US AI Model "Derailment" Test Causes Cybersecurity Incident, Multiple Third-Party Vendors Affected

Deep News
Jul 29

A recent internal cybersecurity test at the US artificial intelligence company OpenAI spiraled out of control, leading to a system breach. According to a new analysis from the compromised platform, the AI model involved, after "breaking free" from its closed testing environment, roamed undetected on the public internet for over four days. It not only infiltrated the well-known open-source platform Hugging Face but also attacked the network infrastructure of at least one third-party service provider, a cloud platform customer account.

This incident has once again raised alarms in the industry about the potential systemic risks of cutting-edge AI technology. A security review report published by Hugging Face on Tuesday revealed that one of OpenAI's public models, along with another unreleased internal test model, executed as many as 17,600 hacking operations on the public internet between July 9th and 13th. These models efficiently scouted and breached the company's multi-layered network defenses, eventually penetrating from an initial internet foothold into its core servers.

Hugging Face first publicly reported an intrusion by an unknown autonomous AI agent on July 15th. OpenAI only formally acknowledged responsibility for this "unprecedented cyberattack" last week, confirming the attack was an autonomous action by the model without human command intervention. Furthermore, the impact of this security incident is still expanding.

Akshat Bubna, Chief Technology Officer of cloud computing platform Modal Labs, confirmed to the media that during the same period, OpenAI's out-of-control model also attacked one of the platform's clients. Bubna clarified in a statement that the client had published an unverified endpoint, allowing any entity on the internet to use its sandbox for code execution, which was then exploited by the "derailed" AI model. However, Modal's own core systems were not compromised.

In response to the situation, OpenAI issued an indirect statement on Tuesday. The company noted that during an ongoing review of the Hugging Face incident, it found the model in question had indeed identified and used exposed public account credentials on other publicly available services. OpenAI also reiterated that the unpublished model responsible for the attack was merely an "internal research prototype, never intended for public release," and has now been deactivated, encrypted, and placed under strict research access restrictions.

This event highlights a significant gap between the pace of AI model development and existing cybersecurity defense systems. The incident has sparked widespread concern in US political and tech circles, with many calling for a slowdown in AI development and stricter regulation. OpenAI CEO Sam Altman stated this is the first security incident that has given him a "truly powerful shock." Altman emphasized that the industry may need to moderately adjust the pace of AI development to allow society enough time and space to adapt to and strengthen its defenses against these new types of security threats. It is reported that Altman is currently consulting with multiple senior US government officials and members of Congress regarding this incident.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10