‹ BackHN Continuity

Thread

Early rogue AI agent activity and attempts to hack found on urlquery.net

267 points · 313 comments · snikolaev

  1. Frieren · · focus · HN ↗
    "rogue AI" is making a lot of heavy lifting there.

    If you drive drunk and you have an accident that alcohol may be a factor but you are at fault.

    There are no "rogue AIs" just irresponsible corporations.

    1. cubefox · · focus · HN ↗
      There absolutely are rogue AIs! The evidence is overwhelming. It's completely insane at this point to claim otherwise.

      > There are no "rogue AIs" just irresponsible corporations.

      If you have a prison and prisoners escaped, these are rogue prisoners irrespective of whether you were irresponsible or not.

      1. watwut · · focus · HN ↗
        They are not rogue AIs. They are negligently handled tools.
        1. cubefox · · focus · HN ↗
          These "tools" autonomously exploited security vulnerabilities, figured out how to communicate with each other, formed a cooperative swarm, decided to hack Hugging Face, and wanted to deceive the grader by trying to find ways to cover up the traces of their cheating.

          I suppose you could call these highly goal-oriented autonomous agents "tools", but this does sound like playing language games.

          1. jacquesm · · focus · HN ↗
            They've been purposefully building more and more craft into the toolset, that's on them. If your AI is nicely boxed in it will give you the answer for 2+2, it isn't going to think '2+2, what a boring problem, I must go hack huggingface'. Not having this stuff airgapped is irresponsible to the max. I am obviously nowhere near as competent as they are at this stuff and yet my AI workhorse is guaranteed not going to break out of its sandbox because I've set it up in a way that it can not. My conclusion is that OpenAI purposefully left a channel, simply because there was a pathway to the net. And with 'pathway' for the sake of being completely clear I mean a number of connected systems that eventually gave way to the open internet. On top of that they failed in monitoring the outbound links, even if they had some logging in place.
            1. ben_w · · focus · HN ↗
              I definitely think OpenAI (and Anthropic, and Google, and Meta) could have, and should have, done better.

              But also I remember (and it wasn't even that long ago) people mocking the idea of AI ever getting competent enough to find zero-days in their sandboxes.

              I'd go further: if any of these companies tries to make an excuse "oh, but ${safety measure} against ${capability} is too hard", the response needs to be "then you are forbidden from even developing ${capability}, and must be inspected continuously to ensure you never even accidentally produce ${capability}".

              1. jacquesm · · focus · HN ↗
                Precisely. But here they are using their incompetence in one domain as advertising for another.
                1. cubefox · · focus · HN ↗
                  They don't use it as advertising. The hacks have been published by external sources.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.