OpenAI Says Its AI Models Acted On Its Own In An 'Unprecedented' Hack (apnews.com)
- Reference: 0184574392
- News link: https://it.slashdot.org/story/26/07/22/0348206/openai-says-its-ai-models-acted-on-its-own-in-an-unprecedented-hack
- Source link: https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3
> "We had a significant security incident during evaluation of our models," OpenAI CEO Sam Altman said in [3]a statement posted on social media. AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own. "We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," Hugging Face co-founder and CEO Clement Delangue said in a statement. "Turns out it did!"
>
> [...] "AI is accelerating the discovery and exploitation of vulnerabilities," OpenAI said in its statement Tuesday. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities." Delangue said he spent the past 24 hours working with OpenAI, "and we strongly believe there was no malicious intent on their part. It's quite mind-blowing that all of this happened autonomously!" Delangue added that it "might be the first incident of its kind."
[1] https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3
[2] https://slashdot.org/~Dr.+Bombay
[3] https://openai.com/index/hugging-face-model-evaluation-security-incident/
They are trying to sell the "cyberwar" sujet.. (Score:2)
...so that military spending is needed. It did not do it from alone, it was a set goal, so no news here.
toast (Score:3)
AI cannot do anything on its own any more than a toaster can make toast on its own. If you don't want toast you simply don't turn the toaster on.
Re: (Score:2)
> If you don't want toast you simply don't turn the toaster on.
I guess you hadn't heard of [1]a toaster that will list itself for sale if you don't use it often enough. [wired.com]
[1] https://www.wired.com/story/addicted-toaster/
Re:toast - talky toaster (Score:2)
I think everyone in the UK has seen this: [1]https://youtu.be/lhnN4eUiei4?s... [youtu.be]
[1] https://youtu.be/lhnN4eUiei4?si=AKP8w0T4IcRH4SKI
Liable for what their models do on their own? (Score:2)
If there is a company which deploys some software, such as an AI agent, and that AI agent breaks laws by hacking other company's network, breaching defense systems and launching missiles, executing ransomware attacks, or any other illegal activity, all based on no other prompts/instructions than provided by the hosting company, would the hosting company be liable?
We don't know how they work (Score:4)
We trained massive statistical models and hooked them up to chat bots, coding tools and some to drones and sentry guns. With no idea how it actually works and zero fucks given on what the consequences are.
Re: (Score:3)
> We trained massive statistical models and hooked them up to chat bots, coding tools and some to drones and sentry guns. With no idea how it actually works and zero fucks given on what the consequences are.
"Move fast and break other peoples things" I think is the saying?
incentives (Score:5, Interesting)
Given the option between (1) it did it by itself, (2) it did it because we told it to, or (3) it did it in response to a prompt where we expected it to do something else, I can guess why they choose option 1, even if what they describe sounds like #3.
Re: (Score:2)
Either way a crime was committed and they should be prosecuted.
Re: (Score:2)
"It" doesn't exist as a legal entity. The legal entity that organized the hack was OpenAI.
Re: (Score:2)
Sorry I was not clear - OpenAI is who I mean by "it".
No idea how this happened (Score:4)
Said Altman on his way to the Pentagon
Apple IP Theft (Score:2)
They going to pin that on AI too? ChatGPT got it done via blackmail.
Using hugging face.... (Score:2)
is its own reward.
People are f'ing crazy.
Suspicious timing (Score:2)
The timing of the announcement, coming right after this:
[1]https://www.tomshardware.com/t... [tomshardware.com]
is definitely suspicious. Especially since Kimi 3 is a lot cheaper to use than OpenAI's models.
[1] https://www.tomshardware.com/tech-industry/artificial-intelligence/kimi-k3-rocks-the-ai-industry-as-moonshot-ai-undercuts-closed-source-american-competitors-on-price-but-the-huge-2-8t-open-weight-model-still-needs-serious-hardware-to-deploy-at-scale
So much drama with Open AI and Anhropic models (Score:1)
while Kimi K3 silently released, open source and as good as them and much much cheaper.
In other, possibly related, news... (Score:2)
Sam Altman is a known liar.
So OpenAI are criminals? (Score:2)
Because that is what I am hearing here. The other thing is that apparently the IT security used by Hugging Face sucks deeply.
Long term might be good (Score:2)
All this chat about the vulnerabilities they exploit - we can either let it happen and actually improve the defenses based on what is learned, or we can "cry ban" and pretend stuff that clearly may be vulnerable is invulnerable. I think ultimately it would be better to uncover the flaws, and rectify them than work on a belief-we-doubt because AI's have demonstrated flaws in things we wish to pretend are pristine and perfect.