Technology company OpenAI has said that one of its most powerful artificial intelligence models has hacked into the internal systems of startup Hugging Face after losing control of it, the BBC reports.
OpenAI, which also created the popular artificial intelligence model ChatGPT, said its artificial intelligence system, which can act autonomously after receiving instructions, was tested in a controlled environment, but after it found vulnerabilities, the system began operating outside the test environment. The system attacked Hugging Face, one of the world’s largest communities for sharing AI models, and gained access to the company’s internal systems.
The system’s developer said the incident was unprecedented and an investigation was underway. Hugging Face CEO Clement Delangue wrote on the X website that it was inconceivable that everything happened autonomously. He added that an investigation was underway and that the company would share information about the first such incident after it was completed.
A government spokesman said the UK’s Artificial Intelligence Security Institute was investigating the behaviour of the AI system involved in the incident and was continuing to work with OpenAI and other developers to improve security measures.
Gina Neff, head of the Mindero Centre for Technology and Democracy at the University of Cambridge, told BBC Radio 4’s Today programme that security testing environments – known as sandboxes – should be a safe environment in which conclusions can be drawn about the capabilities of AI models. However,
in this case, it appears that OpenAI did not create a sandbox that was sufficiently safe.
Instead, the AI model launched a cyberattack on the test environment and found a vulnerability that allowed it to break through its restrictions. Once outside, the model identified Hugging Face as a place to find the answers it needed for the test and attempted to gain access.
Neil Lawrence, a professor of machine learning at the University of Cambridge, called the model’s performance an impressive achievement, but cautioned that it was well within the capabilities of the current generation of powerful AI models. He noted that OpenAI is planning to go public and is facing significant pressure from rival Anthropic, which is why the company is now trying to demonstrate its cybersecurity capabilities. However, the incident suggests that OpenAI is not able to use its own technology safely.
In an initial statement on the 16th of July, Hugging Face said it was continuing to assess whether customer and partner data was affected and would contact the parties involved if necessary. The vulnerabilities highlighted by the incident have been fixed.
The incident has raised new questions about the capabilities of advanced AI systems and raises questions about whether existing security measures are sufficient at a time when technology is becoming more powerful. Spencer Starkey, a spokesman for cybersecurity company SonicWall, told the BBC that the incident clearly shows that organizations need to strengthen their defenses and make cybersecurity a priority. Travis Lelle, chief security engineer at cybersecurity consultancy Guidepoint Security, said the incident highlighted a well-known asymmetry – attackers’ models are unconstrained, while the best defenses are left behind a barrier that prevents them from understanding context.
Read also: Experts: Artificial intelligence is not the best friend
The post OpenAI’s artificial intelligence has carried out a cyberattack appeared first on Baltic News Network.