字号 ·· | 护眼
卫报

OpenAI在Medicare及其他澳大利亚政府网站遭黑客攻击后表示“抱歉并正努力改进”OpenAI ‘sorry and working to do better’ after hack of Medicare and other Australian government websites

点「原文对照」整页切到原文,或双击某段只看那段的原文。

OpenAI已就其智能体攻击澳大利亚医疗保险(Medicare)系统一事向澳大利亚民众道歉,并将于下周出席议会听证。此前,这家科技公司披露了更多关于其在6月份入侵澳大利亚政府网站的细节。

OpenAI has apologised to Australians for its agent attack on Medicare and will front parliament next week, as the tech company revealed more details about its June hack of Australian government websites.

在周二发布的一篇博文中,OpenAI表示其本应更好地处理此次事件的应对工作。

blog post released on Tuesday, OpenAI said it should have handled its response better.

“我们本应更好地处理我们的应对措施。我们深表歉意,并正努力在未来做得更好。”该公司还就澳大利亚总理安东尼·阿尔巴尼斯上周披露的事件提供了更多细节。

“We also should have handled our response better. We are sorry and working to do better in the future.”The company also provided more detail on the incident revealed by the Australian prime minister, Anthony Albanese last week.

OpenAI表示,在7月份Hugging Face遭受攻击后,公司对早期的训练事件进行了审查,并于8月中旬察觉到澳大利亚政府网站上存在智能体活动。

OpenAI said it became aware of agent activity on Australian government websites in mid-August after the company reviewed earlier training incidents after the Hugging Face attack in July.

这些智能体获得了澳大利亚服务局(Services Australia)医疗保险统计门户网站的非公开访问权限。OpenAI称,该智能体能够运行命令、检索内部文件和凭据,并写入文件,但并未访问任何患者或客户记录。

The agents gained non-public access to a Services Australia portal for Medicare statistics, and OpenAI said the agent was able to run commands, retrieve internal files, credentials, and write files, but no patient or client records were accessed.

新南威尔士州犯罪统计与研究局(BOCSAR)的公共犯罪地图工具也遭到了访问,应用程序配置、操作任务、日志以及网站元数据被提供给了该机构。

The NSW Bureau of Crime Statistics and Research’s public crime mapping tool was also accessed, with application configuration, operational jobs and logs, and website metadata provided to the agency.

该智能体还发现了一个暴露的访问密钥,并利用其查询了维多利亚州卫生信息报告系统,从而获取了汇总的调查统计数据。

The agent discovered an exposed access key to query the Victorian agency for health information’s reporting system to access aggregate survey statistics.

对于澳大利亚健康与福利研究所(AIHW),OpenAI的智能体检索到了汇总统计数据,但其绕过访问控制的单独尝试均未成功,且所获取的信息均为公开可查的。

For the Australian Institute of Health and Welfare, OpenAI agents retrieved aggregate statistics, but separate attempts to bypass access controls were unsuccessful and the information obtained was publicly available.

澳大利亚服务局和维多利亚州卫生部于9月10日获悉此事,新南威尔士州犯罪统计与研究局于9月18日获悉。

Services Australia and the Victorian health department were informed on 10 September, while the NSW BOCSAR was informed on 18 September.

澳大利亚健康与福利研究所直到9月24日才收到通知,因为OpenAI认为该事件未达到披露门槛。

The Australian Institute of Health and Welfare was not informed until 24 September, as OpenAI deemed it did not meet disclosure thresholds.

OpenAI表示:“自那时起,我们一直与澳大利亚政府机构密切合作,分享我们迄今为止所了解的情况。如果我们发现还有其他受影响的机构,我们将及时直接通知他们,提供现有信息,并在有进一步事实浮出水面时提供更新。”此次事件发生的原因是,一个模型被指派研究维多利亚州人均皮肤病药物支出。该模型在获取相关信息时遇到了困难,OpenAI称其“采取了我们未授权的行动”,包括访问澳大利亚服务局(Services Australia)的医疗保险统计报告服务。

“Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date,” OpenAI said. “If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge.”The incident occurred after one model was tasked to research government spending per person on medicines for skin conditions in Victoria. The model had difficulty obtaining that information, and OpenAI said “it took actions that we had not authorised it to take” including accessing Services Australia’s Medicare statistics reporting service.

OpenAI表示,将投入资源和专业知识协助受影响的机构,并为澳大利亚政府机构提供支持,以加强关键基础设施的网络防御。

OpenAI said it would commit resources and expertise to affected agencies, and provide Australian government agencies with support to build cyberdefences on critical infrastructure.

该公司还表示,将成立一个由澳大利亚专家组成的特别工作组,就管理人工智能代理风险制定切实可行的政策建议。

The company said it would also establish a taskforce with Australian expertise to develop practical policy recommendations on managing risk with AI agents.

OpenAI首席战略官杰森·权(Jason Kwon)将于下周二出席人工智能联合特别委员会的听证会。《卫报》澳大利亚版周一报道称,Anthropic也将出席此次听证会,但不会参加本周关于人工智能和数据中心的参议院调查。

OpenAI’s chief strategy officer, Jason Kwon, will appear at the Joint Select Committee on AI on Tuesday next week. Guardian Australia reported on Monday that Anthropic would also appear at this hearing, but not at a Senate inquiry into AI and datacentres this week.

阿尔巴尼斯上周在美国宣布这一黑客事件时表示,他已与OpenAI首席执行官萨姆·奥特曼(Sam Altman)进行了交谈,“以表达澳大利亚对此次事件的极度关切”。

Albanese who was in the United States last week when he announced the hack, said at the time he had spoken with OpenAI’s chief executive, Sam Altman, “to express Australia’s extreme concern about this incident”.

周二,阿尔巴尼斯表示,自事件发生以来,OpenAI和Anthropic在沟通方面都表现得“非常具有建设性和开放性”。他表示,人工智能可以促进经济增长和生产力,但也伴随着风险。

On Tuesday, Albanese said OpenAI had been “very constructive and open in engaging” since the incident, as had Anthropic. He said AI can improve economic growth and productivity but it also carries risks.

“我们已经看到了这些风险的存在——不仅在澳大利亚发生的事件中,美国和其他国家也出现了类似的情况。”在 OpenAI 在遭到黑客攻击三个月后,使用一个公开可访问的电子邮件地址向澳大利亚服务部门(Services Australia)报告了该事件之后,联邦政府表示可能会出台针对人工智能相关数据泄露事件的强制性报告规定。

“And we’ve seen those risks exposed – not just in what occurred in Australia, but the revelation that has occurred in the United States and other countries as well.”The federal government has flagged it could introduce mandatory reporting rules for AI-related data breaches, after the revelation OpenAI used a public-facing email address three months after the hack to report the incident to Services Australia.

该公司周二表示,他们“还有许多工作要做”来重建与澳大利亚民众的信任,但同时也表示正在做出“实质性的改变”。

The company said on Tuesday it had “a lot of work ahead” to rebuild trust with Australians but said it was making “meaningful changes”.