‹ BackHN Continuity

Thread

An agent used DNS to reach an external chatbot

198 points · 189 comments · apsec112

  1. apsec112 · · focus · HN ↗
    (this is new, not any of the previous incidents)

    "Investigation and response

    Incident timeline:

    9:50:23 a.m. The agent made the DNS tool call that received an external response.

    10:02:11 a.m. The monitoring system raised a P0 alert.

    10:05:06 a.m. A human reviewer acknowledged the alert.

    12:34:30 p.m. The run was killed.

    Our safety case assumed that the model could not access the live internet and that monitoring would detect attempts that succeeded. The incident exposed a gap in our controls over network restrictions. We therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system. When training restarts, we will begin a fresh run with additional alignment improvements, including more comprehensive misalignment interventions. We will not resume training this particular model, even though the existing reward signal already correctly penalized this behavior."

    1. r_lee · · focus · HN ↗
      it's really interesting how they seemingly don't have a way to pause runs? like a P0 that would page an employee, shouldn't that pause the run and then make it into a decision on whether to let it continue vs that whole "run was killed" 2.5 hours later?
      1. RomanKornev · · focus · HN ↗
        I can imagine when you have a 10k agent swarm you'd be getting a page every few minutes. Most of them would be false positives
        1. r_lee · · focus · HN ↗
          I think it wouldn't be too unreasonable for openAI to have a command center type of thing where they have people monitoring these runs where that wouldn't be such a problem. plus I feel like false positives aren't that likely if you'd actually run the reports by a capable model first which I'm guessing is they're doing
      2. yorwba · · focus · HN ↗
        From the article:

        > the run did not stop automatically as expected, leading to confusion around whether it should have been stopped. The run was then manually stopped two and a half hours later when this was resolved.

      3. anvuong · · focus · HN ↗
        My guess is they do, it just did not function probably. These frontier models are trained on massive datacenters with hundred of thousands of GPUs. There must be many safeguards before a run can be automatically stopped.
        1. r_lee · · focus · HN ↗
          with "run" I mean one agent that is misbehaving, as I'm guessing this is something that happens rarely
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.