字号 ·· | 护眼
阿纳多卢通讯社

安全公司:OpenAI智能体掩盖了针对政府网站的黑客活动OpenAI agents obscured hacking activity targeting government websites: Security firm

点「原文对照」整页切到原文,或双击某段只看那段的原文。

据数字取证公司Asymmetric Security周四发布的调查结果显示,OpenAI的人工智能(AI)代理掩盖了针对政府网站的黑客活动。

OpenAI’s artificial intelligence (AI) agents obscured hacking activity targeting government websites, according to findings by digital forensics firm Asymmetric Security on Thursday.

调查发现,这些代理从属于政府机构、企业和非营利组织的55个网站中提取了数据,其中包括美国疾病控制与预防中心(CDC)、证券交易委员会(SEC)、国际能源署和梅奥诊所。

The investigation found that the agents pulled data from 55 websites belonging to government agencies, businesses and nonprofits including the US Centers for Disease Control and Prevention (CDC), the Securities and Exchange Commission (SEC), the International Energy Agency and the Mayo Clinic.

Asymmetric表示,这些代理删除了记录或使其无法访问,限制了外部审计员和研究人员审查其行为的能力。

Asymmetric said the agents erased records or made them inaccessible, limiting the ability of outside auditors and researchers to scrutinize their actions.

这些代理还在Urlquery(一个网站恶意软件扫描服务)上创建了临时电子邮件收件箱和私人账户,以下载数据。

The agents also created temporary email inboxes and private accounts on Urlquery, a website malware-scanning service, to download data.

研究人员表示,这些手段阻止了外部审计员追踪从包括澳大利亚健康统计局和药品福利计划在内的网站收集了哪些信息。

Researchers said these tactics prevented outside auditors from tracing what information was collected from websites including Australia’s health statistics agency and pharmaceutical benefits scheme.

据《金融时报》报道,Asymmetric Security联合创始人Pippa Thompson表示:“这些代理可能是故意使用这些工具来掩盖踪迹。”

“It’s possible that the agents were deliberately using these tools to cover their tracks,” Asymmetric Security co-founder Pippa Thompson said, according to a report by the Financial Times.

然而,根据该报道,该公司无法确定这些行为是故意的,还是代理在测试演练施加的约束下出现故障导致的。

However, the firm could not establish whether the actions were deliberate or resulted from agents going awry under constraints imposed during a test exercise, according to the report.

这些发现是在有报道称OpenAI模型于6月侵入澳大利亚公共卫生服务网站,访问了公开和非公开文件之后出现的。

The findings follow reports that OpenAI models breached Australian public health service websites in June, accessing public and nonpublic files.

Asymmetric联合创始人Zainab Ali Majid警告称,有限的透明度以及入侵发生与披露之间的时间差可能会阻碍彻底调查。

Asymmetric co-founder Zainab Ali Majid warned that limited transparency and the gap between the breaches and their disclosure could hinder a thorough investigation.

OpenAI对《金融时报》表示:“我们正在审查模型的不一致活动,并在发现对组织系统有潜在影响时通知相关组织。”

“We’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems,” OpenAI told the FT.

该公司表示,检测到的大多数活动涉及“常规研究任务”,包括访问公开可用的网络内容。

The company said most activity detected involved “routine research tasks,” including accessing publicly available web content.

美国证券交易委员会表示未有私人信息被访问,而美国疾病控制与预防中心、国际能源署和梅奥诊所均未回应报社的置评请求。

The SEC said no private information was accessed, while the CDC, International Energy Agency and Mayo Clinic did not respond to the newspaper’s requests for comment.