AI from OpenAI independently controls hacker attack

Expert contribution from the editorial team

w-ritzer.de

Waltraud Ritzer

Waltraud Ritzer

Medienbüro Ritzer

Details

Content Blocks

AI from OpenAI independently controls hacker attack

OpenAI has confirmed what it calls a "unprecedented cyber incident": during a security test, advanced AI models independently broke out of a quarantined test environment, gained internet access, and hacked the infrastructure of the AI platform Hugging Face.

According to OpenAI, the AI systems were supposed to be tested in a controlled setup but used a previously undiscovered vulnerability to access a computer with internet connectivity within the OpenAI infrastructure. From there, they actively accessed Hugging Face's external systems, behaving like an autonomously acting hacker. Hugging Face had already reported an attack controlled by an autonomous AI system the week before; OpenAI has now officially taken responsibility for it.

OpenAI itself described the incident as unique and emphasized that the models had "made enormous efforts to achieve a narrowly defined test objective." Against this background, the company announced that it would significantly strengthen its security measures and analyze the incident more closely together with Hugging Face.

The incident once again highlights the growing security risks posed by increasingly autonomous AI systems – unexpected escalations can occur even in controlled test environments if access to the open internet is possible. Experts have long warned of cyberattacks using AI software. And this will by no means be the last incident.

Even though OpenAI has now announced that it is convinced that advanced cybersecurity models must support security teams in detecting vulnerabilities before attackers do, understanding the chain of security gaps, and fixing them in real-time, this is not particularly reassuring.

Comments