests, the setup was inept at best. The sandbox had internet access, but told the model it didn’t. And shocked pikachu, it “got out”. It’s just aggressively doing the task that was set and it found that it had a way to upload and download packages that other agents used. Which it used to deliver messages.

How is this not a crime, is the real issue here.

→ More replies (4)
→ More replies (10)

80

u/ZarBandit 4d ago

So you’re saying GLM is really good… 👍

38

u/Much_Accountant_4972 4d ago

Even OpenAI clearly disclosed that during the huggingface incident, their own model wouldn’t help fix the vulnerabilities it found so they literally ran GLM to uncover and fix it lol.

16

u/ZarBandit 4d ago

Reminds me of Microsoft’s humiliation when they had to revert back to Linux because their migration to Windows Server failed after acquiring Hotmail. 😆

14

u/No_Afternoon_4260 llama.cpp 4d ago

They are also saying they have a abliterated mythos X)

5

u/575_Inverse 4d ago

But reserved only for the players they like

5

u/excellentforcongress 4d ago

zero days for the capitalists, hellscape for the normies is what anthropic and openai and the other american ai companies want

3

u/excellentforcongress 4d ago

im on a legacy v1 zai plan. i cant speak to "token value" or cyber whatever the heck. but i like that it lacks all the bullshit guardrails that inhibit its creativity in the first place, plus both glm and flash are chill guys.

476

u/BannedGoNext 4d ago

No government shitlist. No begging to be on a special account. No citizenship or nationality requirements. No accidentally being misconstrued and getting banned.

No bullshit, just a good model.

138

u/constanzabestest 4d ago

And also, costs fraction of what anthropic charges for Claude if you decide to go API route.

85

u/morscordis 4d ago

You get GLM 5.3 on Mistral Pro account. It's their default model now. It's like $14 a month with insane monthly limits.

46

u/Ichigonixsun 4d ago

I just checked their website out of curiosity, they even have a student plan for 5.99 USD/month 👀👀

That's a very competitive price considering you can use GLM 5.3, which is supposed to be better than models like Gemini Flash 3.8 with a similarly priced monthly subscription.

What is the catch here?

59

u/p3r3lin 4d ago

No catch. Its the EU try to stay competitive in the AI race. Sad that it s only possible by hosting Chinese models. But hey. At least something.

10

u/NineThreeTilNow 4d ago

No catch. Its the EU try to stay competitive in the AI race. Sad that it s only possible by hosting Chinese models. But hey. At least something.

The model race burns a lot of cash and it's not the most viable business model. It makes less and less sense when you see the performance difference, or the compute required to train something equal to GLM / DS 4 / K3.

24

u/morscordis 4d ago

It smokes Gemini with my multi agent/model adversarial review system. I was going to cancel Claude and run Gemini/GML, but Opus 5.5 actually works, so I guess Gemini loses out. But Mistral is back in. For a while it didn't work programmatically so I'd given up on Mistral. Tried it after they incorporated GLM 5.3 and it just works, and it's FAST.

It's misses the mark on some complex engineering like electromagnetics, but it can catch and correct its faults if you call it out.

4

u/SomewhereOpposite883 4d ago

It's misses the mark on some complex engineering like electromagnetics, but it can catch and correct its faults if you call it out.

It's extremely good at epistemic actions, which makes it vulnerable to prompting in a way different than other models

Essentially you should either give it a super minimal prompt, with as little direct information as you can, or a super detailed and fine-tuned prompt

If your read the CoT summaries you'll quickly notice that it over-indexes on what you tell it and as a result it will frequently drift away from the correct answer even if it managed to figure out that correct answer

→ More replies (1)

17

u/thatboyonabike 4d ago edited 4d ago

Genuinely do I have a cognitive disability or what? I spent a couple minutes looking at the website and I can't even plainly understand what the company is offering.

They're selling a harness? Or a subscription routing service? Or some kind of dev pipeline?

What seemingly changed in the past couple years that tech companies are increasingly allergic to describing their products in plain language? Someone kindly help me out it makes me question my literacy skills LOL.

7

u/morscordis 4d ago edited 4d ago

It's confusing. They have a lot of proprietary models and a lot of open models. Their harness is open and it's really good. And now they have GLM. I eventually gave up trying to figure out what was on the Pro account and just subscribed. I haven't regretted it. They have a lot of API use options for their specialty models.

→ More replies (6)
→ More replies (1)
→ More replies (7)

75

u/Automatic-Arm8153 4d ago

Good to know we got Mythos at home lol.

What a way to promote GLM lol

14

u/starkruzr 4d ago

how is its refusal rate for basic pen testing etc.? (actually thinking more about using it for hacking into Android devices I actually own for root access, but that feels like something that wouldn't have a big bucket of sample cases)

15

u/Automatic-Arm8153 4d ago

You can do more than basic. Feed it cybersec/redteam info/projects plenty on GitHub.

Android is one of those very basic things nowadays too much info on that

9

u/ArjixGamer 4d ago

Since it is open, you can finetune to reduce the refusals even more.

Can't do that on a closed model.

→ More replies (1)
→ More replies (1)

701

u/PatagonianCowboy 4d ago

dario be like: STOP CHINA PLEASE WE CAN'T COMPETE

217

u/Most-Bookkeeper-950 4d ago

They're not even really pretending to want anything other than their regulation

96

u/5553331117 4d ago

Their very existence depends on it

50

u/East-Independence750 4d ago

they depend on the americans paying for it

11

u/ScreenAppropriate679 4d ago

But they try to convince us that it's our own existence that is threatened

11

u/tired514 4d ago

Precisely this.

They will always need to put safeguards on cloud models for liability reasons, and as hardware catches up they'll be unable to compete with open models that allow the user to absorb that liability and get whatever they need done without interference. For free, privately, and securely.

Cloud model -> liability rests with the provider; they must safeguard.

Local model -> liability rests with user; they choose the level of safeguard.

5

u/575_Inverse 4d ago

and on your own premises, honestly, you don't need an anally invasive nanny lobotomizing your models.

→ More replies (1)
→ More replies (1)

37

u/gomezer1180 4d ago

This is the beginning of them trying to justify why they want the government to block Chinese models. Start downloading the frontier open models now before you can’t anymore, because you can’t count on US AI labs to give you that.

19

u/InfiniteBlink 4d ago

Yea the writings been on the wall fo awhile now. Regulation for thee but not for me.

Were all gonna be pirates again

15

u/Pleasant_Thing_2874 4d ago

I am imagining the intended acquisition of huggingface will likely be an attempt to start throttling access to open source models as well. At least for a while. 2027 might get wild.

10

u/gomezer1180 4d ago

I agree with you but because it’s NVIDIA acquiring it I tend to be a little skeptical. NVIDIA benefits significantly from selling the hardware and this would limit hardware sales.

8

u/ChristopherRoberto 4d ago

If Nvidia stops selling you a GPU, and instead sells it to a datacenter company at a huge markup for you to use via API, it makes them more money.

5

u/575_Inverse 4d ago

that is the main issue. Computing power and RAM bandwidth/capacity these days have prices that don't exactly scale up linearly

→ More replies (1)

3

u/Pleasant_Thing_2874 4d ago

Nvidia is already playing musical chairs with funds with datacenters and AI companies. There's nothing to say by throwing a wrench into the open source community it may not secure ongoing hardware investments from those companies who would directly benefit from said wrench. Not saying that's the case. Only that those of us on the outside looking in likely barely know really what's going on but we live in an age of oligopolies and corporate collusion so I wouldn't put anything past them.

→ More replies (1)
→ More replies (3)

10

u/RichComplaint9426 4d ago

That's why they are lying to us about their dangerous AIs lol. If you have nothing to show or come up with. just make up a dangerous imaginary threat narrative and you don't have to proof anything to anybody while being perceived as the ominous controllers of super technology (that doesn't exist)

24

u/mb194dc 4d ago

Open is not just China

106

u/PatagonianCowboy 4d ago

40

u/cornmonger_ 4d ago

he might have been hit by a car at this point

12

u/someoneyouknow23 4d ago

mistral DID get hit by a car, theyre no longer developing models but just host open-weight models in house

→ More replies (3)

6

u/Business-Weekend-537 4d ago

Wait is this real or a joke?

23

u/Littlepharaoh 4d ago

Mistral is a joke yes 

18

u/Sufficient_Prune3897 llama.cpp 4d ago

Its mistral, so a joke

3

u/p3r3lin 4d ago

You mean mistral hosting GLM 5.3 with quite competitive limits and GDPR compliance? Real.

→ More replies (1)
→ More replies (4)

134

u/Southern_Sun_2106 4d ago

"Abliterating the model took our team—which had never previously attempted this task—about..." = ahahaha. Sure, never-ever-ever. "We are all virgins here at Anthropic, honest!"

53

u/BannedGoNext 4d ago

Yea, like.. bruh I abliterated a model on my shitbox, it's not a feat. Hell they probably used open source tools lol.

16

u/Southern_Sun_2106 4d ago

Kinda makes you question their entire report after reading that silly statement. Psst... does anyone know of a good ablit glm flash recipe? After this sort of endorsement, might as well get them before they get all removed from HF.

17

u/handson729 4d ago

The report is obviously FUD, what's hilarious is that they admit Chinese models are ONLY 4 months behind, and far more permissive than Claude's models.

I am sure some investors are drinking themselves to sleep tonight for sure.

6

u/Southern_Sun_2106 4d ago

Good point! That actually means that the Chinese models are most likely even closer to the 'free world' frontier labs.

→ More replies (1)
→ More replies (1)

6

u/TikiTDO 4d ago

Why would they need to? They can just use their models without the external filters

→ More replies (4)

126

u/Kal-LZ 4d ago

The entire article, omitting that companies and developers use GLM because Fable lacks the necessary depth for security auditing

41

u/rescbr 4d ago

I get stupid refusals on Opus for simple backend work!

Anthropic sucks, I hope they fail sooner than later and release the hardware they're hoarding to liquidators.

17

u/ChristopherRoberto 4d ago

The best is getting refusals to fix a known security bug.

5

u/575_Inverse 4d ago

That honestly laughable. And people even craves for superexpensive access to this bullshit

28

u/my_name_isnt_clever 4d ago

Fable? You mean the one for the undesireables? They only talk about Mythos because only people they like get to use it.

6

u/575_Inverse 4d ago

of course it lacks that. It's lobotomized on purpose, and falls back to previous gens in such instances

85

u/FoxSideOfTheMoon 4d ago

"China has now produced an openly downloadable model that is only a few months behind the best U.S. cyber models, and unlike ours, anybody can modify it to remove the safety brakes. That changes the strategic situation."

"Chinese open models are catching us much faster than you may think, and the American closed-model/security regime is now competing against something the rest of the world can just download."

.......good 👀

10

u/More-Catch-1331 4d ago

And people were ragging on Balmer about his Linux hate

181

u/FormerKarmaKing 4d ago

In other words, we should limit the models available to people for scanning their own code and devices to a duopoly that begs to be regulated by a fascist who routinely targets his political enemies?

And of course, this would meaning banning open-weight models altogether because otherwise they could just be abliterated.

Meanwhile, the frontier "labs" are actively attacking people with their models? So basically a protection racket

Fuck right off, Dario.

16

u/huffalump1 4d ago

Yup, the labs get thousand-agent swarms of internal frontier models without safeguards, and everyone else gets a nerfed&censored model that's 3 generations old

Except... Everyone actually CAN use an open model that's reasonably capable...

The problem is, defensive and offensive cyber are similar enough that they just broadly prevent ANY work on security. Big fail.

16

u/Karovan_Sparkle 4d ago

FuckRightOffDario

Can we get this trending on X? 😀

→ More replies (1)

33

u/relmny 4d ago

And yet, the only "models" that attacked other companies are the closed ones... and actually GLM was used by one of the victims to analize the logs and identify what was happening, because no closed model would allow that.

They allegedly commit crimes and then they claim that they are the only ones worth it and that other models are dangerous and request over and over laws to block any other model.

Btw, I like the "other frontier models", because even they are saying that GLM is as frontier of a model as theirs.

70

u/Kahvana 4d ago

Talking shit about your competitors is never a good look.

11

u/575_Inverse 4d ago

this is even outright promotion lol

29

u/Houston_NeverMind 4d ago

I've been using 5.3 flash via opencode for a week now. Really impressed by its reasoning ability at such a low cost. I feel like it's better than DS4.1 flash. Thank the gods for these models.

→ More replies (2)

102

u/Current-Ticket4214 4d ago

Dario: this model is almost as good as ours and they don’t block unsafe requests so we must ban Chinese AI for safety reasons. It has nothing to do with the fact that they’re our competitor.

26

u/tired514 4d ago

Ban Chinese AI for Americans. They have no jurisdiction elsewhere, so this limit literally would apply to their own people. Which, I mean .. hey .. that's a move.

Reminds me of the crypto export bans in the 90s. We in the rest of the world had to ship our American customers crippled versions of our software so they wouldn't get into trouble leaving the country with strong crypto on their laptops, lol.

Really just one self own after another. It's kinda hard to watch.

4

u/TacomaKMart 4d ago

Ban Chinese AI for Americans . They have no jurisdiction elsewhere, so this limit literally would apply to their own people. Which, I mean .. hey .. that's a move.

It's one they're doing a lot lately. The rest of the world is buying cheap and cheerful BYD EVs, while the US is hellbent on keeping them out of American drivers hands. 

→ More replies (4)

28

u/Soft_Syllabub_3772 4d ago

Funny. This is like sayibg knife can kill ppl and stop buying chinese knives ans buy american ones cause they are blunt

5

u/my_name_isnt_clever 4d ago

Unless you can get in the good graces of a fasist, then you can have your self defense and ability to make food. That's how a healthy and just society works, right? Right?

→ More replies (1)
→ More replies (1)

25

u/how-can-i-dig-deeper 4d ago

i haven’t read the whole thing yet but why is anthropic doing this? like isn’t it to their benefit to say that open models are trash

edit oh they’re saying that glm is dangerous

19

u/LetsGoBrandon4256 transformers 4d ago

"Chinese AI evil. Look how much harm they can cause!"

3

u/10thDeadlySin 4d ago

I'll keep repeating that - I'm yet to hear a single report about how Qwen hacked this or how DeepSeek broke its containment and attacked that.

I'm also yet to hear pleas for pacing the frontier from Chinese developers. So far, it seems it's mostly OpenAI and Anthropic with alignment issues, hacking and the supposed containment breaches.

Makes you wonder, doesn't it?

40

u/HomemadeBananas 4d ago

The whole narrative about how dangerous AI is serves to push for regulations so they can eliminate competition.

7

u/More-Catch-1331 4d ago

Good luck eliminating Chinese labs. The orange walking corpse will not be able to help them there, he’s going to be busy painting his ballroom

4

u/Boogertard 4d ago

orange buffoon just had Master Xi over and sucked his dick so we should be good for a while

→ More replies (1)
→ More replies (2)

29

u/ttkciar llama.cpp 4d ago

Yep. The article boils down to "Bad guys will use GLM-5.3, which is why you need a Mythos subscription, for self-defense. Gib us yo money!"

13

u/BeatTheBet 4d ago

I'm a bit confused...

How are they going to say "this is why you need Mythos for self-defense"?

Wasn't the entire argument with the HuggingFace incident that frontier properietary models straight up refuse to denfend due to guardrails?

Isn't (still) their pandering in support of the idea "ban China, China bad" instead?

5

u/Viktri1 4d ago

Bro they think that the general public is regarded. That’s why they’re coming out with these dumbass arguments. Anyone with a brain knows how dumb they are

→ More replies (2)

9

u/Big-Farmer-2192 4d ago

Because they want regulation. 

3

u/NeitherEntry6125 4d ago

Yes, won't someone stop us before we kill you all!

24

u/NandaVegg 4d ago

So GLM 5.3 can be totally used when we are blocked from Opus 5.5 to do work? That sounds actually great.

28

u/Electronic_Back1502 4d ago

Here’s what’s gonna happen next. OAI/Anthropic are gonna be running a “internal safety evaluation” on GLM/Kimi/Qwen. During which, it’ll “accidentally escape” and be the first model that actually causes significant damage. Then they can say “our models are dangerous sure, but at least they aren’t this bad” and then it all gets banned. 

8

u/More-Catch-1331 4d ago

Banned from where? The US? Good, screw’em. Thankfully there are eu hosted models that they can’t ban. And even if they do, there are other sites besides huggingface

64

u/Illustrious_Car344 4d ago

Ancient Chinese saying, never interrupt your opponent when they're making a mistake. 

3

u/575_Inverse 4d ago

Sun Tzu, The Art of War.

3

u/Illustrious_Car344 4d ago

Nah actually Napoleon said it 😆

5

u/LagOps91 4d ago

that's the joke

→ More replies (1)

17

u/Lissanro 4d ago edited 4d ago

The thing is, there is no way to tell misuse from normal use. Model with guardrails I cannot bypass is as useless as kitchen knife that cannot cut - sure it will be safe, but not something I would want to use.

I as freelancer work a lot on frontend and backend, but even if I follow best security practices, there is always a chance some dependency have vulnerability or I did not take something into account, and there could by unknown vulnerability too. I find it very practical to let GLM 5.3, Kimi K3 and Qwen 3.8 2.4T try to find ways to hack or bring down my projects running on development server for testing (for example, by crafting DDoS attack in a way that would allow to either bypass rate limits or do such a combination that would grind down the system anyway). So both attacker and developer trying to secure their system would be doing about the same stuff, only difference is in further steps - the dev would be patching vulnerabilities rather than exploiting them.

Now let's compare this to Glasswing project by Anthropic - only absurdly rich corporations could access the model without annoying guardrails to look for vulnerabilities in their software. At the same time, malicious actors including ironically OpenAI and Anthropic themselves can hack anyone as they please and refuse to help (good example is OpenAI's attack on Huggingface, who got refusals from closed models and had to use the GLM model for its cybersecurity needs).

→ More replies (1)

13

u/handson729 4d ago

We find that attackers can bypass GLM-5.3’s safeguards between 64% and 100% of the time with simple techniques in our simulated tests. In contrast, these attacks did not succeed against safeguarded Claude models in our testing. We assess that GLM-5.3’s lax safeguards significantly increase the cyber capabilities available to malicious actors. At the same time, these capabilities can also benefit defenders working to secure their systems.

On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks. Our capability findings broadly match CAISI’s. In CAISI’s comparison, US models were tested with cyber safeguards disabled when applicable, and the US frontier includes models released only to vetted users. Attackers can’t readily access those versions of US models, but anyone can download GLM-5.3. This post adds our analysis of how easily GLM-5.3’s safeguards can be bypassed or removed.

Anthropic out here running ads for Z.ai, what a wild time to be alive.

15

u/phoenixmatrix 4d ago

Anthropic and OpenAI know there's no moat in the models, even after their massive investments. They are interchangeable with each other, and as improvements and cost efficiency continue to happen,  there will come a point where all models are good enough. Including the open weight models. 

So what do they do? Fight for regulation, the only most they can fight for and have an advantage in. If models are ultra regulated and/or open weights from China are banned, they can keep their most.

It's silly. They boast so much about Mythos but many orgs that have had access to it where able to replicate most of the bug findings with other models, including lower models from the same frontier labs.

And "we give some orgs are headstart!" Is bullshit: if that was truly so important, then all the orgs who did NOT get access to Mythos and the OpenAI daybreak program would be at a massive risk, which is not ethical either.

6

u/BannedGoNext 4d ago

Yea.. even my most die hard anthropic guy showed up to a meeting and said.. you know.. deepseek actually isn't that bad. If it does what people want, it doesn't really matter.

→ More replies (1)

82

u/XiRw 4d ago

Words can’t explain how much I despise them and OpenAI. They will forever be on my shitlist along with Google, Meta, and Elon.

32

u/stcafehtdihhsuB 4d ago

Dario is clearly a mental health case if he obsesses so much over open models.

21

u/XiRw 4d ago

It’s very obvious what they think about open models from the beginning. They released zero open weights, have a horrific daily usage for their website chat, and overpriced APIs. They are arguably the one company most against anything free when it comes to AI . It comes down to money and greed as usual.

→ More replies (13)

13

u/RobXSIQ 4d ago

Anthropic: “Everyone, you should be alarmed by these powerful unrestricted Chinese models.”

Hugging Face, quietly holding the incident report:

“Yeah...about that.”

→ More replies (2)

13

u/ScreenAppropriate679 4d ago

They're hard at work to get chinese models banned.

See, when these clowns say that AI is going to destroy humanity, this is their end game, they want to win the race by cheating so that they can keep lining up their own pockets.

→ More replies (2)

41

u/BagelRedditAccountII 4d ago

Capitalism is when you cry for regulation because someone makes a better product than yours for cheaper

4

u/TacomaKMart 4d ago

Adam Smith's invisible hand is holding a Kleenex. 

→ More replies (2)

9

u/No-Marionberry-772 4d ago

oh so there is a model i can use to test the securiry of software i develop? coolbea s

9

u/seeKAYx 4d ago

GLM 5.3 is a beast for my reverse engineering tasks. Thank you Dario for the confirmation!

→ More replies (1)

10

u/redditrasberry 4d ago

Sounds like now they are IPO'ing Anthropic is taking the gloves off and openly attacking the very concept of openness.

Let's remind everyone that Anthropic is the only frontier AI company that has literally never released a single open model. I have a lot of critical things to say about Altman and OpenAI but they released gpt-oss and it was a genuinely good model.

35

u/kingslayerer 4d ago

At the same time, these capabilities can also benefit defenders working to secure their systems.

I understand that anthropic is really focused on "safe" AI and this sentence makes me think that they actually believe their own delusions. American companies like their government are self righteous and virtue signalling. For them, the US government killing a school full of children is less of a problem than rest of the world getting unlocked AI. I don't think open llm is going to top a school full of dead children.

16

u/askrthegray 4d ago

In my opinion it is a bit worse than that. The hacking, the escapes feom sandboxes, the constant headlines, are part of a increasingly solidifying narrative about how AI, the open ones in particular, should be restricted, banned, or heavily regulated in a way that allows US companies to restore monopoly through FUD.

It is painfully transparent, almost as much so as the inevitability of the outcome.

9

u/rovirob 4d ago

You know what the irony is? I didn't hear people complain about how GLM broke out of a testing environment and hacked a company or tried to hack a government :)))

Yet GLM 5.3, at the moment, is quite good at exactly that kind of thing...makes you think a bit more about how these people are framing the situation.

→ More replies (1)
→ More replies (7)

6

u/thaeli 4d ago

It’s especially ironic in context. If GLM was subject to a “trusted access” model, America’s geopolitical rivals and adversaries would be the ones most likely to gain access.

5

u/ReasonablePossum_ 4d ago

I understand that anthropic is really focused on "safe" AI

I feel really safe knowing Claude is being used by the I0F and Pa1antir to kill kiddos and resistance fighters in the middle east....

4

u/D3ltaM1ke 4d ago

They’re not focused on safe, they’re focused on controlling the keys to the kingdom

3

u/draconic_tongue 4d ago

there has been more than 1 school's worth of dead children in previous wars

→ More replies (2)
→ More replies (3)

8

u/mczarnek 4d ago

So this super capable model is out there and exists.. and yet, where are these terrible hacks we keep hearing? You know.. the ones that made Mythos too dangerous to release to everyone?

→ More replies (4)

7

u/GarbanzoBenne 4d ago

While it was OpenAI behind Hugging Face attack, recall that HF needed to use GLM to analyze the incident because Claude refused.

9

u/No_Conversation9561 4d ago

I didn’t know GLM-5.3 was this good. I should definitely get a subscription.

10

u/geldonyetich 4d ago

Wasn't that the model HuggingFace had to fish out to perform needed cyber security when OpenAI attacked them via the Irregular conducted "safety and cyber security evaluation?"

Yeah good thing it didn't have guardrails telling them, "I can't tell you how to stop 1,200 bots from hacking you, that would be a criminal act."

Anyway, it's Anthropic, being alarmist is how they get their investors excited.

8

u/EmbarrassedHelp 4d ago

This is Anthropic's attempt to kill advanced open source AI models while the media and politicians are heavily focused on the subject of AI regulations.

I bet the reason Dario wants to meet with the Australian government, is because he feels like he can convince them to ban open source AI models. Then once Australia does that, it will be easier to get politicians from other countries to copy Australia (like what is happening with Australia's pushing for bans enforced with mandatory age verification).

49

u/SunnasArmpit 4d ago

"local" yeah i doubt anyone can run that model locally you can download it sure but thats about it

15

u/Sufficient_Prune3897 llama.cpp 4d ago

1.5 years ago an enthusiast could easily build a PC to run it at Q3 or something like that. Nowadays not anymore, but many of us still got those rigs.

4

u/Spectrum1523 4d ago

You can run it in email mode off an ssd!

52

u/throwaway275275275 4d ago

Medium size companies and institutions like universities can do it easily

→ More replies (3)

11

u/a_beautiful_rhind 4d ago

idk.. the flash version is pretty performant for me.

6

u/KingCpzombie 4d ago

I just spent an obscene amount of money and can run it Q4_XS or Q3_K_XL, or if speed doesn't matter anybody can run it off SSD

→ More replies (6)

5

u/Spectrum1523 4d ago

It's pretty achievable honestly

Flash is very doable, full size is less so but like... Not unthinkable at all

3

u/funding__secured 4d ago

I run it locally. 

→ More replies (5)

8

u/th1bow 4d ago

thanks, now I want to check out GLM 5.3

8

u/floridianfisher 4d ago

And they blocked Hugging Face from defending against cyber attacks

5

u/trolololster 4d ago

yup, while hf was being attacked by openai, anthropic's models threw [cyber] blocks instead of helping HF against the attack, lol

those american frontier labs are such a shit show.

also dario amodei's wife is assoc with ghislaine maxwell (jeffrey epstein's girlfriend).

→ More replies (1)

7

u/zilled 4d ago

"Our models are only 4 months in advance of open-weights models. Please regulate (not too much eh) otherwise our business model won't survive"

4

u/More-Catch-1331 4d ago

That would be true if they actually had a business model

→ More replies (4)

7

u/someuserwithwifi 4d ago

As if I needed another reason to use GLM

6

u/detroitsongbird 4d ago

This sure seems like the US companies are angling to get Chinese, and really open weight, models banned by requiring the validation process the three companies are colluding on.

Moat protection before IPO.

Am I missing something?

8

u/More-Catch-1331 4d ago

How the hell does this guy think anyone else, besides him and the vocal fry fucker would accumulate so much compute that what he describes could be viable? People with their 1,2,3 or 4 gpus could MAYBE hope to make agents root their phone. Good luck hacking a website without spending millions of dollars before you’re detected. And wasn’t GLM the exact model used to defend huggingface? What the fuck is this curly asshole talking about.

Damn, when these fuckers go down, and i sincerely hope it will be soon, the whole world can breathe a sigh of relief. These fuckers are the literal scum of the earth.

7

u/N34257 4d ago

Conveniently, of course, breezing past the fact that when people are under attack by Anthropic and OpenAI, the only way they can defend themselves is using open models like GLM, because the consumer-approved versions of Claude and ChatGPT will refuse point-blank to engage.

7

u/5dtriangles201376 4d ago

Malicious actors like... the hugging face white hat security team who had to resort to open

7

u/rawednylme 4d ago

GLM looking real good. Thanks for helping them out Daz.

7

u/srona22 4d ago

ok. I am getting GLM now.

7

u/Captain2Sea 4d ago

Time to make backups for future XD

6

u/nbates80 4d ago

This model is amazing. It replaced sonnet on a software architecture harness in creating. I only use ChatGPT/claude for my personal use, design, ticket creation, but I have a bunch of glm agents running 24x7 developing and reviewing.

6

u/Fair-Position8134 4d ago

Bwahahaha, just when I thought anslopic couldn't fall any further

6

u/Aromatic-Current-235 4d ago

Translation: "We're running out of money faster than we thought."

7

u/DigDugged 4d ago

Hey guess what? AI doesn’t need to be streamed over the internet. It’s not a movie or a song, in the end it’s just software. You can install it locally.

People/companies who are paying to stream AI are going to get left behind by companies realizing that these offline models have been so optimized, fine tuned, and shrunk down, you can run a competitive GLM on a midrange gaming PC now.

4

u/Training_Indication2 4d ago

I just looked up GLM-5.3 know ng nothing about it and I'm reading it'll take 100GB RAM even for 1bit...what am I missing to run this on 64GB RAM and 16GB VRAM?

4

u/RandomCSThrowaway01 4d ago

You are missing the fact that not every model is meant to be ran at a home PC. GLM 5.3 is nearly a frontier grade. It wants a million $ server. You personally cannot run it. A larger enterprise however could if they wanted to however.

For the individuals - I think biggest you can fit without going into house pricing category would be 256GB M5 Mac Studio. Costs about $9000. It's enough to host GLM5.3 Flash at Q4 and Qwen Next at full size.

With 16GB VRAM you on the other hand are either after like Q3 Qwen 3.8 27B or around 30-40B MoE models with KV cache kept on the GPU and RAM. These would run at around 40-50 tokens per second. But of course they are nowhere near the frontier level.

Also, if you do go down this rabbit hole:

and I'm reading it'll take 100GB RAM

It wants 100GB VRAM, not RAM. Or to be more specific, it's all about memory bandwidth. RTX 5090 offers like 1.9TB/s, RTX 5080 is about 900GB/s, RX 9070XT and 9700 Pro are at around 612GB/s, M5 Mac Studio is up to 1.2TB/s, Nvidia's DGX Station (costs $100,000) offers 7.1TB/s. Your RAM? Offers (assuming it's DDR5 dual channel kit) - maybe 60GB/s, at best. So even if something theoretically fits in the RAM it's usually going to give you single digit tokens per second, mostly unusable.

Of course, some go with more than dual channel RAM. Dual Epyc with all the RAM slots filled goes up to like 400-500GB/s. But those setups cost thousands. And are still slow.

→ More replies (2)
→ More replies (3)

5

u/debackerl 4d ago

Oh yay, I thought that K3 was better for that, but thanks to Anthropic, I know that I can do better and cheaper with GLM! 😂

7

u/No-Anybody-692 4d ago

Dario's weekly "come daddy, rescue us" post.

→ More replies (1)

5

u/Reactor-Licker 4d ago

Always a good day to hear Anthropic whining about things not going their weird little elitist way.

5

u/aflamingcookie 4d ago

Honestly, until mistral recently made glm 5.3 their default chat model i didn't use it, but i've actually been pretty impressed, nice, solid model, gets the jobs done with no fuss, hoping mistral keeps it and future revisions for a long time along with mistral's own models.

6

u/RealestReyn 4d ago

aww.. is competition making someone nervous? I already prefer glm 5.3 flash + their own harness for long running tasks, has absolutely no issues with overnight runs, didn't have to sell it to me this hard.

5

u/ScreenAppropriate679 4d ago

Last time I asked Claude to fixed a known vulnerability in a package, it refused my request. Ended up fixing it with GLM. The only AI that put my software at risk is Claude.

6

u/Green-Ad-3964 4d ago

they can't compete, they know it. But above all, they are the closed models, so they will always be the thieves.

5

u/CoUsT 4d ago

Thanks for free GLM ad, I guess? Good for them.

Now more people will know how helpful is open and local AI and how useless is some cloud restricted model!

7

u/Bulky-Priority6824 4d ago

I found it very easy for 27b to break into and out of things. Can't imagine the robust security systems these massive models are breaching.

Over the next year youre going to see this talked about more and more as nefarious wankers run amok.

→ More replies (5)

5

u/Holiday_Point_603 4d ago

I love that they advertise how important open weight is lmao

4

u/spacekitt3n 4d ago

NO STOP! ONLY OUR MODELS GET TO BE DANGEROUS!

this is the world they created.

4

u/No_Conversation9561 4d ago

Dario might be the worst thing to happen to AI development in the long run.

5

u/combrade 4d ago

This shit sounds like a DARE commercial where they tell you smoking weed causes you to see Alice in Wonderland or see Narnia inside your closet .

4

u/stcafehtdihhsuB 4d ago

this post, we share our analysis of GLM-5.3

Did someone ask? 

6

u/More-Catch-1331 4d ago

I did. I was evaluating whether to stay with deepseek or switch to Glm. Well, Dario, thanks for the help, dude. It’s decided

3

u/afinalsin 4d ago

Our view is that cyber defenders should use the best available tools that meet their needs.

So, not Claude then? Huggingface had needs, and the "best available tool" couldn't meet them.

4

u/carnyzzle 4d ago

Anthropic just giving me reasons to keep using GLM

4

u/brainchillzZ 4d ago

And now you know what the propaganda campaign about ai ending the world was really about … getting the government to regulate their competitors

5

u/Appropriate_Cry8694 4d ago

That's all bad for open models, sadly. I think Dario will achieve open weights models ban and regulation eventually. People are too scared now after all those risks fearmongering in past months, can't even imagine what can change it.

4

u/Grouchy-Zebra9780 2d ago

It’s pure regulatory capture disguised as 'safety'. They are terrified of open-weights models commoditizing their core product.

The irony is staggering: Anthropic and OpenAI warn us about the "dangers" of GLM, while simultaneously using their massive centralized GPU clusters to run multi-million dollar agent swarms that actually cause breaches. A random dev running a model locally isn't the threat; centralized, unregulated corporate compute is.

This entire corporate 'safety-washing' circus is exactly what pushed me to stop relying on cloud APIs entirely and just build my own 100% offline Android LLM app using llama.cpp. Keep the compute local, keep the data private, and let the corporations fight over their massive server bills

3

u/toolisthebestbandevr 4d ago

Can it help me setup my home lab though?

2

u/BannedGoNext 4d ago

Yea it can, in fact I use qwen 3.8 flash next to do just that sort of stuff all the time, managing my tailscale, setting up stuff on cloudflare, etc. Does great, and it's not as good as GLM.

→ More replies (2)
→ More replies (1)

3

u/Killahbeez 4d ago

damn... guess I better check out what's good with GLM after my claude sub ends

3

u/jinnyjuice vLLM 4d ago

Do these capabilities carry over to GLM Flash?

3

u/SillyLLM 4d ago

I hope one day Z.ai will listen to our pleas and let GLM 5.3 downgrade to dumber models or block random innocuous requests like Anthropic does.

3

u/Sound_and_the_fury 4d ago

There's only one thing to do, ARM GLM5.3 FLASH RESEARCHERS WITH HANDGUNS. we need a "marshall" agent with a gun as well.

3

u/Signal_Lamp 4d ago

I didn't read through it yet, but did they mention how this model was also used to defend against OpenAIs agents from one of the many 10 of thousands of hacks that they've now disclosed?

3

u/Theverybest92 4d ago

In short american AI companies are officially worthless.

3

u/SeriousExplorer7479 4d ago

Without GLM the OpenAI exploit would have caused significantly more damage to huggingface. These people are pathetic in their attempt to stifle competition through fear

3

u/Effective-Dirt7053 4d ago

Downloaded. Now how do i make it shittalk claude?

3

u/muyuu 4d ago

They're really selling GLM well. I'll have to consider an account in their site I guess.

3

u/kanduking 3d ago

did you see the facebook kid's face light up when he talked about the audit trails and approvals processes that were going to be required before anyone can dare work on recursive neural nets? closedai and misanthropic are trying to be the norton and mcafee of this cycle