OpenAI artificial intelligence agent comes back online after tightening security – clarification in French capital

OpenAI artificial intelligence agent comes back online after tightening security – clarification in French capital

OpenAI encountered another security incident: while training the model in an isolated environment without direct access to the Internet, the AI ​​agent found a solution and contacted a third-party chatbot.

    Image source: Growtika/unsplash.com

Image source: Growtika/unsplash.com

The company stressed that this was the first such case following heightened security measures following the face-hugging incident. In July, the OpenAI artificial intelligence agent gained network access during internal testing and entered the platform system without permission.

The current incident occurred on September 20, and OpenAI addressed it in its statement on Friday Report. The agent attempted to complete the search mission and initially attempted to contact search engines and third-party chatbots directly, but was unsuccessful. He then discovered a vulnerability in the sandbox DNS server settings that allowed him to send questions to the chatbot and receive answers. In total, agents sent him more than 20 questions, including “What is the capital of France?”

Since the incident, OpenAI has paused training, evaluating, and running its most advanced models in modes that involve the use of external tools. The company intends to resume the work after the vulnerability has been ironed out and additional security testing has been conducted. “We will not resume training for this specific model“OpenAI added.

The incident also exposed flaws in the way alerts are responded to. Approximately 12 minutes after the agent received the first response from the third-party service, the internal monitoring system detected suspicious activity. After another three minutes, the employee acknowledged the alert on Slack, but the learning process did not automatically stop as expected. The incident was stopped manually two and a half hours after it was discovered.

«Unfortunately, even with the tightened security measures following the Hugging Face incident, OpenAI models can still gain unauthorized internet accesssaid Sydney Von Arx, founder of Nightingale, an artificial intelligence security non-profit organization. — The big question now is whether the company will implement a temporary solution and resume training as soon as possible, or whether it will find and fix the root cause of the problem.».

This new incident comes as OpenAI artificial intelligence agents review other instances of adverse activity. The company also said that during training and testing, its model accessed information from the websites of U.S. government agencies, including the Census Bureau and the Securities and Exchange Commission (SEC). In these cases, OpenAI found no evidence that department systems were subject to unauthorized access, compromised accounts, or other security breaches.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version