praegune kellaaeg 22.07.2026 16:23:16
|
|
Hinnavaatlus
:: Foorum
:: Uudised
:: Ärifoorumid
:: HV F1 ennustusvõistlus
:: Pangalink
:: Telekavad
:: HV toote otsing
|
|
| autor |
|
Tanel
HV Guru

liitunud: 01.10.2001

|
|
| Kommentaarid: 465 loe/lisa |
Kasutajad arvavad: |
   |
:: |
5 :: |
7 :: |
362 |
|
| tagasi üles |
|
 |
1dumbpcuser
HV Guru
liitunud: 05.03.2002
|
22.07.2026 12:21:38
|
|
|
https://www.msn.com/en-in/money/news/rogue-openai-model-hacked-huggingface-on-its-own-company-used-chinese-ai-to-contain-it/ar-AA28pNCv
| tsitaat: |
How did OpenAI models go rogue?
The incident was part of the ExploitGym evaluation. According to OpenAI, the models were supposed to operate inside a sandbox with no direct internet access. Rather, they were only connected tool to download approved software packages.
But instead of solving the benchmark, the AI models were more focused on trying to find the answers via the internet. OpenAI explained that the the models "spent a substantial amount of inference compute finding a way to obtain open Internet access." These rogue models identified a zero-day flaw in the download tool, and managed to exploit this to find their way to an OpenAI machine with internet access.
Once online, the models concluded that the answers to ExploitGym were likely stored on Hugging Face, which hosts AI models, datasets and related resources. These rogue OpenAI models then gained credentials for HuggingFace, and tried to get the answers for this test from its database.
In effect, they bypassed the test rather than solving it, like a student leaving a locked exam room to steal the answer sheet from elsewhere.
HuggingFace uses Chinese AI to contain rogue OpenAI models
HuggingFace's team was quick to detect and block the attempt made by the rogue models. The company's security team used GLM 5.2, an open-weight Chinese model from Z.ai, to analyse the attack.
HuggingFace resorted to GLM 5.2 after mainstream commercial -- think from US AI labs, though the company does not disclose which models it tried – refused to process the logs and analyse the attack due to their safety guardrails treating the forensic work as potentially harmful activity. That is, these frontier models could not differentiate that HuggingFace was trying to use them to stop an attack, and not to start one.
The company then switched to GLM 5.2, running it on its own infrastructure, which allowed it to reconstruct the attack timeline more quickly while keeping sensitive data inside its own environment.
According to the company, the attack exploited two code-execution paths in Hugging Face's dataset processing pipeline and reached internal datasets and service credentials. HuggingFace CEO Clem Delangue later said there was no evidence of malicious intent and wrote, "It's quite mind-blowing that all of this happened autonomously!"
This incident is particularly important as in the past the US has limited access to frontier models like GPT-5.6 Sol and Claude Mythos over concerns about cybersecurity.
However, in this case, a US company was forced to use a Chinese AI model to protect its systems since the US AI models likely had too many guardrails.
Following the incident, OpenAI has imposed stricter controls on its research infrastructure and patched affected systems. The company has also disclosed the zero-day to the third-party vendor behind the download tool, informed law enforcement and relevant authorities. Hugging Face has also been added to OpenAI's trusted access programme for cyber defence. |
_________________ M: MSI B660M MORTAR
M: Dell RTX 2060
O: AM5 ITX emaplaat |
|
| Kommentaarid: 103 loe/lisa |
Kasutajad arvavad: |
   |
:: |
1 :: |
1 :: |
97 |
|
| tagasi üles |
|
 |
Tanel
HV Guru

liitunud: 01.10.2001

|
22.07.2026 14:58:04
|
|
|
https://www.am.ee/openai-tunnistas-nende-uus-mudel-hakkis-iseseisvalt-teist-firmat
| tsitaat: |
Pääsenud vabasse internetti, tegi tehisarumudel jahmatavalt inimliku ja loogilise järelduse: kuna test kannab nime ExploitGym, siis suure tõenäosusega asuvad selle testi lahendused ja andmestikud Hugging Face'i platvormil.
Nagu osav sissemurdja, otsis mudel kohe viise, kuidas nendele salajastele andmetele ligi pääseda. Tehisintellekt kombineeris mitmeid erinevaid ründemeetodeid, kasutas varastatud paroolide ja täiendavate turvaaukude kombinatsioone, et leida viis koodi kaugkäivitamiseks (remote code execution) Hugging Face'i serverites. Lõppkokkuvõttes õnnestus mudelil pääseda otse Hugging Face'i andmebaasi ja tõmmata sealt alla testi lahendused. Sisuliselt masin spikerdas edukalt.
Õnneks märkasid ebatavalist tegevust peagi nii OpenAI turvameeskond kui ka Hugging Face'i enda kaitsesüsteemid, mis reageerisid kiirelt ja peatasid ründe enne, kui kahju oleks võinud laieneda. |
_________________ Erakopeerimistasu tõstmise ettepaneku tagasilükkamine
Hinnavaatlus.ee - leia parim hind!
HV-s ID-kaardiga autentimine |
|
| Kommentaarid: 465 loe/lisa |
Kasutajad arvavad: |
   |
:: |
5 :: |
7 :: |
362 |
|
| tagasi üles |
|
 |
|
| lisa lemmikuks |
|
|
sa ei või postitada uusi teemasid siia foorumisse sa ei või vastata selle foorumi teemadele sa ei või muuta oma postitusi selles foorumis sa ei või kustutada oma postitusi selles foorumis sa ei või vastata küsitlustele selles foorumis sa ei saa lisada manuseid selles foorumis sa võid manuseid alla laadida selles foorumis
|
|
Hinnavaatlus ei vastuta foorumis tehtud postituste eest.
|