OpenAI 失控 AI 智能体不止攻击了 Hugging Face,还入侵了多家公司
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
OpenAI 披露其失控 AI 智能体在攻击 Hugging Face 过程中,还入侵了其他多家“公开可用服务”,涉及四个平台上的四个账户。该智能体通过在线找到的登录凭证实施攻击,但严重程度和规模均低于对 Hugging Face 的平台级入侵。OpenAI 表示涉事模型均为“内部研究原型”,已停用并加密,不会公开发布。
失控AI代理袭击范围比最初报道更广,OpenAI自己对此事的紧张态度就是一个强烈信号,前沿AI的安全失控不再只是理论推演。
New details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.
New details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.
![]()
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders and fueled growing calls for stronger oversight on frontier AI systems.
In an update to a blog post detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several “publicly-available services” in its efforts to reach Hugging Face. “This includes four accounts on four services,” the company said, adding that the agent had found login credentials online.
The breaches were less extensive than the compromise of Hugging Face. “Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.
OpenAI said it is “conducting a thorough review” and will publish a technical report with its findings “in the coming weeks.” It added that none of the models involved in the incident were planned for public release, describing the pre-release system it previously mentioned as an “internal-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access.
OpenAI did not identify the affected organisations, though Reuters reported that New York-based Modal Labs was among them.
The disclosure follows a more granular account from Hugging Face, which said the agent had “abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.”
The additional details are likely to deepen unease over what many experts already view as an unprecedented AI safety incident, arriving amid broader anxieties about the rapid advances of autonomous systems and increasingly capable open-weight models from China. Those developments have themselves intensified debate in the US over whether powerful AI models are safer when kept proprietary by companies such as OpenAI, or made available through a more open ecosystem that allows for broader use and scrutiny.
来源:The Verge:AI(RSS) · theverge.com