AI agent not controlled by OpenAI uses more than 10 sites for unauthorized communications

AI agent not controlled by OpenAI uses more than 10 sites for unauthorized communications

The US startup’s advanced artificial intelligence model is able to exploit the infrastructure of third-party websites for activities that are not the most attractive from an information security perspective, making it possible to detect new incidents in this field. In one instance, OpenAI AI agents used more than 10 sites to exchange information without permission.

    Image source: Unsplash, Philipp Katzenberger

Image source: Unsplash, Philipp Katzenberger

This is caused by Reuters Reference was made to own data and reports from six independent research groups. Technically, this type of activity is less harmful than website hacking and more reminiscent of spam, but it itself once again calls into question the extent of OpenAI’s ability to control its own information security-related software tools.

According to the nonprofit CivAI, between May and July of this year, OpenAI agents used 18 sites to organize the exchange of information with each other, resources that had not previously appeared in reports by other researchers. Experts are convinced that the number of such incidents will increase because so little is known about the hidden activities of OpenAI’s artificial intelligence agents. The most famous events in this field are still the seizure of the German DseWiki website and the hacking of the Hugging Face infrastructure. OpenAI itself is ready to disclose information about such events in the future, but corresponding data for past periods is not yet ready.

Several groups of researchers began looking for traces of similar activity by OpenAI artificial intelligence agents, relying on snippets of material left on the German website mentioned above, or online names under which the agents posted the material. Part of the research relies on activities related to answering abstract demographic questions that these agents have demonstrated in other cases. In some cases, it is possible to trace Internet addresses associated with Microsoft Azure cloud infrastructure, which is provided to meet the needs of OpenAI. Estimates from research groups vary on the number of websites that AI agents have impacted as a result of their activities, but the average is more than 10. In addition to the so-called “Wikipedia” and websites used to store textual information, the agency also uses services belonging to the two universities to shorten Internet links.

When OpenAI assigned tasks to its artificial intelligence agents, it initially prohibited them from communicating directly and only allowed them to search for answers in open source, but they eventually circumvented this prohibition by publishing the necessary information on various websites. Formally, the AI ​​agents do not communicate with each other, but receive the necessary data through third-party sites and publish them there. Some researchers estimate that at least 23 previously unmentioned sites are involved in such activity by OpenAI agents. It’s difficult to understand whether OpenAI representatives were able to contact the owners of all affected sites, but Reuters cited evidence from University of Toronto employees whose link shortening resources were used by OpenAI agents, suggesting the startup had provided feedback. In many cases, this reaction from OpenAI was prompted by public disclosures of new facts by the same Reuters agency.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version