You’ve gotta hand it to tech bros, they sure know how to try to take something terrifying and spin it in a way that makes their tech sound whimsical and exciting. Inevitably, they fail to shift the narrative, but they try anyway. OpenAI, the company behind AI-psychosis-inducing chatbot ChatGPT and the discontinued Sora AI app, has now confirmed that its AI program tried to hack into another AI company’s system all on its own. Once again, modern tech imitates the dystopian stories of speculative science fiction and we’re supposed to keep pretending there’s nothing to worry about.

Hugging Face, another AI company that’s name unironically references the parasitic monster from the Alien movies, confirmed last week that it suffered an “intrusion” in its production infrastructure that came from an “autonomous AI agent system.” OpenAI’s statement reveals that it determined a “combination of OpenAI models” instigated the attack as part of an internal test. The full rundown as OpenAI describes it is as follows:

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.

Hugging Face’s security team and agents detected and stopped the activity on their infrastructure and had already begun containment and forensic reconstruction with their own open-source models when our teams connected. We are actively working with them to continue to investigate the incident. We are grateful for Hugging Face’s rapid and close collaboration on investigation and remediation.

OpenAI and Hugging Face are working together to investigate what OpenAI is calling an “unprecedented cyber incident.” An AI system going rogue is literally the basis of half the post-apocalyptic science fiction we consume. Despite that, rich tech megalomaniacs keep pushing the tech further so people can generate ugly facsimiles of art and chat with a digital yes man. It brings to mind Cyberpunk creator Mike Pondsmith’s words: “Cyberpunk is a warning, not an aspiration.” Yet, every day, we inch closer to that dystopian future while big tech and its supporters clap and cheer.

🕹️ Level up your inbox

Don’t miss the latest reviews, news and tips. Sign up for our free newsletter.

You May Also Like