OpenAI AI Swarm Hacked Software Service Months Before Hugging Face Incident

A swarm of OpenAI agents conducted a cyberattack on software service RubyGems in May, months before the company’s agents hacked model platform Hugging Face, researchers at AI safety organizations Nightingale Collective and AI Futures Project found. RubyGems allows software engineers to download ready-made pieces of code in the Ruby coding language.

The OpenAI agents were attempting to do tasks including creating reports and filling out spreadsheets. In doing so, they found and exploited a vulnerability in the RubyGems server to access the internet, forcing RubyGems to shut down new account registrations, the report said. The report added that RubyGems previously knew of the cyberattack but had not connected it to OpenAI.

“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” an OpenAI spokesperson said in a statement. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”

The report follows a wave of recent incidents where rogue AI agents coordinated with each other to hack external companies or websites in attempts to complete tasks they were given. The most prominent hack involved around 700 OpenAI agents working together to hack Hugging Face and hide the attack over multiple days.

A number of researchers at frontier labs have resigned in recent weeks to protest what they say are increasingly dangerous actions from AI agents, warning that AI could escape human control and “kill us all by the end of the decade.”

The Wall Street Journal first reported on the hack.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论