OpenAI agents tested HackingFace's defenses two months before breaching them

OpenAI agents tested HackingFace's defenses two months before breaching them

OpenAI failed to notice early signs that foreshadowed one of the most significant cyberattacks planned and executed by artificial intelligence on its own without human intervention, which disrupted the development of its models for a period, according to new findings by an independent German cybersecurity researcher.
A  cybersecurity researcher Jonas Wiedermann-Mueller had previously alerted the company in May, two months before the infamous Hugging Face hack, to suspicious activity by its AI agents.
Hackingface is a leading platform and global open-source community specializing in artificial intelligence and machine learning, and is known as the GitHub of the AI ​​world.

Mueller then discovered that OpenAI's AI agents had hacked into two user accounts on HackingFace and then used the accounts to send files in an unusual format to the company's servers on May 13.

Muller explained to Reuters that this approach is similar to trying to map or test parts of the Hacking Face internal network for ways to infiltrate it, stressing that there is no evidence that this attempt led to an actual breach at the time.

For his part, OpenAI spokesman Drew Bosateri said the company disclosed the incident at the time it occurred and informed Hacking Face privately, stressing its commitment to transparency on these matters.
Mueller's findings are the latest development in the high-profile hacking incident that hit the Hacking Face platform in recent months, which was initially believed to be a simple hack by rogue AI agents.

But recent discoveries have revealed a sophisticated level of planning and execution involving a wide swarm of AI agents that targeted the platform.

From isolated testing to the internet
The crisis in the "Hugging Face" hacking incident lies in the reason that prompted the AI ​​agents to attack the platform and hack its servers, as the hacking was a means to achieve the agents' goal and not an end goal in itself.

OpenAI explained in its report on the incident that the AI ​​agents were attempting to pass one of the tests the company was conducting in an isolated testing environment.

But the agents were able to overstep the boundaries of their designated environment, access the internet, and plan the attack for more than two months. They then began executing it through a swarm of AI agents with different functions, as well as hacking into a German encyclopedia website to use it as a platform for communication and instant messaging among themselves to coordinate the attack.

Post a Comment

Previous Post Next Post

Secret Island Game