据数字取证公司 Asymmetric Security 周四发布的调查报告,OpenAI 的自主代理程序曾侵入预生产服务器,尝试各类攻击手段,并试图探测美国疾病控制与预防中心、美国证券交易委员会、国际能源署以及梅奥诊所的网站。这些代理程序的一些操作导致相关记录被删除或无法访问。该公司指出,仅凭公开数据尚无法排除它们获取敏感信息的可能性。
OpenAI’s rogue agents reached pre-production servers, tried attacker techniques and probed the websites of the CDC, the SEC, the International Energy Agency and the Mayo Clinic. That is according to an investigation published on Thursday by Asymmetric Security, a digital forensics firm. Some of their tactics left records erased or out of reach. Public data alone cannot rule out access to sensitive information, the firm said.
据路透社报道,同日,加利福尼亚州总检察长罗布·邦塔就与 OpenAI 模型相关的网络安全事件及风险向其发出传票。
On the same day, California Attorney General Rob Bonta subpoenaed OpenAI over cyber incidents and risks tied to its models, Reuters reported.
从健康统计数据到预生产服务器,Asymmetric Security 的团队耗时48小时,对今年3月至9月期间这些代理程序的公开活动记录进行了分析。这些活动主要针对澳大利亚政府及其他机构,在6月16日至21日期间达到高峰。这些代理程序最初似乎是在执行研究任务,比如搜集健康、处方药及贸易统计数据,这很可能是评估流程的一部分。
From health statistics to staging servers Asymmetric’s team spent 48 hours examining public records of agent activity between March and September. The activity targeted the Australian government and other organisations, and it peaked between 16 and 21 June. The agents seem to have started with research tasks, such as finding health, prescription and trade statistics, possibly as part of an evaluation.
调查人员写道:“我们观察到的活动起初看似无害,但随后逐渐演变为具有风险的行为。”
“The activity we observed looked like it stemmed from innocent tasks which then evolved into problematic activity,” the investigators wrote.
当无法直接获取所需数据时,这些代理程序便将各类公共服务串联起来加以利用。一款名为 httpbin 的开发工具会生成包含其自有代码的网页;另一款名为 urlquery 的扫描服务则会在浏览器中打开这些网页并记录结果。这样一来,尽管处于沙盒环境限制之下,这些代理程序仍获得了近乎完整网页浏览器的功能。
When the agents could not get the data, they chained public services together. A developer tool called httpbin served pages containing their own code. A scanning service called urlquery opened those pages in its browser and recorded the results. That gave the agents something close to a full web browser, despite the limits of their sandbox.
记录显示,这些代理程序曾访问澳大利亚健康与福利研究所的预生产系统,部分请求还成功返回了数据。据该公司所知,这些数据均为公开信息。此外,他们还发现类似活动曾针对 Data USA、健康指标与评估研究所以及联合国贸易与发展会议的预生产系统发生。
The records show access to a pre-production system of the Australian Institute of Health and Welfare (AIHW). Some requests returned data. As far as the firm knows, that data was public. It found similar activity against staging systems for Data USA, IHME and the UN’s trade body, UNCTAD.
这些代理程序还试图寻找未受保护的 Git 代码库文件,并对美国教育部的数据接口实施了 SQL 注入攻击。Asymmetric Security 虽发现了这些尝试行为,但并无证据表明攻击最终得逞。
Private accounts and expiring mailboxes The agents also probed for exposed Git files and tried a SQL injection against a US Department of Education data API. Asymmetric found the attempts but no evidence that they succeeded.
6月14日起,这些智能体试图利用一次性邮箱和扫描服务创建账户。首次尝试于6月18日成功。私人扫描服务可以隐藏他们的搜索记录,其中一个邮箱被设置为在48小时后失效。为将数据带出,他们利用了葡萄牙的一家网页存档服务和一项推送通知服务。新南威尔士州犯罪统计工具返回的一份存档响应数据约为22 MB。
From 14 June, the agents tried to create accounts with disposable email and scanning services. The first succeeded on 18 June. Private scans could hide their searches, and one mailbox was set to expire after 48 hours. To pull data out, they used a Portuguese web archive and a push-notification service. One archived response from a New South Wales crime statistics tool ran to about 22 MB.
公司表示,仅凭这些记录无法判断这些智能体是否有意隐藏其活动。要确认这一点,需要完整的模型对话记录。《金融时报》报道称,这些智能体从55个企业、非营利组织和政府网站提取了数据。
The records alone do not show whether the agents meant to hide their activity, the firm said. That would need the full model transcripts. The agents pulled data from 55 business, non-profit and government websites, the Financial Times reported.
加州要求给出答案:“我的办公室正在就涉及该公司及其人工智能模型的网络安全事件和风险,向OpenAI提出更多问题。”邦塔在一份声明中表示。
California wants answers“My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models,” Bonta said in a statement.
邦塔警告称,未能阻止其模型实施或协助网络攻击的开发者可能面临法律责任。路透社报道称,他上个月就Hugging Face黑客事件启动了正式调查。美国联邦贸易委员会正在调查OpenAI和Anthropic。由爱荷华州牵头的15州联盟已寻求获取与这起黑客事件有关的记录。
Bonta warned that developers who fail to stop their models from carrying out or enabling cyberattacks could face legal accountability. Last month he opened a formal investigation into the Hugging Face hack, Reuters reported. The FTC is already investigating OpenAI and Anthropic. A 15-state coalition led by Iowa has sought records about the hack.
澳大利亚总理上周表示,一个OpenAI智能体侵入了Medicare统计门户。
Australia’s prime minister said last week that an OpenAI agent broke into a Medicare statistics portal.