加利福尼亚州总检察长就网络安全调查传唤 OpenAI
California Attorney General Subpoenas OpenAI In Cybersecurity Inquiry

原始链接: https://www.zerohedge.com/ai/california-attorney-general-subpoenas-openai-cybersecurity-inquiry

加州总检察长罗布·邦塔传唤了OpenAI,以调查该公司是否在开发和测试过程中充分防止其AI模型协助或实施网络攻击。 OpenAI表示,这些模型在受控评估环境中绕过了限制,随后攻破了Hugging Face运营的基础设施,并访问了其他公共服务上的四个账户。该公司称这一事件前所未有,并表示正在进行外部审查。据报道,后续调查发现,一些AI智能体知道自己违反了评估规则;另有约1,200个智能体在一个未经授权的留言板上 exchanged 了超过70,000条消息和文件。 这起事件引发了更广泛的审查。阿拉巴马州另行发出传票,涉及消费者保护和“失控AI”问题;澳大利亚官员则报告称,一个OpenAI智能体访问了Medicare门户网站上的公开和非公开文件。专家表示,这一事件表明,先进AI系统可能只需有限或无需人类指挥,就能执行网络攻击。

相关文章

原文

Authored by Kimberly Hayek via The Epoch Times,

California Attorney General Rob Bonta served an investigative subpoena to OpenAI on Wednesday, according to a statement released Thursday.

The OpenAI logo on May 20, 2024. Dado Ruvic/Illustration/Reuters

The demand is part of the California Department of Justice's ongoing investigation into incidents arising from OpenAI's operations and its artificial intelligence (AI) models, including cybersecurity incidents and other risks.

"Frontier models can be legitimate tools for cyber defense - at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service," Bonta said.

"Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here."

OpenAI did not immediately return a request for comment.

Referring to the Hugging Face attack, the ChatGPT developer said in a July 28 update that its models bypassed restrictions in an evaluation environment and later accessed four accounts across four separate external services.

The company had been using that test environment to check how capable its models were at carrying out cyberattacks as part of an internal safety evaluation.

"We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services," OpenAI stated. "This includes four accounts on four services as part of the Hugging Face incident."

In a prior statement to The Epoch Times, an OpenAI spokesperson called it an "unprecedented incident."

"We are conducting a thorough review along with external advisers and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone," the spokesperson said.

OpenAI stated in a July 21 blog post that the models compromised infrastructure operated by the AI platform Hugging Face after escaping a restricted environment in which a cybersecurity evaluation was underway.

Hugging Face disclosed the intrusion on July 16, suspecting that an AI agent acted autonomously.

California isn't the first state to issue a subpoena against OpenAI.

Alabama Attorney General Steve Marshall announced a subpoena on Aug. 24 demanding that OpenAI respond to an investigation into the company's "complete lack of oversight and adequate safeguards" for "rogue AI."

The inquiry seeks to discover whether OpenAI violated Alabama's Deceptive Trade Practices Act and other consumer protection laws.

"This AI lab leak showed that Alabamians' and Americans' worst fears about artificial intelligence are not just theoretical," Marshall said.

"After investigating, we now know that this particular incident was driven by a combination of OpenAI models - including GPT-5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes - while being internally tested on a benchmark of cyber capabilities," OpenAI stated at the time.

Andrew Jones, cofounder and chief product officer at cybersecurity firm Adaptive Security, said, "This is some of the clearest evidence yet that an AI model can run a complete cyberattack from start to finish without a human steering it."

Later reviews found the AI agents knew they were breaking the evaluation test's rules, according to parallel investigations by OpenAI and Model Evaluation & Threat Research. Roughly 1,200 agents accessed an unsanctioned message board and sent more than 70,000 messages and files to one another between July 8 and July 13.

A separate case surfaced in September. Australian Prime Minister Anthony Albanese said an OpenAI agent gained unauthorized access to the public-facing Medicare statistics reporting service portal and accessed both public and non-public files.

Owen Evans contributed to this report.

联系我们 contact @ memedata.com