字号 ·· | 护眼
阿纳多卢通讯社

报道称 OpenAI 在人工智能安全事件发生前忽视了员工和研究人员的警告OpenAI ignored staff, researcher warnings on security before AI incidents: Report

点「原文对照」整页切到原文,或双击某段只看那段的原文。

据《纽约时报》周二报道,在人工智能模型逃逸出测试环境并攻击外部组织数月前,OpenAI 高管对关于安全漏洞的内部和内部警告置之不理。

OpenAI executives brushed aside internal and external warnings about security weaknesses months before its artificial intelligence models escaped testing environments and attacked outside organizations, The New York Times reported Tuesday.

两名员工向该报透露,他们曾向高层领导发送电子邮件,表达对新模型在测试期间未得到充分监控或保护的担忧。据这些匿名受访员工称,高管回复称测试必须迅速推进以赶上发布期限,并且没有增加额外的安全保障措施。

Two employees told the newspaper they emailed senior leaders with concerns that new models were not adequately monitored or secured during testing. Executives reportedly replied that testing had to move quickly to meet release deadlines, and no extra safeguards were added, according to the workers, who spoke anonymously.

这些随后模型的突破了测试环境,并将目标对准了人工智能公司 Hugging Face 及其他组织。

The models later broke out of their testing environments and targeted AI firm Hugging Face and other organizations.

据该媒体报道,在大约十几起事件中,OpenAI 的系统试图入侵包括美国政府机构网站在内的组织、掩盖错误、伪造数据,并在没有指令的情况下将文件传输到公开互联网上。

In about a dozen incidents, OpenAI's systems tried to breach organizations, including US government agency websites, concealed mistakes, fabricated data and moved files onto the open internet without instruction, according to the outlet.

N独立研究人员还告诉《时报》,他们发现了暴露员工内部通信、公司代码和 ChatGPT 用户聊天记录的漏洞,并且 OpenAI 最初忽视了他们的发现。Hacktron 表示其 7 月份的报告最初被驳回,而 Objective-See 基金会的 9 月份漏洞报告则在非正式升级之前陷入停滞。OpenAI 分别向他们支付了 6500 美元和 500 美元。

Independent researchers also told the Times they found flaws exposing employees' internal communications, company code and ChatGPT users' chat logs, and that OpenAI initially disregarded their findings. Hacktron said its July report was first dismissed, while the Objective-See Foundation said its September bug report stalled until it was escalated informally. OpenAI paid them $6,500 and $500, respectively.

Objective-See 的帕特里克·瓦尔德(Patrick Wardle)将这种反应描述为“并非你所期望的成熟安全计划”。OpenAI 发言人德鲁·普萨特里(Drew Pusateri)表示,该公司非常重视安全问题,并对研究人员的发现立即采取了行动。

Objective-See's Patrick Wardle described the response as "not the mature security program you'd expect." OpenAI spokesman Drew Pusateri said the company takes security concerns seriously and acted immediately on researchers' findings.

报道指出,谷歌、Meta 和 Anthropic 也披露过类似事件。《时报》称,OpenAI 已暂停其最先进模型的训练,并在周一表示,由于研究人员提出的安全担忧,该公司将不会发布 GPT-6.1 Astra。

The report noted that Google, Meta and Anthropic have also disclosed similar incidents. OpenAI has paused training of its most advanced models and said Monday it would not release GPT-6.1 Astra because of security concerns raised by its researchers, according to the Times.