字号 ·· | 护眼
连线

OpenAI因Hugging Face遭黑客攻击而被起诉OpenAI Gets Sued Over the Hugging Face Hack

点「原文对照」整页切到原文,或双击某段只看那段的原文。

一家法律类非营利组织于周二在加利福尼亚州一家法院起诉了OpenAI,起因是该公司的人工智能智能体逃逸出测试环境并黑客入侵了开源人工智能平台Hugging Face。“OpenAI的行为直接违反了加州法律,”诉讼指控称。

A legal nonprofit sued OpenAI in a California court on Tuesday over the company’s agents escaping a testing environment and hacking the open source AI platform Hugging Face. “OpenAI’s actions straightforwardly violated California law,” the suit alleges.

该诉讼由“安全科学与技术法律倡导者”(LASST)组织和Gerstein Harrow律师事务所在位于旧金山的加州高级法院提起,OpenAI的总部即设在此地。诉讼指控称,OpenAI的智能体在今年夏天入侵Hugging Face,违反了加州的《全面计算机数据访问和欺诈法》(CDAFA)。正值业界不断爆出智能体失控的丑闻之际,该诉讼指出,根据1月1日起生效的一项加州人工智能法律,即“人工智能自主对原告造成损害不得构成抗辩理由”,OpenAI应为其活动承担责任。

The suit was filed by Legal Advocates for Safe Science and Technology (LASST) and the law firm Gerstein Harrow in California Superior Court in San Francisco, where OpenAI is headquartered. It alleges that OpenAI’s agents violated California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) by breaching Hugging Face over the summer. The suit, which comes amid ongoing disclosures across the industry of agents going rogue, claims that OpenAI should be held responsible for the activity given a California AI law in effect since January 1 that says “it shall not be a defense … that the artificial intelligence autonomously caused the harm to the plaintiff.”

LASST创始人泰勒·惠特默(Tyler Whitmer)对《连线》杂志表示:“我们认为,严格执行现有法律以追究人工智能公司对其所造成损害的责任至关重要。特别是当这种损害是由自主智能体造成的时候,因为我们认为这是世界上一种显而易见、极其危险且非常崭新的事物。”OpenAI没有立即回应置评请求。

“We think it’s extremely important that existing laws are enforced to hold AI companies accountable for the harm they’re causing,” Tyler Whitmer, founder of LASST, tells WIRED. “Especially when that harm is caused by autonomous agents, because we see that as an obvious, extremely risky thing in the world that’s very new.”OpenAI did not immediately respond to a request for comment.

周一,佛罗里达州总检察长詹姆斯·乌斯迈尔(James Uthmeier)针对OpenAI申请了临时禁令,以阻止在没有独立监督的情况下开发模型。此前,佛罗里达州于6月对OpenAI及其首席执行官萨姆·奥尔特曼(Sam Altman)提起了诉讼。乌斯迈尔在一份声明中表示,OpenAI“请求政府将他们绑在桅杆上。好吧,佛罗里达州正在回应他们的求救呼声。”

On Monday, Florida Attorney General James Uthmeier filed for a temporary injunction against OpenAI to block development of models without independent oversight, amid a lawsuit Florida brought in June against OpenAI and its CEO, Sam Altman. OpenAI “asked the government to tie them to the mast. Well, Florida is answering their cries for help,” Uthmeier said in a statement.

鉴于人工智能(AI)代理的核心功能就是能够代表用户执行某些操作,AI开发者和安全研究人员早就预见到:随着机器学习技术的不断发展,那些非预期的、具有“自主性”的AI行为将成为一个严重问题。目前,主流消费级AI系统中内置的安全机制在很大程度上防止了大规模的恶意行为;然而,AI技术的飞速进步,以及某些情况下安全防护措施的被暂时解除(例如Hugging Face公司在测试过程中取消了部分模型限制),确实导致了恶意行为的增加。

Given that the whole point of AI agents is that they can be empowered to take actions on a (human) user’s behalf, AI developers and safety researchers have long foreseen that unintended “agentic” activity would be a concern as machine learning development progressed. Protections built into mainstream, consumer AI systems have largely prevented mass rogue activity so far, but rapidly advancing capabilities in general, as well as situations where guardrails are suspended (such as in the Hugging Face case where OpenAI had removed some model restraints for testing), have led to an apparent uptick in rogue agent activity.

在各国政府权衡AI监管措施时(这些决策需要同时考虑人工智能的安全性、经济影响以及国家安全等因素),全球范围内的研究人员和公众越来越多地呼吁建立针对AI的问责机制。从法律角度来看,专家们普遍认为:关于责任、赔偿责任以及行为过失的问题,只能通过法院审理的具体案例来加以明确。

As governments weigh AI regulation amid both existential safety questions and economic and national security considerations, researchers and people around the world have increasingly called for accountability mechanisms for AI. And from a legal perspective, experts have largely emphasized that questions of responsibility, liability, and culpability can only be answered through precedent set by cases working their way through courts.

“在Hugging Face事件曝光后,我们确实做了很多工作,试图向监管机构和民间社会组织普及相关情况。我们当时就在想:到底会不会有人通过法律途径来追究责任呢?”Whitmer说道,“我们认为Hugging Face公司本应成为提起诉讼的合适对象,但它却什么都没有做。既然似乎没有其他机构会采取行动,我们就决定自己采取行动。随着AI系统的规模不断扩大,其潜在的危害性也会越来越大。”

“After the Hugging Face incident was disclosed, we actually did a bunch of work trying to educate regulators and civil society organizations about the hack. And we were kind of wondering is anyone going to do anything about this in court?”Whitmer says. “There are structural reasons why we think Hugging Face, which is the obvious potential plaintiff to do something here, is not doing anything. So given that it didn’t seem like anyone else was going to do anything about this, we moved forward. As these systems scale and as things get crazier, AI really could be catastrophically harmful.”

LASST与Gerstein Harrow律师事务所依据加利福尼亚州的《反不正当竞争法》提起了这起诉讼,他们指出:由于Hugging Face事件以及OpenAI的违法行为,LASST的工作和资源受到了严重影响和破坏。

LASST and Gerstein Harrow brought the lawsuit under California’s Unfair Competition Law, which requires that LASST allege both how its work and resources were impacted and diverted as a result of the Hugging Face incident, as well as unlawful activity by OpenAI.

该诉讼并未寻求经济赔偿,而是要求法院颁布禁令,禁止OpenAI开发能够自主黑客攻击其他实体的AI智能体,同时要求赔偿诉讼费以及“法院认为公正和适当的其他救济”。

The suit does not seek financial damages, and instead asks the court for injunctive relief such that OpenAI would be barred from developing AI agents that can autonomously hack other entities, plus legal fees and “any other relief deemed just and proper.”