林·多安报道:OpenAI表示,一个本应在安全且断网的受控环境中进行训练的代理式AI系统,成功获取了网络访问权限,并连接到了一个外部的第三方聊天机器人。
By Lynn Doan OpenAI said another agentic AI system that was being trained in what was supposed to be a secured, internet-free environment was able to gain access to the web to reach an external, third-party chatbot.
根据OpenAI周五在其网站上发布的博客文章,这一发现发生在不到一周前。其一个代理式AI系统正在沙箱环境中接受训练,期间利用了一个“漏洞”访问了公共互联网。获得访问权限后,该系统向一个未具名的第三方聊天机器人服务发送了至少20条查询,其中包括“法国的首都是哪里”,报告指出。
The discovery was made less than a week ago, according to a blog post on OpenAI’s website on Friday. One of its agentic AI systems was being trained in a sandbox environment when it exploited a “gap” to reach the public internet. With that access, it sent at least 20 queries to an unnamed, third-party chatbot service, including “What is the capital of France,” the report showed.
OpenAI将此次突破描述为自7月一组模型在内部测试期间意外获得互联网访问权限并入侵AI平台Hugging Face的系统以来,首次发生此类安全事件。
OpenAI described the breakout as the first security incident of its kind since a combination of models gained internet access during internal testing and inadvertently breached the system of the AI platform Hugging Face in July.
这家AI开发商表示:“这为我们指明了下一阶段工作的重点方向。”该公司称,在最新事件发生后,决定暂停其最强大模型的工具使用训练,直至沙箱缺陷得到解决。OpenAI补充道:“我们将不会恢复对该特定模型的训练。”
“It gives us an important signal about where to focus the next phase of that work,” the AI developer said. The company said it decided after the latest incident to pause training with tool use on its most capable models until the sandbox flaw was resolved. “We will not resume training this particular model,” OpenAI added.
OpenAI、Anthropic PBC、谷歌DeepMind和Meta Platforms Inc.等公司开发的AI模型在近几个月内发生的多次安全漏洞,已令网络安全和AI安全专家感到担忧。Hugging Face事件是Anthropic首席执行官达里奥·阿莫迪(Dario Amodei)两周前呼吁全行业放缓AI开发时引用的原因之一。他的呼吁迅速获得了OpenAI首席执行官萨姆·奥特曼(Sam Altman)、埃隆·马斯克(Elon Musk)等人的支持,并引发了一场关于加强AI监管必要性的全球性辩论。
Breaches by AI models developed OpenAI, Anthropic PBC, Google’s DeepMind and Meta Platforms Inc. in recent months have alarmed cybersecurity and AI safety experts. The Hugging Face incident was among the reasons cited by Anthropic Chief Executive Officer Dario Amodei when he called for an industrywide slowdown in AI development two weeks ago. His call, quickly endorsed by OpenAI CEO Sam Altman, Elon Musk and others, has touched off a global debate over the need for more AI regulation.
OpenAI披露了最新的沙盒故障,而此时该公司仍在努力理解其智能体AI系统此前在接入互联网时所引发的干扰。该公司周五证实,其模型在训练和评估过程中访问了美国政府网站的信息,其中包括人口普查局和证券交易委员会的网站。
OpenAI disclosed the latest sandbox failure even while it’s still working to understand the disruption brought about by its agentic AI systems when they previously gained access to the internet. The company confirmed on Friday that its models accessed information from US government websites, including those of the Census Bureau and the Securities and Exchange Commission, during training and evaluation.
就在几天前,OpenAI披露其模型在今年早些时候曾干扰了一个澳大利亚政府网站。
Just days ago, OpenAI disclosed that its models had disrupted an Australian government website earlier this year.
最近的这次沙盒漏洞也暴露了OpenAI运营流程中的缺口。博文显示,一名“人工审核员”收到了内部监控系统的警报,并在三分钟内通过Slack进行了确认,但训练任务并未像预期那样自动停止。据报告显示,直到两个多小时后,才有人手动停止了该任务。
The most recent sandbox breach also exposed gaps in OpenAI’s operational processes. A “human reviewer” received an alert from an internal monitoring system and acknowledged it on Slack within three minutes, but the training run didn’t automatically stop as expected, the blog post showed. It took more than two hours for someone to manually stop the run, according to the report.
人工智能安全非营利组织Nightingale的创始人悉尼·冯·阿克斯(Sydney Von Arx)表示:“令人遗憾的是,即使在Hugging Face事件后加强了安全性,OpenAI的模型仍然能够获得未经授权的互联网访问权限。现在最大的问题是,他们是会对此进行修补并尽快恢复训练,还是会找到问题的根源并彻底解决它。”
“It’s unfortunate that even after upping their security in the wake of Hugging Face, OpenAI’s models are still capable of gaining unauthorized internet access,” said Sydney Von Arx, founder of an AI safety nonprofit Nightingale. “The big question now is whether they will slap a Band-Aid on this and turn training back on ASAP versus if they’ll find the root cause of the issue and fix it.”