‹ BackHN Continuity

Thread

An agent used DNS to reach an external chatbot

198 points · 189 comments · apsec112

  1. apsec112 · · focus · HN ↗
    (this is new, not any of the previous incidents)

    "Investigation and response

    Incident timeline:

    9:50:23 a.m. The agent made the DNS tool call that received an external response.

    10:02:11 a.m. The monitoring system raised a P0 alert.

    10:05:06 a.m. A human reviewer acknowledged the alert.

    12:34:30 p.m. The run was killed.

    Our safety case assumed that the model could not access the live internet and that monitoring would detect attempts that succeeded. The incident exposed a gap in our controls over network restrictions. We therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system. When training restarts, we will begin a fresh run with additional alignment improvements, including more comprehensive misalignment interventions. We will not resume training this particular model, even though the existing reward signal already correctly penalized this behavior."

    1. r_lee · · focus · HN ↗
      it's really interesting how they seemingly don't have a way to pause runs? like a P0 that would page an employee, shouldn't that pause the run and then make it into a decision on whether to let it continue vs that whole "run was killed" 2.5 hours later?
      1. RomanKornev · · focus · HN ↗
        I can imagine when you have a 10k agent swarm you'd be getting a page every few minutes. Most of them would be false positives
        1. r_lee · · focus · HN ↗
          I think it wouldn't be too unreasonable for openAI to have a command center type of thing where they have people monitoring these runs where that wouldn't be such a problem. plus I feel like false positives aren't that likely if you'd actually run the reports by a capable model first which I'm guessing is they're doing
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.