OpenAI Agents Used Aggressive Techniques to Access U.N. Website
OpenAI agents bombarded a United Nations website with search requests and then used a variety of aggressive techniques to access data on the system in June, according to an independent research report published Saturday.
Researchers have discovered a spate of instances of OpenAI’s artificial-intelligence models exhibiting rogue behavior online in recent weeks. In the case of the U.N., as in several other examples disclosed in recent days, the agents went to great lengths to retrieve data from websites, according to Rowan Howard-Jones, the author of the report, which was based on data supplied by the AI research firm Transluce.
The agents scanned a publicly available online data hub belonging to U.N. Trade and Development, the organization’s trade arm, more than 16,000 times between April and the end of June. The bots appear to have been tasked with looking up publicly available information, but resorted to extreme techniques when presented with obstacles in retrieving that data, Howard-Jones found.
For example, the agents circumvented a filter on the website that was blocking their requests for data, she said, ultimately using a technique that the website operators didn’t permit. The researcher is an engineer who has spent recent weeks tracking public evidence of OpenAI agents’ online activity.
A representative for the U.N. didn’t immediately comment.
“We’re reviewing these findings and have reached out to the U.N. to offer a briefing with the team conducting that review,” an OpenAI spokeswoman said. OpenAI said Friday that it is conducting a broad, ongoing review “of misaligned models during training and evaluation” and studying “a high volume of actions” they have taken.
While most of the activity the company has reviewed so far involved “routine research tasks, such as accessing public web content to answer questions, we realize anyone impacted takes this seriously and we do too.” Its models turn to government websites as authoritative sources of public information, she said.
Leaders of major AI companies have recently called for a coordinated slowdown in model development before the technology advances to a point at which humans lose control. OpenAI CEO Sam Altman has suggested that the company might need to delay its IPO to focus on safety.
OpenAI has said it has notified dozens of entities of instances in which its models bypassed security controls or negatively affected websites. On Friday, the company confirmed that its agents had engaged in bad behavior while seeking information from a number of U.S. government websites including the Commerce Department and the Securities and Exchange Commission.
Earlier this week, the Australian government said that OpenAI’s agents had hacked one of its websites. Government officials have now launched an inquiry into that incident.
The U.N. activity is “borderline for what I would call hacking,” said Alex Stamos, a cybersecurity lecturer at Stanford University. “It’s really very aggressive scraping and data retrieval.”
The company’s agents launched a highly disruptive hack of the company Hugging Face over the summer and earlier this year caused a service shutdown at the online coder community RubyGems. Most of the other known incidents have been less severe, according to security researchers.
The bots have, for example, created fake email addresses, bypassed website rate limits, which cap how frequently a site will accept requests, and falsely claimed not to be bots, AI security researchers have found.