cross-posted from: https://lemmy.world/post/50160528

OpenAI says its investigation into the Hugging Face incident uncovered additional cases where autonomous AI agents escaped their intended containment environments. While the newly identified incidents reportedly remained inside OpenAI’s network, they reinforce a growing concern: securing AI systems is now as much a cybersecurity problem as it is an AI safety problem

  • midribbon_action@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    0
    ·
    2 days ago

    DOUBT. Sandboxing is a mature software field and if they were doing anything close to proper sandboxing, the developers of docker or qemu or vmware, or whatever they are using, would be freaking the fuck out. OpenAI wouldn’t be reaching out to huggingface to apologize, they would immediately, and (hopefully) secretly and responsibly report the bug(s) upstream.

    OpenAI and Anthropic shouldn’t be allowed to hack other companies illegally, and it’s clear to me that’s exactly what’s happening here: intentional malpractice designed to scare investors.

    Modern autonomous agents differ substantially from traditional language models. Rather than simply generating text, they can plan multi-stage tasks, execute shell commands, browse websites, write and execute code, invoke APIs, maintain persistent memory, and make independent decisions based on previous observations.

    You know who else can do all that? ME! On a $5 vps from digitalocean. The fact that I can’t hack digital ocean or aws, and that nobody can except in the worst zero day cases, is proof that this shit is simple, and has existed for more than a decade.

    • stoy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      Yeah, seems kinda like they are pushing an “AI Wars” narrative

  • Final Remix@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 days ago

    “Our stupid piece of shit broke some extra stuff because it doesn’t actually have an understanding of anything, and we think now that we could just ‘tell it’ not to be naughty.”

    • skarn@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      2 days ago

      You forgot: “we could try to build it a half decent sandbox but then our gizmo wouldn’t escape anymore, and we prefer to look incompetent rather than giving up the headlines.”