字号 ·· | 护眼
彭博社

OpenAI表示其模型可能干扰了政府网站OpenAI Says Its Models May Have Interfered With Government Sites

点「原文对照」整页切到原文,或双击某段只看那段的原文。

根据 Rachel Metz 和 Jeff Stone 的报道,OpenAI 表示已通知了“数十家”组织,包括政府和大学。这些组织的网站可能在 OpenAI 对其人工智能技术进行评估的过程中受到了影响(即这些网站的正常运行受到了干扰)。

By Rachel Metz and Jeff Stone OpenAI said it has notified “dozens” of organizations, including governments and universities, whose websites may have been hampered by visits from its artificial intelligence models during company evaluations of the technology.

在周五发布的一篇长篇博客文章中,OpenAI 称已向多个相关方通报了以下情况:其开发的软件可能绕过了某些在线服务的安全防护机制,导致这些服务的正常运行受到阻碍;或者某些错误配置的人工智能模型可能对第三方网站或服务产生了负面影响。这些问题的发现源于 OpenAI 在几个月前意外入侵 Hugging Face 之后展开的调查。受影响的网站包括由政府、大学、公共机构等机构运营的网站。

In an extensive blog post Friday, the company said it had notified a range of groups about cases in which its software may have bypassed an online service’s security controls or hampered its availability, or in situations where a misaligned AI model may have “negatively impacted” a website or service outside of OpenAI. The company discovered these incidents while expanding a probe it began after its AI inadvertently hacked Hugging Face several months ago. OpenAI said the websites that were affected include ones run by governments, universities, public agencies and other groups.

就在几天前,OpenAI 承认其人工智能模型在今年早些时候入侵了澳大利亚政府的网站,这是已知的首批针对政府数据库的人工智能网络攻击案例之一。OpenAI 在声明中表示,此次攻击发生在该公司对其人工智能模型进行评估的过程中。

Only days ago, OpenAI acknowledged that its AI models hacked an Australian government website earlier this year, marking one of the first known AI cyberattacks on a government database. The company said in a statement that the breach occurred while it was evaluating its models.

澳大利亚总理安东尼·阿尔巴内塞本周表示,OpenAI 的技术未经授权访问了用于发布医疗统计数据的政府网站。他强调,6 月 18 日发生的这次攻击并未泄露澳大利亚公民的个人信息。

Australian Prime Minister Anthony Albanese said this week that OpenAI’s technology had gained unauthorized access to a government website used for reporting healthcare statistics. The hack, on June 18, didn’t appear to compromise Australians’ personal information, he said.

在周五发布的社交媒体帖子中,OpenAI 表示其调查的重点是那些“人工智能模型超出其预定任务或使用方法与第三方网站进行交互的情况”。该公司表示:“目前发现的大多数案例都属于较轻的级别,且几乎没有证据表明这些行为对第三方服务造成了实质性影响。”

In a post on social network X on Friday, OpenAI said its investigation is focusing on “instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods.” “Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service,” the company wrote.

OpenAI 还指出,大多数被审查的情况都是人工智能模型在执行“常规研究任务”时发生的(例如从网站上获取信息)。该公司预计完成整个调查过程需要数月时间。

OpenAI said that most of the actions it has reviewed involved AI models carrying out “mundane research tasks,” like getting answers to questions from websites. The company said it expects it to take months to finish its review.

在周五于 X 平台上发布的一篇帖子中,OpenAI 的首席执行官 Sam Altman 表示,公司的进展速度并未达到他们的预期;不过他们正在努力在保持透明度的同时,从海量的数据中提取相关信息,并与受到影响的公司进行沟通与合作。

In a post on X Friday, OpenAI chief Sam Altman said the company has not worked as fast as it would like, but that it is balancing transparency with the need to find information in huge amounts of data in activity logs and then work with the companies that were impacted. “We are prioritizing as best as we can based on severity, and adding resources,” Altman said.

Altman 说:“我们正根据问题的严重程度来优先处理这些问题,并不断增加相应的资源。”

Hacks by models from OpenAI, Anthropic PBC, Google’s DeepMind and Meta Platforms Inc. have resulted in widespread cybersecurity concerns for major companies. Cyber vendors typically provide products that monitor for known strains of malicious software, or detect and block anomalous behaviors. Traditional cyber software such as firewalls, email filters and incident response tools specialize in detecting those threats, and then alerting human staffers who isolate breached accounts or devices.

OpenAI、Anthropic PBC、谷歌的 DeepMind 以及 Meta Platforms Inc. 开发的 AI 模型所引发的攻击事件,引发了各大企业的广泛网络安全担忧。传统的网络安全产品(如防火墙、电子邮件过滤工具和事件响应系统)主要用于检测已知的恶意软件或异常行为;这些系统会在发现威胁后向相关人员发出警报,由工作人员来隔离被入侵的账户或设备。

Hacks by models from OpenAI, Anthropic PBC, Google’s DeepMind and Meta Platforms Inc. have resulted in widespread cybersecurity concerns for major companies. Cyber vendors typically provide products that monitor for known strains of malicious software, or detect and block anomalous behaviors. Traditional cyber software such as firewalls, email filters and incident response tools specialize in detecting those threats, and then alerting human staffers who isolate breached accounts or devices.

然而,AI 模型的技术水平要高得多——它们有时能够发现此前未知的软件漏洞,并同时利用多个漏洞来入侵目标组织。这类攻击更难以被阻止,攻击者可以借此深入感染系统,同时逃避网络安全人员的察觉。

AI models have proven to be significantly more advanced, sometimes finding previously unknown software vulnerabilities and then using multiple flaws at a time to breach a targeted organization. Such compromises are harder to stop, and could provide malicious attackers with deep access to infected systems while remaining hidden from cybersecurity staffers.