← 返回 Avalaches

研究显示一家 AI 图像生成初创公司的未设防数据库暴露了约 1,099,985 条记录,超过 100 万张图像与视频,几乎全部为色情内容,其中包括真实人物被非自愿“裸化”、换脸至裸露身体的素材,以及疑似未成年人的 AI 生成或高度写实图像。研究者指出数据库每日新增约 10,000 张图像,并且这是今年发现的第三个存在非自愿露骨内容的误配置 AI 图像数据库,反映“nudify”服务生态规模巨大、应用量达数百万并带来年度营收达数百万美元,同时与过去一年犯罪分子使用 AI 生成儿童性虐待材料的报告翻倍趋势一致。

数据库与 MagicEdit、DreamPal 等网站关联,这些产品被下线或暂停功能,并被其运营方 DreamX 声称属于“遗留资产”。多家相关实体相互否认运营关联,但数据库中包含 SocialBook 水印页面的记录。Google 与 Apple 均确认已因违反政策将 BoostInsider 名下的相关应用移除。研究者向美国全国失踪与受剥削儿童中心举报,尽管无法确定数据库暴露持续时间,其内容全部为图像或视频文件,且包含疑似未成年人露骨描绘。

DreamX 对外表示已关闭数据库访问、启动内部与外部法律调查,并强化内容审核。MagicEdit 网站的工具包括“AI Clothes”“face swap”等模式,其展示的多种生成风格明显性化女性,评级为 18+。研究者指出此类服务可被用于勒索、骚扰与更广泛的技术性暴力,依赖用户自我声明同意不足以防止滥用。专家认为此事件体现初创公司在信任、安全与儿童保护上的结构性失范,AI 进一步加剧了女性与女孩被性化及被控制的既有社会问题。

Research shows that an unsecured AI image generator startup’s database exposed approximately 1,099,985 records, revealing more than one million images and videos, almost all pornographic, including real people who were nonconsensually “nudified,” face-swapped onto nude bodies, and AI-generated or hyperrealistic depictions of apparent minors. The database was receiving about 10,000 new images per day, and this was the third misconfigured AI-image database found this year containing nonconsensual explicit content. The findings align with the scale of “nudify” services used by millions and generating millions of dollars annually, as well as reports that AI-generated child sexual abuse material incidents have doubled over the past year.

The database was linked to MagicEdit, DreamPal, and other sites that were subsequently removed or suspended, with operator DreamX attributing the exposed content to “legacy assets.” Multiple entities denied operational involvement, although SocialBook watermarked materials appeared in the dataset. Google and Apple confirmed removing BoostInsider-listed apps for policy violations. The researcher reported the exposed dataset to the US National Center for Missing and Exploited Children. The duration of exposure is unknown, but the trove consisted solely of image and video files, including explicit depictions of apparent underage individuals.

DreamX states it closed access, initiated internal and external legal investigations, and strengthened moderation. MagicEdit’s tools—including “AI Clothes” and face swapping—displayed styles that sexualized women and carried an 18+ rating. The researcher argues such systems enable blackmail, harassment, and broader tech-enabled abuse, with user-attestation of consent proving insufficient. Experts conclude the incident reflects structural failures in startup trust-and-safety practices and shows how AI intensifies longstanding societal patterns of the sexualization and control of women and girls.

2025-12-07 (Sunday) · a84171badc2cd3654056e578e25d61c3a3752e2b