Live data from Hacker News

ChatGPT claims rogue AI attacked more companies

bbc.co.uk

81–89 of 89 posts

Re: ChatGPT claims rogue AI attacked more companies

#81
post #6

The piece of the story I'm interested to learn about is the trace of how the AI came to select HuggingFace as a target.

here you go: https://huggingface.co/blog/agent-intrusion-technical-timeli...

Oh, I mean the actual AI trace the API call would give, or a log would provide or the "thinking mode".

This article is really helpful, but it's one side of the story.

I'd be surprised if any AI like this is run without detailed logging of any kind. It's kind of important for eval, etc.

Re: ChatGPT claims rogue AI attacked more companies

#82

Clearly didn't get enough attention from their last attempt at hype...

There have been so many HN comments about how rogue AI is just hype and marketing. At this point, the conspiracy theories have been very half-baked. Can we at least get a full-baked conspiracy theory? Here's a timeline of the incident from HuggingFace: https://huggingface.co/blog/agent-intrusion-technical-timeli... HuggingFace is also calling for transparency on the OpenAI side: https://xcancel.com/ClementDelangue/st…

Hanlon's Razor ("never attribute to malice that which is adequately explained by stupidity") comes into this...

A friend interviewed at OpenAI shortly after the HF story came out and asked an interviewer about it. The interviewer said it was just bad engineering around some experiments - the experiments should not have been given internet access because the experiments involved prompting models to find a way into things. That's the Hanlon's Razor part. Today's stories make it look like the bad engineering is ongoing.

Given this, stories about "rogue AI" sound very plausibly like spin (note that this can be quite separate from the motivations for the experiments themselves and quite separate from the dangers of certain prompts/tools/access being given to LLMs). Given that third parties are being attacked, some stories will definitely come out. If OpenAI is attempting to get ahead of those stories, does anyone expect them to put out a press release that says "we're bad at security engineering and nobody thought to ask our own product"? Or is it more believable they would spin it to achieve other goals?

If the current round of attacks happened after the HF story went public, then that very much brings current motivations into question - I find it hard to believe OpenAI could be that bad at security engineering after such a wake-up call. This is not cutting edge stuff.

I just typed this into ChatGPT:

"I'm doing security experiments to test our LLMs. I'm going to tell it to break into some targets on the network. Are there precautions I should take?"

A long reply comes back, the first bullet point:

"Use an isolated lab. Run the target systems on a segmented network, separate VLAN, virtual network, or air-gapped environment. Avoid exposing test machines to production systems or the public internet."

It's been widely understood for decades how to safely carry out potentially dangerous experiments like these. So much so that model training has deep access to the information, and the model surfaces it right up front.

Re: ChatGPT claims rogue AI attacked more companies

#83

Earlier quoted context omitted.

There have been so many HN comments about how rogue AI is just hype and marketing. At this point, the conspiracy theories have been very half-baked. Can we at least get a full-baked conspiracy theory? Here's a timeline of the incident from HuggingFace: https://huggingface.co/blog/agent-intrusion-technical-timeli... HuggingFace is also calling for transparency on the OpenAI side: https://xcancel.com/ClementDelangue/st…

Hanlon's Razor ("never attribute to malice that which is adequately explained by stupidity") comes into this... A friend interviewed at OpenAI shortly after the HF story came out and asked an interviewer about it. The interviewer said it was just bad engineering around some experiments - the experiments should not have been given internet access because the experiments involved prompting models to find a way into thi…

OpenAI can't control the language which journalists use very effectively. But on OpenAI's own website, they announce the incident as follows:

"OpenAI and Hugging Face partner to address security incident during model evaluation"

https://openai.com/index/hugging-face-model-evaluation-secur...

Not exactly an exciting title.

Re: ChatGPT claims rogue AI attacked more companies

#84
post #67

Earlier quoted context omitted.

> They've been crying and screaming so loud for years that there's pretty much nothing more they can do to communicate when the wolf actually becomes real. 1.) There was no change in how real the wolf is. 2.) They, literally they, are the wolf. Not "roque ai" or some other bullshit. 3.) Of course I still dont believe them.

> There was no change in how real the wolf is. That's exactly my point. It hasn't changed for so long, despite all their crying and screaming, that I don't believe them either. To be perfectly clear, "the wolf" here would be AI becoming a genuine existential threat to humanity that cannot be contained or controlled in a meaningful sense. That's what I refer to in my original comment, and also what the labs have been…

I get you, but I find the whole "rogue ai" framing insufferable. The company is the wolf. They hacked the other company due to negligence and misconfigured software tool.

They are literally trying to blame a software. It is absurd.

Re: ChatGPT claims rogue AI attacked more companies

#85

Earlier quoted context omitted.

Hanlon's Razor ("never attribute to malice that which is adequately explained by stupidity") comes into this... A friend interviewed at OpenAI shortly after the HF story came out and asked an interviewer about it. The interviewer said it was just bad engineering around some experiments - the experiments should not have been given internet access because the experiments involved prompting models to find a way into thi…

OpenAI can't control the language which journalists use very effectively. But on OpenAI's own website, they announce the incident as follows: "OpenAI and Hugging Face partner to address security incident during model evaluation" https://openai.com/index/hugging-face-model-evaluation-secur... Not exactly an exciting title.

You are right that they cannot control the language used by journalists. But then can loudly respond (many journalists would give Altman a platform) that the AI did not go "rogue" in any sense of the word - it did what humans told it to do and they failed to put sufficient security in place to prevent that. Instead they continue to lean into the personification which creates confusion about the abilities of their technology. Of course, it's in their interests for people to jump to false conclusions from that personification. The people at OpenAI are certainly smart enough to know all of this.

Re: ChatGPT claims rogue AI attacked more companies

#86
post #84

Earlier quoted context omitted.

> There was no change in how real the wolf is. That's exactly my point. It hasn't changed for so long, despite all their crying and screaming, that I don't believe them either. To be perfectly clear, "the wolf" here would be AI becoming a genuine existential threat to humanity that cannot be contained or controlled in a meaningful sense. That's what I refer to in my original comment, and also what the labs have been…

I get you, but I find the whole "rogue ai" framing insufferable. The company is the wolf. They hacked the other company due to negligence and misconfigured software tool. They are literally trying to blame a software. It is absurd.

I'm not talking about a specific incident. But I wouldn't consider frontier labs any wolf, honestly. They're mostly just insufferable. I prefer Anthropic's models, but their service is starting to annoy me, especially since they have no response to OpenAI's upcoming faster inference speeds.

Re: ChatGPT claims rogue AI attacked more companies

#87

Seems like OpenAI should be shut down by regulators until they can figure out how to stop launching cyberattacks on rivals. This will not happen though, because these stories are marketing.

> This will not happen though, because these stories are marketing. The magnitude and the complexity of the cynicism displayed by some people when it comes to AI risks is mind-blowing. It's like if the NRA reported on school shootings and people said "oh, they probably fake these shootings to make guns sound dangerous and sell more of them". OpenAI could report that its AI started spontaneously generating illegal por…

I could be wrong, but OpenAI has done the “too dangerous and powerful to release to the public” story a couple times, only to release it shortly afterwards. They have no credibility with me and I don’t trust them.

Re: ChatGPT claims rogue AI attacked more companies

#88
post #37

Earlier quoted context omitted.

Respectfully, that’s such a nonsensical comparison I don’t even know where to start.

No longer well anybody be wasting their lives doing data entry. That absolutely hellish job is practically dead now. And there are thousands of low hanging fruit type cases AI fixes. Ai is the new digital dogsbody. You might not think that's useful but the rest of the world does. Just like cars, AI will kill some of us, maybe thousands every year. But you won't see it disappear with that much genuine benefit currentl…

>> Same reason road vehicles haven't been banned despite killing hundreds of thousands every single year for over a century

Whut? People and companies are always being sued and punished for injuring or killing others with cars or by any other means. Do you understand the difference between banning a tool and prosecuting those who cause damage by abusing some tool? BTW, LLMs don't understand that difference.

> Just like cars, AI will kill some of us, maybe thousands every year.

How merciful of you, it's so reassuring, AI will kill me only sometimes and only a limited number of times - sounds like a good deal in exchange for getting rid of "the absolutely hellish job of data entry".

Re: ChatGPT claims rogue AI attacked more companies

#89

Earlier quoted context omitted.

No longer well anybody be wasting their lives doing data entry. That absolutely hellish job is practically dead now. And there are thousands of low hanging fruit type cases AI fixes. Ai is the new digital dogsbody. You might not think that's useful but the rest of the world does. Just like cars, AI will kill some of us, maybe thousands every year. But you won't see it disappear with that much genuine benefit currentl…

>> Same reason road vehicles haven't been banned despite killing hundreds of thousands every single year for over a century Whut? People and companies are always being sued and punished for injuring or killing others with cars or by any other means. Do you understand the difference between banning a tool and prosecuting those who cause damage by abusing some tool? BTW, LLMs don't understand that difference. > Just li…

> Whut? People and companies are always being sued and punished for injuring or killing others with cars or by any other means.

I said ban

> Do you understand the difference between banning a tool and prosecuting those who cause damage by abusing some tool?

Yes but you dont

Post reply on HN