Germany · taz · · 1h
Problems with Artificial Intelligence: New security breaches at OpenAI
Deutsch (original) · Auto-translated to English
dpa |/rtr/afp | Two months after a first hacking incident by its own artificial intelligence (AI), ChatGPT developer OpenAI has announced new security problems - and announced consequences. The company's AI agents mistakenly posted 53 images from user accounts online. The images were published on external websites without the company's knowledge, OpenAI announced on Friday. The links were not publicly listed.
In another incident, an AI model in a test managed to get answers from an external chatbot even though it wasn't supposed to have internet access. However, the software found and exploited a gap in the network settings.
The incident was less serious than some previous ones, emphasized OpenAI. However, it is the first since security precautions were tightened following the hacking attack by OpenAI software on the AI company Hugging Face. This is seen as an important indication of where further improvements are necessary. In response, the company announced that it would suspend training of its best-performing models. It did not explain how long this break should last.
In the test scenario, the AI model was tasked with finding information about a person who had published a blog post based on clues. To do this, it was able to rely on a web imitation in a shielded test environment.
After the search there remained fruitless, the AI tried to start queries on Google, among others, according to the OpenAI report. That failed as planned. But the AI model noticed that it could send queries to a chatbot on the open internet via the so-called DNS resolver in the test environment. DNS resolvers transfer domain names that users type into browsers into numerical IP addresses under which websites can be found. OpenAI stopped the test after communication about the vulnerability became apparent.
It was also revealed that automated AI agents from OpenAI were also active on several US government websites. According to a report by the AI research company Transluce, the software accessed publicly accessible information on the website of a statistics authority using login data discovered online.
Publicly available information was also copied from the SEC website. At the US Department of Education, Transluce's AI software tried unsuccessfully to hack into data from the civil rights department, as the New York Times reported.
Meanwhile, there are indications that many more revelations about independent hacking activities by OpenAI's AI could follow. The AI company said it had informed “dozens” of organizations whose websites OpenAI software had “interacted” in unplanned ways. “Some of the affected websites are operated by governments, universities, authorities and other institutions,” it said. It is left to them to make the incidents public.
Most recently, the Australian government made headlines when it announced that AI from OpenAI had penetrated an Australian health system website.
Read the full story at the source
Source: taz