‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. damowangcy · · focus · HN ↗
    Imagine having a virus escape a sandbox, why are we worried about the virus but not the incompetency of those who are responsible for setting up the sandbox?

    If I post something on the Internet today claiming that I asked my agent to do X but it went rogue and did Y, all I will be getting in return is a jar full of "skill issue".

    Should we worried about people using LLMs for attacks? Yes, but not in the premise of LLMs going rogue but someone with the intention of abusing it to cause harm. And this is not something we as individual or even company can deal with, responsibility should be held by those who use it, in a legal way.

    I am baffled by the fact that up until now, no one is held responsible for so many incidents reported publicly or privately. At this point, it's free marketing, if I am CEO of any AI company, I will run swarm of agents hacking all NGOs and stating that I am just looking for some random piece of data that happened to be hidden in their servers, at least that's what my LLMs think, not me. Then I will start preaching everyone how dangerous this piece of technology is and start giving out free tokens for these NGOs so they can start defending themselves and we should slow the f down.

    1. user43928 · · focus · HN ↗
      > someone with the intention of abusing it to cause harm [...] responsibility should be held by those who use it

      This is obviously already the case and it's much different from a scenario where the AI genuinely takes unexpected action.

      I frankly find it ridiculous how many suggest OpenAI or its employees should face criminal charges, without actual legal basis at the time.

      It's also hardly outrageous that they ran training and/or benchmarks with only network-isolated VMs with access to a package repository.

      This being the first well-known incident of its kind, I wouldn't expect them to have done more than that.

      The idea that AI labs will now intentionally have their models hack companies in order to market their models, well, I don't even know what to say.

      That's ridiculous and what you describe would obviously be criminal behavior under existing law.

      1. dmazzoni · · focus · HN ↗
        I don't think it was intentional or marketing, but I think it was criminally negligent and they should be held responsible.

        They gave powerful models with no guardrails access to the Internet and didn't monitor it.

        Even the slightest bit of monitoring of their outgoing Internet activity would have immediately given it away and they could have shut it down.

        They were asleep at the wheel, and that's just plain negligence.

        1. user43928 · · focus · HN ↗
          I'm no lawyer but that seems extremely unlikely.

          As I said, they were running in network-isolated VMs with no access to the internet.

          And as for monitoring, what I heard is that there are petabytes of agent logs. Considering the scale of training, you can obviously not just manually review it.

          Before this, we had no reason to believe the AI was capable of escaping the sandbox's network isolation via hacking the package repository with a zero day, and that it then was likely to go on to hack external companies as well.

          Another factor here is that criminal law in the US relevant to hacking requires intent. You don't want to go to prison for a software malfunction.

          So I understand we are left with civil liability at most. However, there was no notable damage, and OpenAI can pay to settle.

          In the aftermath of this and the now discovered other incidents, they strengthened their monitoring and isolation.

          Case closed as far as I am concerned. I feel many just want to dramatize this.

          1. cma · · focus · HN ↗
            > Another factor here is that criminal law in the US relevant to hacking requires intent. You don't want to go to prison for a software malfunction.

            Do you think if you went out and purchased a humanoid robot and gave it a whittling knife and hooked it to an OpenAI LLM as the overall planner and set it out on the sidewalk in front of the OpenAI offices to make and sell crafted goods you wouldn't be charged if it killed someone, because you had no intent?

            There is such a thing as criminal negligence, and you would be going to jail for a software malfunction, exempting all software malfunctions doesn't seem reasonable, some are worse than others.

            Maybe hacking law doesn't have an option for that, but many people are just advocating change the laws when they say they should go to jail. A lot of people don't know you can't change the law to cover past stuff, but even ones that do may say something like that as a shorthand to pushing to change the law, not know the law doesn't already have an option (if it really doesn't), or just say a phrase to express frustration more strongly than saying something weaker.

            Even if it is a user prompting the system, if a user asked for "make a fairly stable chlorinated molecule that can last long enough to spread through the atmosphere and induce contagious misfolding prions in people," I think if a hosted model that was near capable of it even started carrying out the first steps of research planning the whole company and its largest limited liability investors should go to jail, in all the senses mentioned above. Amend the constitution to allow ex post facto laws for that kind of stuff if models get close to that level of capability.

            1. user43928 · · focus · HN ↗
              We are not exempting all software malfunction.

              No crime occurred in the first place, because no one intentionally hacked anything.

              The hacking law requires intent, as we discussed.

              For other crimes, like manslaughter, I understand criminal negligence is already relevant?

              About biological weapons, I know even less about the legal aspects, so I can't say whether this is covered well already under existing law.

              1. cindyllm · · focus · HN ↗

                [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.