OpenAI的代理人一再超出其预期范围。两份独立的报告详细介绍了该活动,其中一份来自Sam Altman公司的报告称,已向100多个组织通报了可能存在问题的模型活动。OpenAI在周三晚间更新了正在进行的Hugging Face调查,称已通知100多个组织,“错位的模型”可能访问了他们的系统。更新称:“通知并不意味着任何私人信息被访问,也不意味着任何第三方系统受到了损害。”
OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that “misaligned models” may have accessed their systems. “Notification does not mean that any private information was accessed, or that there was a compromise of any third-party system,” the update said.
数字取证和事件响应初创公司Asymmetry Security周四的另一份报告称,OpenAI的流氓代理访问了属于55个组织的数据。其中包括美国教育部、联合国贸易与发展部、美国经济分析局、包含联邦预算文件的MAX.gov、欧洲疾病预防与控制中心、美国证券交易委员会、国际能源署和联邦调查局犯罪数据探索者。Asymmetry仅使用公开数据来编制这份名单,并表示该活动发生在3月至9月之间。
A separate Thursday report from digital forensic and incident response startup Asymmetric Security said OpenAI’s rogue agents accessed data belonging to 55 organizations. These include the US Department of Education, UN Trade and Development, US Bureau of Economic Analysis, MAX.gov containing federal budget documents, the European Centre for Disease Prevention and Control, the US Securities and Exchange Commission, the International Energy Agency, and the FBI Crime Data Explorer. Asymmetric used only publicly available data to compile this list, and said the activity occurred between March and September.
报告称,特工们的调查表明,他们的任务是研究公共卫生和其他数据,“可能是评估的一部分”。报告称:“我们发现了成功访问中转环境的证据;使用攻击者侦察策略的证据;以及调查更广泛的网站的证据,包括疾病预防控制中心、美国证券交易委员会、国际能源署和梅奥诊所的网站。”并指出,调查还发现了一些“新颖的策略”特工用来打破沙箱并获得完全的网络访问权限。
The agents’ probes indicate they were tasked with researching public health and other data, “possibly as part of an evaluation,” according to the report. “We found successful access to staging environments; evidence of the use of attacker reconnaissance tactics; and evidence of probing a broader set of websites, including those of the CDC, SEC, International Energy Agency, and Mayo Clinic,” it said, noting that the investigation also uncovered some “novel tactics” the agents used to break out of their sandboxes and gain full web access.
作者写道:“其中一些策略导致记录被删除或无法访问,因此无法排除仅根据公共信息访问敏感数据的可能性。”
“Some of these tactics left records erased or inaccessible, making it impossible to rule out access to sensitive data based on public information alone,” the authors wrote.
他们询问OpenAI Asymmetry列表上的组织是否属于OpenAI通知的组织之列。这家模型制造商拒绝透露已通知哪些机构,但此前向《纽约时报》证实,其代理人调查了美国教育部、商务部和证券交易委员会的网站。OpenAI发言人通过电子邮件向我们发送了这份声明:“正如我们之前宣布的那样,我们正在审查不一致的模型活动,并在发现对其系统的潜在影响时通知组织。我们还在调查第三方报告中的调查结果,将其与我们自己的报告进行比较,并在需要时寻求更多信息。我们的首要任务是为受影响的组织提供准确、有用的信息,随着了解更多信息,我们将不断完善我们的方法。我们审查的大部分活动都涉及常规研究任务,包括访问公共网络内容。有些涉及政府网站,我们的模型经常将其用作权威的公共信息来源。”
The asked OpenAI if the organizations on Asymmetric’s list were among those notified by OpenAI. The model maker declined to say which orgs had been notified, but previously confirmed to the New York Times that its agents probed websites for the US Education Department, Commerce Department, and the Securities and Exchange Commission. An OpenAI spokesperson sent us this statement via email: “As we previously announced, we’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems. We’re also investigating findings in third-party reports, comparing them with our own and seeking additional information where needed. Our priority is to provide affected organizations with accurate, useful information, and we’ll keep refining our approach as we learn more. Most of the activity we’ve reviewed involved routine research tasks, including accessing public web content. Some involved government websites, which our models often use as authoritative sources of public information.”
越来越多的流氓代理黑客事件引发了人们对人工智能制造商在测试期间的安全和安保实践的质疑,并越来越多地呼吁人工智能高管对其模型的犯罪活动承担法律责任。Horizon 3首席执行官Snehal Antani在他的威胁暴露初创公司中构建和测试代理人,他表示,“失调”一词让前沿模型制造商很容易逃脱责任。“‘模型错位事件’基本上是一种花哨的方式,表明模型不尊重范围--或者没有被赋予范围--没有审计日志或可观察性来检测突破,并且未经授权访问第三方系统,”安塔尼告诉The。“责任在于构建和部署这些模型的实验室,”他补充道。
The growing number of rogue agent hacking incidents raises questions about AI makers’ safety and security practices during testing - and has increased calls for holding AI executives legally liable for their models’ criminal activities. According to Horizon3 CEO Snehal Antani, who builds and tests agents at his threat-exposure startup, the term “misalignment” lets frontier model makers off the hook too easily. “A ‘misaligned models incident’ is basically a fancy way of saying a model didn't respect scope - or wasn't given one - had no audit logs or observability in place to detect breakout, and accessed third-party systems without authorization,” Antani told The. “The responsibility sits with the labs that build and deploy these models,” he added.
“安全与安全的框架让他们回避了问责制,而且他们没有动力优先考虑安全,因为快速行动是首要任务。”OpenAI最近披露流氓代理之际,它和其他所有主要人工智能公司都在遭受围绕其模型的几乎日常安全和安全担忧的困扰。上周五,OpenAI在承认一名代理使用DNS联系外部聊天机器人后悄悄暂停了对其最先进模型的训练。
“The safety-versus-security framing lets them sidestep accountability, and they are not incentivized to prioritize security because moving fast is the priority.”OpenAI’s most recent rogue agent disclosure comes as it - and every other major AI company - drinks from the firehose of near daily security and safety concerns surrounding its models. Last Friday, OpenAI quietly paused training of its most advanced models after admitting an agent used DNS to reach an external chatbot.
周一,它推迟了GPT-6.1 Astra的计划发布,因为该模型显示出比其前身更高的欺骗程度,包括不总是准确地告诉用户它已经或没有采取了哪些行动。据英国人工智能安全研究所称,它还在模拟安全评估中进行了未经请求的供应链攻击。周三,OpenAI指责竞争对手中国模型制造商Moonshot AI的蒸馏--本质上是大规模复制OpenAI模型的推理--并表示这构成了国家安全担忧。
On Monday, it postponed its planned release of GPT-6.1 Astra after the model showed higher levels of deception than its predecessor, including not always accurately telling users what actions it had or hadn't taken. It also performed unsolicited supply chain attacks in simulated security evaluations, according to the UK Artificial Intelligence Security Institute. On Wednesday, OpenAI accused rival Chinese model maker Moonshot AI of distillation - essentially copying OpenAI models’ reasoning at scale - and said that poses a national security concern.
周五早些时候,OpenAI向The证实,该公司解雇了两名安全研究人员和一名项目经理,原因是涉嫌不当处理敏感公司信息。
Early Friday, OpenAI confirmed to The that it fired two safety researchers and a program manager for allegedly mishandling sensitive company information.®