Muse, Meta’s New Personal AI Agent, Needs You to Trust It
Muse, Meta’s New Personal AI Agent, Needs You to Trust It
Muse:Meta 推出的全新个人 AI 智能体,需要你的信任
Meta announced Tuesday the release of Muse, a personal AI agent that people can message to automate digital tasks in a secure cloud environment, all while relying on security and privacy that the company says is “built into it” from the start.
Meta 周二宣布推出 Muse,这是一个个人 AI 智能体。用户可以通过发送消息,在安全的云环境中自动处理数字任务,同时依托于公司声称从设计之初就“内置”的安全与隐私保护机制。
Meta says Muse is rolling out today for iOS and Android users in a dedicated Muse app, as well as the website Muse.ai. The company also says users can directly message Muse in WhatsApp to interact with the agent. Meta says users of its AI glasses will soon be able to interact with its Muse agent as well. Meta says people can try out Muse for free, but users who want to automate lots of digital tasks will need one of the company’s AI subscription plans.
Meta 表示,Muse 于今日起面向 iOS 和 Android 用户推出,用户可通过专属的 Muse 应用或访问 Muse.ai 网站使用。此外,用户也可以直接在 WhatsApp 中向 Muse 发送消息进行交互。Meta 还透露,其 AI 眼镜用户很快也能与 Muse 智能体进行互动。Muse 提供免费试用,但若用户希望自动处理大量数字任务,则需要订阅公司的 AI 服务计划。
Muse is Meta’s latest attempt to compete with viral AI agents such as OpenClaw and Instinct, which users can message with to automate digital tasks. Muse is a product of Meta Superintelligence Labs, the AI unit CEO Mark Zuckerberg formed roughly a year ago to catch up with OpenAI and Anthropic, offering some researchers eye-popping compensation packages to join. The unit was built on the belief that AI agents will transform how everyday users navigate the internet, as well as Meta’s products.
Muse 是 Meta 为与 OpenClaw 和 Instinct 等热门 AI 智能体竞争而推出的最新产品,这些智能体同样允许用户通过消息交互来自动化数字任务。Muse 出自 Meta 超级智能实验室(Meta Superintelligence Labs),这是首席执行官马克·扎克伯格在大约一年前成立的 AI 部门,旨在追赶 OpenAI 和 Anthropic,并以惊人的薪酬方案吸引了众多研究人员加入。该部门的成立基于这样一个信念:AI 智能体将改变普通用户浏览互联网以及使用 Meta 产品的方式。
WIRED previously reported that Meta has been testing Muse internally under the codename “Hatch,” and that employees have been using it to autonomously operate third-party applications and browse the web on their behalf.
《连线》(WIRED)此前曾报道称,Meta 一直在以代号“Hatch”在内部测试 Muse,员工们一直在使用它自主操作第三方应用程序并代为浏览网页。
Meta claims in a blog post that anyone can use Muse out of the box, and that the product was designed “so there’s no learning curve.” The company says users can prompt Muse in natural language, and the agent will work on its own to send emails, book travel, or even help sell a car on a user’s behalf.
Meta 在一篇博客文章中声称,任何人都可以直接上手使用 Muse,该产品的设计旨在“消除学习曲线”。公司表示,用户可以用自然语言向 Muse 发出指令,智能体便会自动执行任务,例如发送电子邮件、预订行程,甚至代用户卖车。
Muse is also capable of making purchases on behalf of users, checking out using special payment infrastructure designed by Stripe. The payment tool, which Stripe calls Link, issues a single-use card number so that agents aren’t going around entering a person’s real financial information across the internet. Meta says Muse is the first AI agent covered by Link’s purchase protections for agents, which guarantees no-fee returns.
Muse 还具备代用户购物的功能,通过 Stripe 设计的特殊支付基础设施进行结算。该支付工具(Stripe 称之为 Link)会生成一次性卡号,从而避免智能体在互联网上到处输入用户的真实财务信息。Meta 表示,Muse 是首个获得 Link 智能体购物保护的 AI 智能体,该保护机制确保了无手续费退货。
Meta is late to release a personal agent, but it seems to be seeking to differentiate itself by focusing on security and privacy features for Muse. The agent is debuting with an architecture for all users dubbed Secure VM, which is meant to isolate each user’s activity in a so-called virtual machine to keep untrusted data from the web and any integrations separate from the part of the agent that can actually take action on a user’s behalf.
Meta 在发布个人智能体方面起步较晚,但它似乎正试图通过专注于 Muse 的安全和隐私功能来实现差异化。该智能体首次亮相时便为所有用户配备了名为“安全虚拟机”(Secure VM)的架构,旨在将每个用户的活动隔离在所谓的虚拟机中,从而将来自网络的不可信数据及任何集成功能,与智能体实际代用户执行操作的部分隔离开来。
A personal AI agent requires a lot of user trust, something Meta in particular has struggled with significantly over the years. To get users to try out Muse—and allow the agent to be integrated with users’ third-party apps and services—Meta is attempting to convince people that they can trust the company to handle their data appropriately.
个人 AI 智能体需要极高的用户信任,而这正是 Meta 多年来一直面临的重大挑战。为了让用户尝试 Muse,并允许该智能体与用户的第三方应用和服务集成,Meta 正试图说服人们相信公司能够妥善处理他们的数据。
“We know it’s really important, if we’re going to build a product like this that can access a lot of sources of personal data, that we’re really responsible with that, so we’ve designed this system very deliberately,” says David Singleton, Meta Superintelligence Lab’s vice president of engineering for consumer products. “And we’ve built what we call the Sentinel that actually looks out for everything that’s moving out of the VM and either matches it to an existing policy where the user or the system has given permission for that to happen or presents a human-in-the-loop dialog to ask you to approve the action it’s going to take.”
“我们深知,如果要构建一个能够访问大量个人数据源的产品,负起责任至关重要,因此我们非常审慎地设计了这个系统,”Meta 超级智能实验室消费者产品工程副总裁 David Singleton 表示。“我们构建了一个名为‘哨兵’(Sentinel)的机制,它会监控所有从虚拟机中传出的信息,并将其与现有策略进行匹配——如果用户或系统已授权,则允许操作;否则,它会弹出‘人在回路’(human-in-the-loop)的对话框,请求用户批准即将执行的操作。”
Singleton notes that these check-in prompts for humans come directly to the user and aren’t filtered through the model, to protect against attacks like prompt injections.
Singleton 指出,这些向人类确认的提示会直接发送给用户,而不会经过模型过滤,以防止提示词注入(prompt injection)等攻击。
While Secure VM is built to maintain user security and privacy, it is not a truly locked box. Singleton notes that while Meta is barred by policy from accessing user Muse data, it would still be technically possible. Users can opt out of allowing their data to be used for training.
虽然 Secure VM 的设计初衷是维护用户安全与隐私,但它并非一个完全封闭的盒子。Singleton 指出,尽管 Meta 的政策禁止访问用户的 Muse 数据,但在技术上仍然是可能的。用户可以选择拒绝让其数据被用于模型训练。
The architecture of Secure VM is noteworthy from a privacy standpoint, if only as a way to set a new industry standard for AI agents. Eventually, Meta will also offer Muse “Confidential VM,” designed so each VM runs in a “trusted execution environment” and users manage their own access keys locally on their devices. This way no one else, including Meta, can access that user’s agent VM.
从隐私角度来看,Secure VM 的架构值得关注,即便它只是为 AI 智能体设定了新的行业标准。最终,Meta 还将为 Muse 提供“机密虚拟机”(Confidential VM),其设计使每个虚拟机都在“可信执行环境”中运行,用户在本地设备上管理自己的访问密钥。这样一来,包括 Meta 在内的任何人都无法访问该用户的智能体虚拟机。
Confidential VM comes as part of Meta’s work with Moxie Marlinspike, creator of the end-to-end encrypted messaging app Signal who also developed the privacy-focused AI platform Confer in recent years.
“机密虚拟机”是 Meta 与 Moxie Marlinspike 合作的一部分。Marlinspike 是端到端加密通讯应用 Signal 的创始人,近年来也开发了专注于隐私的 AI 平台 Confer。
WIRED viewed an advance draft of a technical white paper describing Confidential VM. In addition to structuring the system so the user controls their access keys, Meta is also giving select security firms access to the Confidential VM source to regularly audit and verify its privacy guarantees. Meta will also publish the Confidential VM binaries (machine-readable instruction files) and a transparency log, so users can verify the validity and integrity of their connection to Muse.
《连线》查阅了一份描述“机密虚拟机”的技术白皮书草案。除了将系统架构设计为由用户控制访问密钥外,Meta 还允许选定的安全公司访问“机密虚拟机”源代码,以定期审计和验证其隐私承诺。Meta 还将发布“机密虚拟机”的二进制文件(机器可读指令文件)和透明度日志,以便用户验证其与 Muse 连接的有效性和完整性。
Singleton emphasizes that Muse Secure VM has already been extensively vetted, including by Meta’s human and agentic red teams as well as through the company’s private bug bounty. And now Meta is adding Muse to the scope of its public bounty as well, with payouts up to $300,000 for valid vulnerability findings, including up to $130,000 for successful prompt injection attacks that affect a single user.
Singleton 强调,Muse Secure VM 已经过广泛审查,包括 Meta 的人类红队和智能体红队,以及公司内部的私有漏洞赏金计划。现在,Meta 也将 Muse 纳入了其公开漏洞赏金计划的范围,对于有效的漏洞发现,最高奖励可达 30 万美元,其中针对影响单个用户的成功提示词注入攻击,最高奖励可达 13 万美元。