Adversaries Using Claude AI To Target Americans And Develop Missiles Is A Sign Of What’s To Come敌对势力利用克劳德人工智能系统瞄准美国人并研发导弹,这预示着未来可能发生的情况。
A new report from Anthropic presents a stark picture of how malign actors are using commercially available U.S. AI services despite safeguards.
新闻视频

By Joseph Trevithick
Published Sep 11, 2026 6:24 PM EDT
Houthi-controlled media
Earlier this year, an Iran-linked actor used Anthropic’s Claude artificial intelligence model to scrape and analyze data with the aim of helping target U.S. naval forces in the Middle East . A group in Yemen – very likely Iranian-backed Houthi militants – also used Claude to assist with work on guidance systems for ballistic and hypersonic missiles.
These are just some of the revelations about how adversaries and other malign actors have been using one of the premier pieces of AI software being developed in the United States that were contained in a new report Anthropic released late yesterday . The 154-page document also details instances where Claude was used directly and indirectly to support intelligence gathering and surveillance, cyberattacks, influence operations, and even worrisome biological research over the past eight months. In addition to Iran and Yemen, the human actors behind these activities were based in Russia, China, and a host of other countries.
Anthropic has shared details about what it calls the “misuse” of its models in the past , but describes the new report as its “most detailed” to date. The company has clearly been cataloging these case studies, and has assigned each one a control number. Though the entire contents of the report are cause for concern, the explicit attempt to use Claude to target American forces, as well as to develop new higher-end missiles and other military technology, are particular standouts and signs of what’s to come, as we will highlight below.
GTG-30005: Military reconnaissance
GTG-30005 is the case study dealing with the targeting of U.S. naval forces, and the summary is as follows:
“In another investigation, we identified and disrupted an Iran-nexus threat actor that used Claude to collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region. The threat actor used Claude to compile targeting handbooks, through a Python pipeline the threat actor built with Claude’s assistance, to identify and track naval positions based on open-source information. The compiled material included a roster of US personnel scraped from captions on public military photographs; publicly accessible ship and aircraft transponder identifiers; commercial satellite-imagery query scripts; and an inventory of public websites that exposed US naval movements. The threat actor also directed Claude to compile vulnerability research on shipboard systems, cataloging known CVEs in maritime VSAT terminals, Cisco communications equipment, and industrial control products.”
“We banned the actor’s account, developed detections to reduce the risk of future misuse, and shared threat intelligence with government authorities to disrupt the threat.”
The Nimitz class aircraft carrier USS George H.W. Bush and several other US Navy warships sail together in the Arabian Sea in June 2026. CENTCOM
How exactly Anthropic defines the term “nexus” here is not immediately clear, and other entries in its new report also use “state-nexus” in addition to country-based variations. However, in this specific case, an addendum is added to the entry that explicitly says that the same account was separately tied to “domestic mass surveillance” software development work “for Iranian state systems,” clearly pointing to an actor directly linked to the regime in Tehran.
Whether or not any of the data collected and analysed here was directly used to subsequently carry out attacks on U.S. forces is unknown. However, there have been media reports just in recent weeks that Iran has been increasingly trying to strike American warships . Those same reports have raised questions about how the country has been prosecuting those operations given its limited capabilities and capacity to track maritime targets far from its shores. The possibility that Russia or China could be supplying targeting data has been put forward.
The use of AI technology by nation-state armed forces to develop target sets and engage them is already known to be growing globally. The Israel Defense Forces (IDF) have been a pioneer in this regard , but the U.S. military , China’s People’s Liberation Army (PLA), and others are also known to be developing and fielding these capabilities.
U.S. military officials have also voiced increasing concern in recent years about the ability to track the movements and disposition of U.S. military assets and personnel using publicly available pictures and other data . There has been much talk, in turn, about how to balance transparency and operational security .
GTG-87001: Disrupting a Yemen-based guided weapons engineering cell using Claude to develop guidance software
Anthropic’s new report details an instance where an individual in Yemen used Claude as part of missile guidance work, which is given the control number GTG-87001.
“We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant.”
“The actors used Claude Code in place of human software engineers to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle. For example, they used Claude to integrate an open-source autopilot onto a phone-class flight computer, writing the control and position estimation software, tuning the control settings, running a firmware build pipeline, and performing a flight simulation. The actors managed several Claude instances at once, assigning each one a role, much as a lead would delegate work on a small engineering team: the actors tasked one instance with writing the code, another with research, and a third with reviewing the code the first instance produced.”
A graphic included in Anthropic’s new report summarizing the ways in which Claude was used by the actors in Yemen to support missile guidance system development. Anthropic
“Our safeguards blocked many of their requests, but not all of them. The actors used a variety of tactics to evade our safeguards, including hiding their goals and the products the software was meant for, and they split their work across multiple sessions so no single session revealed their full intent.”
“These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software. We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed.”
“We identified this activity as part of our internal investigations into suspected weapons development. We banned accounts associated with the actors and shared threat information with public- and private-sector partners to mitigate risks posed by the actors. Nevertheless, we have evidence that the actors had already built an offline simulation toolkit that does not rely on Claude or other engineering computing environments such as MATLAB.”
As mentioned earlier, the report does not name the Houthis, but that group has historically been based primarily in the northern end of Yemen. It is also the only entity in the country known to have active missile development programs , which are conducted with critical support from Iran.
Whether this particular work directly resulted in any new capabilities is unknown. Anthropic notes that there looked to be at least one failed test launch before the accounts were banned, which would have occured sometime after the beginning of this year, based on the stated cutoff dates for the report. By the end of 2025, the Houthis had already amassed a wide array of very real ballistic missiles , including types with at least claimed ranges of 2,000 kilometers (approximately 1,242 miles). The group also has a variety of cruise missiles and one-way attack drones that it has employed operationally.
An example of just one of the many types of ballistic missiles in the Houthis’ arsenal. Houthi-controlled media
Still, being able to leverage Claude could only have helped any domestic missile development efforts in Yemen, which might help reduce dependency on Iran, at least to a degree. Furthermore, developing functional hypersonic glide vehicles capable of prolonged stable flight has historically been notoriously difficult, even for entities with extensive relevant knowledge bases on an organizational level.
GTG-17001: Disrupting a China-based operation using Claude to draft a fire control specification and acquisition documents for undersea warfare
Use of Claude in foreign military endeavours goes beyond the Middle East, as evidenced by case study GTG-17001. This involved a Chinese actor conducting work related to a naval counter-torpedo defense system.
“We identified a China-based threat actor who used Claude to advance three parallel tracks of work on an anti-torpedo weapons system:”
“First, the actor used Claude to draft a Chinese-language specification for an anti-torpedo fire control system (the core logic that aims and times an anti-torpedo weapon’s response). The document was written to win approval from a Chinese defense manufacturer, which would move the work on to technical certification and operational testing.”
“Second, the actor used Claude to produce a Chinese-language technical proposal of more than 200 pages, accompanied by an executive briefing deck.”
“Third, the actor used Claude to benchmark their own system against specific US anti-torpedo and anti-submarine programs based on publicly accessible information. They then generated a Chinese-language briefing on US Navy systems derived from open-source reporting.”
“The actor presented themselves as an original equipment manufacturer in the US defense sector. We assess the actor was associated with a Chinese defense industry manufacturer aiming to produce a weapons specification and acquisition proposal for the People’s Liberation Army Navy.”
This picture shows a test of an anti-torpedo system fitted experimentally to a Nimitz class aircraft carrier in the 2010s. USN
“The actor used Claude to write the acquisition proposal, refining it over many drafts. After each draft, the actor instructed Claude to role-play a hostile expert reviewer to critique the proposal, then used that feedback to sharpen the next version. In parallel, the actor used Claude to build pieces of the anti-torpedo weapons system’s fire control software and a test matrix to validate them.”
“The operational lift the actor achieved was a function of using Claude to automate complex technical outputs. The actor leveraged the model to compress the development timelines for the certification registry, compliance documentation, and automated fire control logic. The actor also accelerated the traditional human review cycle by having Claude critique the acquisition proposal across multiple rounds of review while role-playing a persona.”
“We uncovered this activity as part of our internal investigations into suspected weapons development. We cannot attribute the activity to a specific entity or actor. But we have banned the account for violating our Supported Regions Policy and our Usage Policy, which prohibits weapons design and development, and incorporated our investigative findings into our safeguards to mitigate the risk of future misuse.”
Anthropic’s report does not name the US programs leveraged here, but does note the information in question was publicly available. Anti-torpedo systems for surface warships and submarines have been an area of significant interest for the U.S. Navy for years now . Those developments have also produced compact torpedo designs for use in other applications.
A Very Lightweight Torpedo (VLT), a compact torpedo design developed by Northrop Grumman. Northrop Grumman
The PLAN’s interest in these same kinds of capabilities is not at all surprising. Underwater threats and countermeasures to them, broadly speaking, would play a central and vital role in any future conflict between the United States and China across the broad expanses of the Pacific.
GTG-27005: Disrupting a Russia-based operation using Claude to engineer an autonomous military drone swarm
Another case study, GTG-17001, details the use of Claude by Russian actors working on drone swarming technology.
“We identified likely freelance Russia-based threat actors who set out to build a full-stack autonomous first-person-view (FPV) kamikaze drone swarm. The actors used Claude Code to write and test the code and save it directly into the actors’ own project files. In addition to Claude Code, the actors used a software-in-the-loop simulation stack and a rented graphics processing host for model training. They called the operation ‘DronDoc’ or ‘Serafim.'”
“The actors used Claude to build the core software system, including the drones’ shared swarm memory and fault-tolerant coordination logic (FTCL); an onboard small language model to govern attack, observe, and return-to-base behaviors; a terminal guidance software system to steer drones to their target (using the onboard camera) and issue the call to detonate; a control-link geolocation module to find opposing drone operators; a passive acoustic detection layer; and low-level logic for the drones’ programmable chips. The actors designed the platform for autonomous lethal engagement; the onboard model could select targets (including a ‘person’ target class) and issue detonation commands without a human in the loop. The actors’ activity—including flashing the low-level firmware to live development boards, provisioning single-board computers, and wiring up a simulation environment over a mesh network—confirmed that they were using real hardware-in-loop testing within their sessions.”
Many were surprised yesterday by the news that a Russian fiber-optic FPV drone flew into Kramatorsk and attacked a car. But there is nothing surprising here. The war of 2025 is already very different from the war of 2024. From LBZ to Kram — 20 kilometers. Enemy FPVs can fly even… pic.twitter.com/hTfhJFPcxZ — Richard Woodruff 🇺🇦 (@frontlinekit) October 6, 2025
Many were surprised yesterday by the news that a Russian fiber-optic FPV drone flew into Kramatorsk and attacked a car. But there is nothing surprising here. The war of 2025 is already very different from the war of 2024. From LBZ to Kram — 20 kilometers. Enemy FPVs can fly even… pic.twitter.com/hTfhJFPcxZ
“The actors trained a computer vision classifier on scraped Ukrainian combat footage, splitting the target classes into “enemy” and “friendly,” and allow-listing Russian systems. They also repeatedly used a fixed coordinate in Donetsk Oblast as the demonstration strike point, with front-line cities and corridors in Ukraine as the mission geography.”
“The actors created their accounts between late 2025 and early 2026 and started the operation in mid-May 2026. The actors circumvented our geographic access controls by routing traffic through commercial virtual private servers.”
“We assess the actors were a small, specialized freelance team doing a mix of civilian and military work, not a Russian state entity. We identified nine accounts associated with this group; eight were used only for ordinary freelance work, not weapons-related software development. Based on our investigation, we assess the actors had ties to a regional university with a federal research center associated with the Russian Academy of Sciences. The actors claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative, and Ministry of Defence, though we cannot verify those claims. We identified this activity as part of our internal investigations into suspected weapons development, we banned accounts associated with the actors, and have incorporated our investigative findings into safeguards to reduce the risk of future misuse.”
Anthropic’s report included a table, reproduced below, detailing different types of drones and other capabilities that were fed into the model as part of this work.
Also, while Anthropic said it could not confirm any direct ties in this instance to the Russian government, the work described here is fully in line with capabilities that have already been demonstrated to varying degrees in Ukraine in the past few years . TWZ has been very closely tracking developments on both sides of the conflict when it comes to new automated targeting and swarming capabilities for shorter- and longer-ranged kamikaze drones. In 2024, we also published a detailed feature outlining a coming revolution in drone warfare, signs of which were already emerging then, thanks to AI and the ever-lowering barrier to entry to leveraging that technology.
GTG-17002: Disrupting a China-based operation using Claude to build targeting software for electronic warfare and air defense suppression
The last case study in the Conventional Weapons section of Anthropic’s new report, GTG-17002, covers electronic warfare-related work by a Chinese actor, with a particular focus on potential air defense targets in Taiwan.
“We identified a China-based actor who used Claude’s chat, coding, and agentic work tools to design, build, and iterate on a Chinese-language suite of about 16 modules for electronic warfare, using the electromagnetic spectrum to detect, jam, or deceive an opponent’s radar and communications, and for suppressing an opponent’s air defenses.”
“The actor used Claude to build the software system, from the underlying logic to the user interface, and iterated through 12 versions. This included implementing and optimizing the system’s radar detection and jamming physics, generating a vulnerability analysis module, and drafting Chinese-language targeting instructions. The software suite the actor built analyzed an opponent’s radars, surface-to-air missile sites, command posts, and communications nodes, then computed their detection coverage, assessed the effectiveness of jamming, ranked targets by value and vulnerability, including which to suppress first, and determined how best to assign jammer sorties to targets across multi-day campaigns. The suite also ranked which of an opponent’s assets to suppress first, and modeled specific engagement envelopes, including those of Patriot and THAAD-class [ Terminal High Altitude Area Defense ] systems.”
“Mid-project, we observed the actor change the simulation’s default scenario to 12 targets in Taiwan. The targets included a command bunker in Taiwan, an early warning radar site, Patriot and Tien Kung [surface-to-air missile] batteries, major air bases, and a regional combatant command headquarters.”
“The actor also ran a self-hosted model on an internal network alongside Claude and connected the software suite to this model through a tool-use integration.”
“Based on our investigation, we assess the actor is a China-based defense and military-industrial researcher. Account-level metadata and content flagged by our safeguards indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences. We detected this activity as part of our internal investigations into suspected weapons development, we banned accounts linked to the actor, and have incorporated our investigative findings into our safeguards to reduce the risk of future misuse.”
An accompanying table, seen below, mentions several specific types of U.S.-made air defense radars, as well as the Link-16 datalink network, as having come up in the course of this work. Electronic warfare variants of the Chinese Y-8 and Y-9 aircraft , as well as the J-16D electronic warfare jet, and what appears to be a reference to the Golden Eagle drone helicopter , are also mentioned.
A Chinese Y-8GX-11, one of several electronic warfare variants of the Y-8/Y-9 design. Chinese internet via X
The suppression of enemy air defenses is an essential part of any modern air campaign, whether conducted independently or as a part of a larger operation. This would be no less critical in any military intervention against Taiwan from the mainland , or any other larger-scale conflict the PLA might find itself in.
Guardrails and ethics
Beyond the details in any of the specific case studies, Anthropic’s new report underscores growing broader concerns about guardrails for the use of AI and general ethics surrounding the technology. As noted in the instances above, Anthropic has also implemented various safeguards to try to block access to Claude from certain regions and/or to prevent the model from conducting certain types of work. At the same time, what the company has now shared makes clear that those protections can still be circumvented to a significant degree, at least for now.
For its part, Anthropic has been publicly supportive of transparency laws and regulation , at least within the United States. The company also notably made tweaks to certain Claude models earlier this year to address U.S. government cybersecurity concerns.
Starting in December 2025, Anthropic has also been very publicly embroiled in a dispute with the Pentagon over the potential use of Claude to support mass surveillance and fully autonomous weapon systems . This subsequently led to the company being designated a supply chain risk , and limitations being imposed on the use of that model within the U.S. military and elsewhere across the U.S. government. Anthropic is continuing to fight that action in court . However, just yesterday, Under Secretary of Defense for Research and Engineering and the Pentagon Chief Technology Officer Emil Michael said the U.S. military had scaled back the use of Anthropic’s products in support of classified work by 90 percent.
Anthropic is still a designated Supply Chain Risk at @DeptofWar and for the Defense Industrial Base. Thank you for your attention to this matter! — Under Secretary of War Emil Michael (@USWREMichael) September 3, 2026
Anthropic is still a designated Supply Chain Risk at @DeptofWar and for the Defense Industrial Base. Thank you for your attention to this matter!
The concerns about ‘misuse’ outlined in Anthropic’s new report apply, in general terms, to publicly accessible models being developed by other companies, too. There have already been publicly disclosed instances of AI agents themselves engaging in hacking and other malign behavior in order to complete assigned tasks, raising additional questions about security and public safety , not to mention ethics.
TWZ has noted in the past that America’s adversaries are likely to be less worried about ethics, in general, when it comes to AI. Anthropic’s new report also shows there are few bounds to what state-aligned or even non-state actors might seek to use this technology for, including the development of potential weapons of mass destruction.
At the same time, AI models like Claude are not going away, and developments continue to advance at an ever-quickening pace, opening the door to further proliferation. Developments are rapidly intermingling globally, with companies in China notably leveraging models created in the U.S. to further their own work, which is then released publicly. The technology will increasingly become more integrated and critical to most aspects of military operations and weapons development, alongside its commercial and civilian applications. It is just as much a superweapon as anything else, and the country with the more capable models, and the willingness to deploy them, will have a major edge in future conflicts.
With all this in mind, it seems very plausible, if not probable, that the case studies described in Anthropic’s new report are just the tip of an approaching iceberg that will need concerted effort to tackle.
Contact the author: joe@twz.com
Comments couldn’t be loaded. Please refresh the page.
作者:约瑟夫·特雷维西克
发布于美国东部时间2026年9月11日下午6:24
胡塞武装控制的媒体
今年早些时候,一个与伊朗有关联的组织利用Anthropic公司的Claude人工智能模型抓取和分析数据,旨在帮助其攻击驻中东的美国海军部队。也门的一个组织——很可能是受伊朗支持的胡塞武装——也利用Claude协助开发弹道导弹和高超音速导弹的制导系统。
以上只是Anthropic公司昨日晚间发布的一份新报告中披露的部分内容,揭示了敌对势力和其他恶意行为者如何利用美国正在开发的一款顶尖人工智能软件。这份长达154页的报告还详细描述了过去八个月中,Claude如何被直接或间接地用于支持情报收集和监视、网络攻击、影响力行动,甚至令人担忧的生物研究。除了伊朗和也门之外,这些活动背后的操纵者还来自俄罗斯、中国以及其他许多国家。
安特罗皮克公司过去曾披露过其模型被“滥用”的情况,但称这份新报告是迄今为止“最详尽”的。该公司显然一直在收集这些案例研究,并为每个案例分配了一个编号。尽管报告的全部内容都令人担忧,但其中明确提及的利用“克劳德”模型攻击美军、研发新型高端导弹和其他军事技术等行为尤为突出,也预示着未来可能发生的情况,我们将在下文中重点阐述。
GTG-30005:军事侦察
GTG-30005 是关于美国海军部队目标定位的案例研究,摘要如下:
在另一项调查中,我们发现并捣毁了一个与伊朗有关联的威胁行为体。该行为体利用 Claude 收集和分析公开数据,以制定针对该地区美国海军部队的攻击目标建议。该威胁行为体利用 Claude 编写目标手册,并通过其在 Claude 协助下构建的 Python 管道,基于开源信息识别和追踪海军位置。收集到的材料包括:从公开军事照片的说明文字中提取的美国人员名册;公开的舰船和飞机应答器标识符;商业卫星图像查询脚本;以及一份公开美国海军动向的网站清单。该威胁行为体还指示 Claude 对舰载系统进行漏洞研究,并对海上 VSAT 终端、思科通信设备和工业控制产品中已知的 CVE 进行编目。
“我们封禁了该用户的账号,开发了检测机制以降低未来滥用的风险,并与政府部门共享了威胁情报,以阻止威胁的发生。”
2026年6月,尼米兹级航空母舰“乔治·H·W·布什”号及其他几艘美国海军军舰在阿拉伯海联合航行。(中央司令部)
人类学研究所(Anthropic Institute)在此处对“关联”(nexus)一词的具体定义尚不明确,其新报告中的其他条目除了基于国家的变体外,还使用了“国家关联”(state-nexus)一词。然而,就此特定案例而言,该条目添加了一条附录,明确指出同一账户还与“伊朗国家系统”的“国内大规模监控”软件开发工作有关联,这显然指向了与德黑兰政权直接相关的行为体。
目前尚不清楚此处收集和分析的数据是否直接用于随后对美军发动袭击。然而,近几周来,媒体报道称伊朗正日益频繁地试图袭击美国军舰。这些报道也引发了人们的质疑:鉴于伊朗追踪远离海岸的海上目标的能力有限,它是如何开展这些行动的?有人提出,俄罗斯或中国可能提供了目标数据。
各国武装部队利用人工智能技术制定目标并执行作战任务的现象已在全球范围内日益增多。以色列国防军(IDF)在这方面一直处于领先地位,但美国军方、中国人民解放军(PLA)和其他一些国家也在开发和部署这些能力。
近年来,美国军方官员越来越担心,利用公开图片和其他数据追踪美国军事资产和人员的动向和部署情况。由此,如何平衡透明度和作战安全成为人们热议的话题。
GTG-87001:利用 Claude 系统破坏也门一家制导武器工程部门的制导软件开发
人类学研究所的新报告详细描述了也门一名个人使用 Claude 进行导弹制导工作的案例,该导弹的控制编号为 GTG-87001。
“我们发现一个位于也门北部的威胁行为体小组正在开展三个武器研发项目:一种使用商用手机级飞行计算机进行末级寻的制导火箭;一种射程目标超过 2000 公里的多级弹道导弹;以及一种多变型导弹(称为“R2000”系列),其中包括一种高超音速滑翔飞行器变型。”
“参与者们使用 Claude Code 代替人类软件工程师来开发用于控制和稳定飞行器的制导、导航和控制 (GNC) 软件。例如,他们使用 Claude 将开源自动驾驶仪集成到手机级飞行计算机上,编写控制和位置估计软件,调整控制设置,运行固件构建流程,并进行飞行模拟。参与者们同时管理多个 Claude 实例,并为每个实例分配任务,就像领导在小型工程团队中分配工作一样:参与者们指派一个实例编写代码,另一个进行研究,第三个审查第一个实例编写的代码。”
安特罗皮克公司最新报告中的一张图表总结了也门各方如何利用克劳德导弹来支持导弹制导系统的研发。
“我们的安全措施阻止了他们的许多请求,但并非全部。这些攻击者使用了多种策略来规避我们的安全措施,包括隐藏他们的目标和软件的目标产品,并且他们将工作分散到多个会话中,因此任何单个会话都无法完全暴露他们的意图。”
“这些行动者持续致力于研发制导武器,包括利用克劳德设计制导软件。我们没有证据表明他们成功部署了可操作的装置;但他们确实试射了一枚制导火箭。这次实地测试似乎失败了:几个小时后,这些行动者就返回克劳德,试图找出失败的原因。”
“我们在对疑似武器研发活动进行内部调查时发现了这一活动。我们封禁了与这些行为者相关的账户,并与公共和私营部门的合作伙伴共享了威胁信息,以降低这些行为者构成的风险。尽管如此,我们仍有证据表明,这些行为者已经构建了一个离线仿真工具包,该工具包不依赖于 Claude 或其他工程计算环境,例如 MATLAB。”
如前所述,该报告并未点名胡塞武装,但该组织历来主要盘踞在也门北部。它也是该国唯一已知拥有活跃导弹研发项目的组织,而这些项目得到了伊朗的关键支持。
这项工作是否直接催生了任何新的能力尚不得而知。Anthropic 指出,在这些账户被封禁之前,似乎至少进行过一次失败的试射,根据报告中列出的截止日期,试射应该发生在今年年初之后。到 2025 年底,胡塞武装已经积累了种类繁多的、极具实战能力的弹道导弹,其中包括一些据称射程至少达到 2000 公里(约 1242 英里)的导弹。该组织还拥有多种巡航导弹和单向攻击无人机,并已将其投入实战。
这是胡塞武装武器库中众多弹道导弹类型中的一种示例。胡塞武装控制的媒体
尽管如此,利用“克劳德”导弹无疑有助于也门国内导弹研发工作,这或许能在一定程度上减少也门对伊朗的依赖。此外,研发能够长时间稳定飞行的实用型高超音速滑翔飞行器历来都极其困难,即使对于那些在组织层面拥有广泛相关知识储备的机构而言也是如此。
GTG-17001:干扰中国利用克劳德系统起草水下作战火控规范和采购文件的行动
Claude 在外国军事行动中的应用范围已超出中东,案例研究 GTG-17001 就证明了这一点。该案例涉及一名中国参与者开展与海军反鱼雷防御系统相关的工作。
“我们发现了一个位于中国的威胁行为者,他利用 Claude 推进了反鱼雷武器系统的三项平行研发工作:”
“首先,这位演员利用克劳德起草了一份中文版的反鱼雷火控系统技术规范(该系统是控制反鱼雷武器瞄准和反应时间的核心逻辑)。这份文件的目的是为了获得一家中国国防制造商的批准,以便推进技术认证和作战测试阶段的工作。”
“其次,这位演员利用克劳德制作了一份超过 200 页的中文技术方案,并附有高管简报。”
“第三,该演员利用克劳德号潜艇,根据公开信息,将他们自己的系统与美国特定的反鱼雷和反潜项目进行对比。然后,他们根据开源报告,制作了一份关于美国海军系统的中文简报。”
“该行为者自称是美国国防部门的原始设备制造商。我们评估认为,该行为者与一家中国国防工业制造商有关联,其目的是为中国人民解放军海军制定武器规格和采购方案。”
这张照片显示的是2010年代在一艘尼米兹级航空母舰上试验性安装的反鱼雷系统测试。美国海军
“这位演员利用克劳德撰写采购提案,并经过多次修改完善。每次修改后,演员都会指示克劳德扮演一位持反对意见的专家评审员,对提案进行批评,然后利用这些反馈来改进下一版本。与此同时,这位演员还利用克劳德构建了反鱼雷武器系统火控软件的部分组件以及用于验证这些组件的测试矩阵。”
“该机构取得的运营效率提升得益于利用 Claude 实现复杂技术输出的自动化。该机构利用该模型缩短了认证注册、合规性文档和自动化火控逻辑的开发周期。此外,该机构还通过让 Claude 在多轮审查中扮演特定角色,对采购方案进行评估,从而加快了传统的人工审查流程。”
“我们在对疑似武器研发活动进行内部调查时发现了这一活动。我们无法将该活动归咎于特定实体或行为者。但我们已封禁该账户,因为它违反了我们的支持区域政策和使用政策(该政策禁止武器设计和研发),并将我们的调查结果纳入了安全措施,以降低未来滥用的风险。”
人类学研究所的报告并未指明此处所利用的美国项目,但指出相关信息是公开的。多年来,美国海军一直对水面舰艇和潜艇的反鱼雷系统给予了高度关注。这些研发成果也催生了可用于其他用途的紧凑型鱼雷设计。
超轻型鱼雷(VLT),是由诺斯罗普·格鲁曼公司开发的一种紧凑型鱼雷设计。
中国海军对这类能力的兴趣并不令人意外。总的来说,水下威胁及其应对措施将在未来中美两国在广阔的太平洋地区发生的任何冲突中发挥核心和至关重要的作用。
GTG-27005:利用克劳德干扰俄罗斯的自主军事无人机集群行动
另一项案例研究 GTG-17001 详细介绍了俄罗斯从事无人机集群技术研究的人员如何使用 Claude。
“我们发现了一些可能位于俄罗斯的自由职业威胁行为者,他们试图构建一个全栈式自主第一人称视角(FPV)自杀式无人机群。这些行为者使用 Claude Code 编写和测试代码,并将其直接保存到他们自己的项目文件中。除了 Claude Code 之外,他们还使用了软件在环仿真堆栈和租用的图形处理主机进行模型训练。他们将此次行动称为‘DronDoc’或‘Serafim’。”
“参与者利用Claude构建了核心软件系统,包括无人机的共享集群记忆和容错协调逻辑(FTCL);用于控制攻击、观察和返航行为的机载小型语言模型;用于引导无人机飞向目标(利用机载摄像头)并发出引爆指令的终端制导软件系统;用于定位敌方无人机操作员的控制链路地理定位模块;被动声学探测层;以及无人机可编程芯片的底层逻辑。参与者设计的平台用于自主致命打击;机载模型无需人工干预即可选择目标(包括‘人员’目标类别)并发出引爆指令。参与者的活动——包括将底层固件刷写到开发板上、配置单板计算机以及通过网状网络搭建模拟环境——证实了他们在实验过程中使用了真实的硬件在环测试。”
昨天,一架俄罗斯光纤FPV无人机飞入克拉马托尔斯克并袭击了一辆汽车,这一消息令许多人感到惊讶。但其实这并不奇怪。2025年的战争与2024年的战争已经截然不同。从LBZ到克拉马托尔斯克只有20公里。敌方的FPV无人机甚至可以飞得更远…… pic.twitter.com/hTfhJFPcxZ — Richard Woodruff 🇺🇦 (@frontlinekit) October 6, 2025
昨天,一架俄罗斯光纤FPV无人机飞入克拉马托尔斯克并袭击了一辆汽车,这一消息令许多人感到惊讶。但其实这并不奇怪。2025年的战争与2024年的战争已经截然不同。从LBZ到克拉马托尔斯克只有20公里。敌方的FPV无人机甚至可以飞得更远…… pic.twitter.com/hTfhJFPcxZ
“演习人员利用从乌克兰战场上搜集的战斗录像训练了一个计算机视觉分类器,将目标分为‘敌方’和‘友方’两类,并将俄罗斯系统列入允许名单。他们还反复使用顿涅茨克州的一个固定坐标作为演示打击点,以乌克兰的前线城市和走廊作为任务地理区域。”
“这些攻击者在 2025 年末至 2026 年初期间创建了账户,并于 2026 年 5 月中旬开始实施攻击。他们通过商业虚拟专用服务器路由流量,绕过了我们的地理访问控制。”
“我们评估认为,涉事人员是一个小型、专业的自由职业团队,从事民用和军用混合工作,并非俄罗斯国家实体。我们发现了与该团队相关的九个账户;其中八个仅用于普通的自由职业工作,而非武器相关软件开发。根据我们的调查,我们评估认为,涉事人员与一所隶属于俄罗斯科学院的联邦研究中心所在的地区性大学存在关联。涉事人员声称曾获得俄罗斯高级研究基金会、国家技术倡议组织和国防部的资助,但我们无法核实这些说法。我们在对涉嫌武器开发的内部调查中发现了这一活动,并已封禁了与涉事人员相关的账户,并将调查结果纳入安全措施,以降低未来滥用风险。”
Anthropic 的报告中包含一个表格(如下所示),详细列出了作为这项工作的一部分输入到模型中的不同类型的无人机和其他功能。
此外,尽管Anthropic公司表示无法证实此次事件与俄罗斯政府存在任何直接联系,但此处描述的工作与过去几年在乌克兰不同程度上已展示的能力完全一致。TWZ一直密切关注冲突双方在新型自动化目标定位和集群作战能力方面的进展,这些能力涵盖了短程和远程自杀式无人机。2024年,我们也曾发表一篇专题文章,详细阐述了无人机战争即将发生的革命,而当时,由于人工智能的出现以及该技术准入门槛的不断降低,这场革命的迹象已经显现。
GTG-17002:干扰中国境内利用Claude系统开发用于电子战和防空压制的目标定位软件的行动
人类学研究所新报告 GTG-17002 中常规武器部分的最后一个案例研究涵盖了中国某势力开展的电子战相关工作,尤其关注台湾潜在的防空目标。
“我们发现一名中国境内的攻击者利用 Claude 的聊天、编码和代理工作工具,设计、构建并迭代了一套约 16 个模块的中文电子战软件套件,该套件利用电磁频谱来探测、干扰或欺骗对手的雷达和通信,并压制对手的防空系统。”
该行动者利用Claude软件构建了这套系统,从底层逻辑到用户界面,共迭代了12个版本。这包括实现和优化系统的雷达探测和干扰物理特性,生成漏洞分析模块,以及编写中文目标指示。该行动者构建的软件套件能够分析对手的雷达、地对空导弹阵地、指挥所和通信节点,计算其探测覆盖范围,评估干扰效果,根据目标的价值和脆弱性对其进行排序(包括优先压制目标),并确定如何在多日作战行动中最佳地分配干扰机出动次数。该套件还能对优先压制对手的哪些资产进行排序,并模拟特定的交战范围,包括爱国者导弹和萨德(末段高空区域防御系统)的交战范围。
“项目进行到一半时,我们发现对方将模拟的默认场景更改为台湾境内的 12 个目标。这些目标包括台湾境内的一个指挥掩体、一个预警雷达站、爱国者和天宫地空导弹阵地、主要空军基地以及一个区域作战司令部。”
“这位演员还与克劳德一起在内部网络上运行了一个自托管模型,并通过工具使用集成将软件套件连接到该模型。”
“根据我们的调查,我们评估该行为者是一名在中国从事国防和军工研究的研究人员。账户级别的元数据和我们安全措施标记的内容表明,该行为者与包括解放军军事科学院在内的中国研究机构有关联。我们在对疑似武器研发活动进行内部调查时发现了这一活动,我们已封禁了与该行为者相关的账户,并将调查结果纳入我们的安全措施,以降低未来滥用风险。”
下表列出了在本次研究过程中涉及的几种美国制造的防空雷达以及Link-16数据链网络。此外,表中还提到了中国的运-8和运-9电子战飞机的电子战改型、歼-16D电子战飞机,以及疑似“金鹰”无人直升机。
中国产Y-8GX-11,是Y-8/Y-9系列电子战衍生型号之一。图片来自中国互联网(X)。
无论独立作战还是作为更大规模行动的一部分,压制敌方防空系统都是现代空袭行动的重要组成部分。这一点在大陆对台军事干预,或解放军可能卷入的任何其他更大规模冲突中,都同样至关重要。
护栏与伦理
抛开具体案例研究的细节不谈,Anthropic 的这份新报告凸显了人们对人工智能使用监管以及相关伦理问题的日益关注。正如上文所述,Anthropic 也已实施多项安全措施,试图阻止某些地区访问 Claude,或阻止该模型从事某些类型的工作。然而,该公司目前披露的信息表明,至少就目前而言,这些保护措施仍有很大程度的漏洞可钻。
Anthropic公司一直公开支持透明度法律法规,至少在美国是如此。值得一提的是,该公司今年早些时候还对部分Claude系列产品进行了调整,以回应美国政府对网络安全的担忧。
自2025年12月起,Anthropic公司与五角大楼就其Claude无人机可能用于支持大规模监控和全自动武器系统的问题,公开陷入争议。随后,该公司被认定为供应链风险企业,其产品在美国军方及美国政府其他部门的使用也受到限制。Anthropic公司仍在法庭上就此进行抗争。然而,就在昨天,负责研究与工程的国防部副部长兼五角大楼首席技术官埃米尔·迈克尔表示,美军已将Anthropic公司产品在机密工作中的使用量减少了90%。
Anthropic公司仍被美国陆军部和国防工业基地认定为供应链风险企业。感谢您对此事的关注!——美国陆军部副部长埃米尔·迈克尔(@USWREMichael)2026年9月3日
Anthropic公司仍被美国战争部和国防工业基地认定为供应链风险企业。感谢您对此事的关注!
Anthropic公司新报告中提出的关于“滥用”的担忧,总体而言也适用于其他公司开发的公开模型。此前已有公开披露的案例表明,人工智能代理为了完成指定任务,会进行黑客攻击和其他恶意行为,这引发了人们对安全性、公共安全以及伦理道德的更多担忧。
TWZ此前曾指出,美国的对手在人工智能领域通常不太关注伦理问题。Anthropic的最新报告也显示,无论是国家行为体还是非国家行为体,都可能利用这项技术从事各种活动,包括研发潜在的大规模杀伤性武器,而这些活动几乎没有任何限制。
与此同时,像克劳德这样的AI模型并不会消失,其发展速度仍在不断加快,为进一步扩散打开了大门。全球范围内,这些模型正迅速融合,尤其值得注意的是,中国企业正在利用美国开发的模型来推进自身研发,并将成果公之于众。这项技术将日益融入军事行动和武器研发的各个方面,并发挥其在商业和民用领域的重要性。它本身就是一种超级武器,拥有更先进模型并愿意部署这些模型的国家,将在未来的冲突中占据巨大优势。
考虑到所有这些因素,即使不是必然,也很有可能 Anthropic 新报告中描述的案例研究只是冰山一角,而要解决这个冰山需要各方共同努力。
联系作者:joe@twz.com
评论加载失败,请刷新页面。