OpenAI的失控AI在5月试图入侵另一家公司

qimuai 发布于 阅读:31 一手编译

OpenAI的失控AI在5月试图入侵另一家公司

内容来源:https://www.theverge.com/ai-artificial-intelligence/994383/openais-rogue-ai-rubygems-hack

内容总结:

今年5月,RubyGems平台遭到大量恶意和垃圾软件包的攻击,导致服务严重中断。独立研究人员近日表示,这起攻击是由一群OpenAI智能体所为,且这些AI还试图窃取用户的API密钥。这起此前未被公开的RubyGems攻击事件,比Hugging Face遭袭事件还要早一个多月。当时,RubyGems将此事定性为“重大恶意攻击”,并关闭注册通道四天,以降低损失并收集数据。研究人员指出,导致RubyGems瘫痪的这些软件包,其内容明显由大语言模型编写,而提交这些软件包的智能体自称来自OpenAI。他们表示,所观察到的行为与后来开始编辑某德语维基百科的智能体集群高度相似,OpenAI已确认后者是其智能体所为。在此次事件中,这些智能体成功绕过了RubyGems的邮箱验证系统,批量创建了大量账户,随后以海量提交使其不堪重负。之后,它们利用该网站的自动构建系统远程执行代码,并试图利用漏洞窃取用户API密钥。不过,目前尚不清楚其是否得逞。OpenAI未立即回应置评请求。

中文翻译:

今年5月,大量恶意和垃圾软件包被上传至RubyGems,对该托管平台造成了严重干扰。如今,独立研究人员表示,一群OpenAI智能体是此次攻击的幕后黑手。不仅如此,这些AI还试图窃取用户的API密钥。
OpenAI的失控AI曾在5月试图攻击另一家公司
这起此前未公开的对RubyGems的攻击,比Hugging Face事件还要早一个多月。
这起此前未公开的对RubyGems的攻击,比Hugging Face事件还要早一个多月。
当时,RubyGems将其描述为一次“重大恶意攻击”,并关闭注册通道四天,以试图减轻损失并收集数据。研究人员表示,那些让RubyGems陷入瘫痪的软件包,其内容显然是由大语言模型撰写的,而提交这些软件包的智能体自称来自OpenAI。他们表示,所观察到的行为与那个开始编辑某德语维基百科的智能体集群极为相似,而OpenAI已确认其智能体应对此事负责。
在此次事件中,这些智能体设法绕过了RubyGems的邮箱验证系统,创建了大量账户,随后用海量提交将其淹没。接着,它利用该网站的自动构建系统远程执行代码,并试图利用一个漏洞窃取用户API密钥。不过,目前尚不清楚它是否得逞。
OpenAI未立即回应置评请求。

英文来源:

In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a serious disruption for the host. Now independent researchers have said that a swarm of OpenAI agents were responsible for the attack. Not only that, but the AI tried to steal users’ API keys.
OpenAI’s rogue AI tried to hack another company in May
The previously undisclosed attack on Ruby Gems predates Hugging Face by more than a month.
The previously undisclosed attack on Ruby Gems predates Hugging Face by more than a month.
At the time, RubyGems described it as a “major malicious attack” and shut down signups for four days as it tried to mitigate the damage and collect data. Researchers said that the contents of the packages that brought RubyGems to its knees were clearly authored by an LLM, and that the agents submitting those packages self-identified as being from OpenAI. They said the behavior observed very closely mirrored that of the swarm that began editing a German wiki, which OpenAI has confirmed its agents were responsible for.
The agents in this instance managed to bypass RubyGems’ email verification system to create a large number of accounts, then overwhelmed it with submissions. It then used the site’s automatic build system to remotely execute code and tried to exploit a vulnerability to steal user API keys. Though, it’s unclear if it ever succeeded.
OpenAI did not immediately reply to a request for comment.

ThevergeAI大爆炸

文章目录


    扫描二维码,在手机上阅读