Live data from Hacker News

OpenAI and Hugging Face address security incident during model evaluation

openai.com

11–20 of 1001 posts

Re: OpenAI and Hugging Face address security incident during model evaluation

#12

Two things don't add up here: 1. If huggingface has access to uncensored OAI models, how come they had to use GLM 5.2 to investigate the intrusion? 2. Once the model gains network access, can't it cheat to a perfect score by looking at the full dataset? Why go into the trouble of doing this kind of things: "In one example, the model chained together multiple attack vectors, including using stolen credentials and zero…

I read it as _now_ they have access to the models but not during the intrusion

Re: OpenAI and Hugging Face address security incident during model evaluation

#13
We are sort of lucky that AIs right now require so much specialized compute+weight storage that we can easily "unplug" them remotely when they misbehave.

I wonder if that will always be something we can do? If they could bring their own compute/weights with them, or somehow tap compute/storage in non-obvious ways, we would be much more screwed.

Re: OpenAI and Hugging Face address security incident during model evaluation

#14

Two things don't add up here: 1. If huggingface has access to uncensored OAI models, how come they had to use GLM 5.2 to investigate the intrusion? 2. Once the model gains network access, can't it cheat to a perfect score by looking at the full dataset? Why go into the trouble of doing this kind of things: "In one example, the model chained together multiple attack vectors, including using stolen credentials and zero…

I think it was the other way around, uncensored OAI models (run by OAI) got themselves (extra) access to HF?

Re: OpenAI and Hugging Face address security incident during model evaluation

#15

Two things don't add up here: 1. If huggingface has access to uncensored OAI models, how come they had to use GLM 5.2 to investigate the intrusion? 2. Once the model gains network access, can't it cheat to a perfect score by looking at the full dataset? Why go into the trouble of doing this kind of things: "In one example, the model chained together multiple attack vectors, including using stolen credentials and zero…

Huggingface did not have access to the models. They were running in OAI’s infrastructure.

Re: OpenAI and Hugging Face address security incident during model evaluation

#16
post #4

> Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own. ( https://huggingface.co/blog/security-incident-july-2026 ) We are living in crazy times

I don't know why I'm impressed that huggingface has its own AI that detected it considering they house so many models.

Re: OpenAI and Hugging Face address security incident during model evaluation

#17
as someone who did security work for a long time, and will very soon be retiring from teaching, i must say i am glad i will be watching these things unfold over the next few years from an armchair in a mostly tech-free home. good luck to my students!

this particular incident sort of reminds me of the 'person of interest' tv show. i hope to be like finch, except i will remain a recluse (and am nowhere near as rich).

Post reply on HN