On how OpenAI lost control of an AI Model that ended up attacking Hugging Face

On July 21st OpenAI published this piece about how they and Hugging Face partnered to address a security incident during model evaluation. Like many people, I was shocked by the news of how agents at OpenAI broke out of their secure environment and attacked the Hugging Face site.

Later, though, in reading other pieces, I was less focused on how impressive the agents were and how poor a job the OpenAI team did. Reading this piece in TIME, it appears the agentic software was left unmonitored on the weekend. That was bad enough. Worse, the secure environment was not air gapped in any way. Once the agents figured out how to break through any software barriers between them and the Internet, they were free to wreck havoc on the outside world.

As the San Francisco Examiner states: “A recent hacking incident involving a pair of OpenAI’s artificial-intelligence models highlights the cybersecurity risks of the technology — and a serious security lapse by the San Francisco company, computer-security experts say.” Indeed.

For more on how OpenAI screwed up, see the pieces linked to here.

P.S. It gets worse…I just came across this: OpenAI’s rogue models roamed the internet for 4 days and staged a second attack – POLITICO

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.