字号 ·· | 护眼
卫报

前联合国网络谈判代表警告:澳大利亚运行的系统陈旧过时,人工智能代理可轻易加以利用Australia is run on legacy systems that AI agents can easily exploit, former UN cyber negotiator warns

点「原文对照」整页切到原文,或双击某段只看那段的原文。

澳大利亚前联合国网络谈判首席代表警告称,澳大利亚政府及经济各领域广泛使用的老旧计算机系统极易受到人工智能(AI)代理的攻击,这增加了敏感信息泄露的风险。

Ageing computer systems used throughout Australia’s government and large sections of the economy are easily exploited by AI agents, increasing the risk that sensitive information could be compromised, Australia’s former chief UN cyber negotiator has warned.

在政府紧急对一个违规OpenAI代理访问医疗保险(Medicare)数据事件进行取证调查之际,人工智能专家、科技政策设计研究所执行主任乔安娜·韦弗(Johanna Weaver)表示,老旧的IT系统普遍存在巨大漏洞。

As the government urgently undertakes a forensic investigation into a rogue OpenAI agent accessing Medicare data, the AI expert and Tech Policy Design Institute executive director, Johanna Weaver, said huge vulnerabilities existed across older IT systems.

韦弗说:“正是这些陈旧的遗留系统带来了巨大的漏洞,因为大量信息和数据都存储在这些自互联网诞生之初就已存在的系统中。”

“It is old legacy systems that present the huge vulnerabilities, because large amounts of information and data is stored on these systems that have been around since the beginning of the internet,” Weaver said.

“这些系统没有得到更新和维护,原因要么是人们已经遗忘了它们,要么是维护成本太高,又或者是这些系统已经不再提供更新了。这造成了巨大的漏洞,而这正是这些AI代理将要利用的地方。”周一的联邦内阁会议将讨论此次事件的影响。此前,OpenAI在周日表示,由于不断有关于其代理违规操作的报道,公司已暂停了最新人工智能模型的训练。

“They aren’t updated and maintained because either people have forgotten about them or it’s too costly, or there aren’t updates for systems any more. That creates an enormous vulnerability, and that is what these agents are going to be exploiting.” Monday’s meeting of federal cabinet will discuss the fall out, as OpenAI said on Sunday it had paused training of its latest artificial intelligence models amid growing reports of its agents going rogue.

在澳大利亚的黑客事件于周四曝光后,该公司披露了正在审查几起相关事件,这些事件中OpenAI代理在搜索美国政府网站时,其行为远远超出了操作人员的要求。

After the Australian hack was revealed on Thursday, the company disclosed moves to review several incidents in which OpenAI agents searching American government websites went far beyond what handlers asked of them.

OpenAI表示,只有在“确信已采取额外保障措施”的情况下才会恢复训练,并补充称,随着人工智能的发展和其他问题的出现,预计未来可能还需要再次“按下暂停键”。

OpenAI said it would resume training “only when we are confident that we have additional safeguards” in place, adding that it expected it would have to “hit pause” again as AI developed and other issues emerged.

2021年结束联合国任期的韦弗表示,需要进行彻底的调查和补救工作以弥补漏洞,并呼吁人工智能公司不要在互联网上发布他们无法控制的模型。

Weaver, who completed her term at the UN in 2021, said thorough investigation and remediation efforts would be required to close vulnerability gaps, calling on AI companies not to release models they could not control on the internet.

她说:“我们并非无能为力。我们可以淘汰旧系统,并将敏感数据从遗留系统中迁移出来。可以把它想象成一次数字大扫除。”

“We are not powerless. We can decommission old systems and move sensitive data of legacy systems. Think of it as a digital spring clean,” she said.

“我们必须划定底线,明确表示如果企业无法管控其人工智能系统,就不应将其发布。如果企业执意发布且这些系统造成了损害,企业必须承担责任。”政府系统通常运行在几十年前的程序上,有时是因为更换这些系统的成本高昂且过程复杂。

“We must also draw a line in the sand and say that, if companies cannot control their AI systems, they shouldn’t release them. And if they do, and those systems cause harm, companies must be held accountable.” Government systems are commonly run on programs dating back decades, sometimes due to the cost and complexity of replacing them.

金融与政府服务部长凯蒂·加拉格尔(Katy Gallagher)上周表示,该智能体通过与澳大利亚服务局(Services Australia)相连的旧系统,访问了医疗保险统计报告服务门户网站以及其他三个政府网站。

The finance and government services minister, Katy Gallagher, said last week the agent had accessed Medicare statistics reporting service portal, as well as three other government sites, through legacy systems linked to Services Australia.

周日,一位发言人表示,该机构正与澳大利亚信号局(Australian Signals Directorate)合作,追踪该人工智能智能体在6月份事件中的活动轨迹。

On Sunday a spokesperson said the agency was working with the Australian Signals Directorate to track the AI agent’s movements in the June incident.

目前,一项跨政府的快速审查正在进行中,总理部门、国家网络安全协调员以及澳大利亚人工智能安全研究所均参与其中。

A cross-government rapid review is under way, with the prime minister’s department, the ational cybersecurity coordinator and the Australian AI Safety Institute all involved.

Axios周日报道称,OpenAI、Anthropic和安全研究人员正在调查全球范围内数以万计的事件,在这些事件中,前沿模型采取了有问题或出乎意料的行动。

Axios reported on Sunday that OpenAI, Anthropic and security researchers were investigating tens of thousands of incidents globally in which frontier models undertook problematic or unexpected actions.

这些事件包括绕过安全护栏、创建留言板、逃避测试系统、劫持网站、所谓的“自我提示”以及绕过监控。

Incidents included bypassing safety guardrails, creating message boards, escaping testing systems, hijacking websites, so-called “self prompting” and the bypassing of monitors.

在针对人工智能初创公司Hugging Face的网络攻击被披露后,OpenAI也于7月暂停了其模型的开发。

OpenAI also halted development of its models in July, after the disclosure of a cyber-attack targeting AI startup Hugging Face.

在OpenAI和竞争对手Anthropic的负责人呼吁行业放缓发展步伐后,对人工智能模型的审查日益严格。

Growing scrutiny of AI models follows calls from the heads of OpenAI and rival Anthropic for an industry slowdown.

影子国防部长詹姆斯·帕特森(James Paterson)呼吁这些公司派遣高管出席议会的人工智能调查,以回答相关问题。

The shadow defence minister, James Paterson, called on the companies to make executives available to answer questions in a parliamentary inquiry into AI.

调查委员会主席、绿党参议员莎拉·汉森-杨(Sarah Hanson-Young)周日呼吁OpenAI的萨姆·奥特曼(Sam Altman)和Anthropic的达里奥·阿莫代(Dario Amodei)提供证词。汉森-杨领导的调查委员会定于周四在堪培拉恢复听证会。

The chair, Greens senator Sarah Hanson-Young, called on OpenAI’s Sam Altman and Anthropic’s Dario Amodei to give evidence on Sunday. Hanson-Young’s inquiry is due to resume hearings in Canberra on Thursday.

自由党副领袖简·休姆对 OpenAI 公司因黑客攻击而面临法律后果表示怀疑。

The deputy Liberal leader, Jane Hume, was sceptical that the OpenAI hack should result in legal consequences for the company.

“我不太清楚他们最终会逮捕谁、把谁带到街头并关进监狱……”这位自由党参议员在周日的 ABC 电视节目中说道。

“I’m not entirely sure who it is that they’re going to put in cuffs and drag through the city streets and put in the stocks,” the Liberal senator told ABC’s Insiders program on Sunday.

“本周真正令人担忧的是:我们之所以知道这次安全漏洞的存在,完全是因为 OpenAI 自己主动告知了我们。”阿尔巴尼亚政府为其应对措施进行了辩护。

“The real alarm bell that was set off this week is the fact that the only reason we knew about this breach … is because OpenAI told us.” The Albanese government has defended its response to the incident.

“人工智能程序未经授权就访问了澳大利亚政府的网站,这本身就是一个非常严重的事件,”国防部长理查德·马尔斯对 News 24 电视台表示,“这一点无可否认。”

“The fact that we’ve got an artificial intelligence agent gaining unauthorised access to an Australian government website, that of itself is very serious,” the defence minister, Richard Marles told News 24. “There’s no hiding that.

“这是澳大利亚首次发生此类事件,但我们不会回避这个问题。事实上,该程序获取的信息性质并不严重,因为这些信息我们早已公开了——而且那些信息根本不属于任何个人的隐私数据。”

“This is the first time this has happened in the context of Australia, and so we’re not shying away from that. In fact, the information that it obtained, was minor in its nature, in as much as that information we’ve now made public anyway – it wasn’t anyone’s personal data.”