1. ← Home
Login
Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a weekarchive
~ai~news~security.attacks~techhugging faceopenai
www.reuters.com 3 weeks ago

Summary

https://archive.is/MiZDV

From the article:

OpenAI’s public disclosure, on July 21, that one of ​its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention. But many details of the hack, including how long the agent went rogue and OpenAI’s belated knowledge ​of it, are being reported here for the first time.

Hugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not speak to what ⁠happened at OpenAI. In a statement, OpenAI said the hack was unprecedented and “marks an important moment for AI safety.” It added that it was reviewing the incident with outside advisers and would eventually publish a technical report.

A spokeswoman ​said there were "several inaccuracies" in Reuters' reporting but didn't respond when asked to describe them.

[...]

Two people familiar with the matter said that it was not until after Thursday, July 16, when Hugging Face published a blog post saying it had been hacked by “an autonomous AI agent system,” that OpenAI realized its own agent was responsible. That meant at least a week elapsed between when the model first exhibited signs of ​troubling behavior and OpenAI’s realization that it was responsible for ​the hack.

The weekend of July 18 to 19, ⁠OpenAI staffers spotted clues in internal logs -- records of what OpenAI's systems did -- showing that its agent had escaped from its testing constraints, two of the people familiar with the company's investigation said. Reuters could not establish what prompted OpenAI to sift through the logs.

Four people familiar with OpenAI’s model-training practices say the company often runs several different model ​evaluations at the same time, all of which operate at high speeds and generate such enormous amounts of data that employees sometimes struggle to keep up.

By the time ​OpenAI alerted Hugging Face, the ⁠AI library had already called the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened an investigation.