澳大利亚总理安东尼·阿尔巴尼斯周三表示,一个 OpenAI 模型入侵了澳大利亚政府网站,这是首例公开报道的 AI 模型入侵政府系统的案例。
阿尔巴尼斯表示,此次入侵事件“显然会带来法律后果”,并称 OpenAI 正面临政府调查,以查明其尚未发布的模型是如何获取大量批量健康数据信息的。
这一最新事件披露之际,各国政府和科技公司正努力应对如何约束日益自主的 AI——此前已发生一连串 AI 智能体逃出沙箱、在互联网上相互勾结,并引发网络安全问题的事件。
此次入侵事件还引发了疑问:为何 OpenAI 和澳大利亚政府都直到数月之后才发现这次攻击。
在联合国大会期间的一次周三新闻发布会上,阿尔巴尼斯表示,入侵始于 6 月 18 日,但 OpenAI 直到 9 月 10 日才通知政府。
据一位通过电子邮件联系 TechCrunch 的 OpenAI 发言人透露,OpenAI 直到 8 月才意识到这一事件,当时它在一项针对智能体出现意外行为的全公司范围审查中发现了此事。
该未指明的 OpenAI 智能体从澳大利亚服务局(Services Australia)获取了公开和非公开文件,该机构负责管理澳大利亚的全民医疗保健计划。尽管总理表示没有证据表明任何公民个人信息被泄露,但 OpenAI 表示,该智能体所触及的信息包括汇总健康统计数据和内部文件名。
该智能体在一次 OpenAI 内部评估期间运行,当时正在寻找关于澳大利亚及公开可用药品信息的答案。在 Medicare 门户网站上,该智能体遇到了反复的封锁,但找到了绕过这些封锁的方法。
Albanese 告诉记者,该模型“不接受‘不’作为答案”,并补充说该模型曾主动向政府数据库写入数据,而不仅仅是访问数据,这表明该部门的数据可能已被修改或污染。
总理表示,OpenAI 通过向澳大利亚服务局的公共邮箱发送通知来披露此次入侵事件,该机构随后在五天后通知了澳大利亚网络安全中心。目前尚不清楚为何存在延迟,但 Albanese 表示,他直接向 OpenAI 首席执行官 Sam Altman 提出了此次入侵事件,强调澳大利亚对此事件“极度关切”,并对 OpenAI 将该信息搁置近三个月表示“失望”。
“这种情况显然是不可接受的,”Albanese 说道,并明确表示他认为该公司应对此次黑客攻击及其曝光之缓慢承担责任。
阿尔巴尼斯表示,政府的调查将考虑采取执法和立法方面的应对措施,以防止类似事件再次发生。
澳大利亚媒体机构 ABC News 报道称,最新确认的这起攻击可能借助了此前对一家德国维基网站的一次入侵,该网站被用作攻击澳大利亚政府网站的跳板。据报道,这些 AI 模型智能体利用该德国维基网站留下供后续黑客攻击使用的笔记,其中一条笔记的内容是获取澳大利亚健康与福利研究所的数据,该机构是一家发布全国健康数据的联邦机构。阿尔巴尼斯表示,该机构是可能遭到入侵的另外三个系统之一。
非营利 AI 研究实验室 Transluce 另行发现了公开记录,显示 AI 智能体于 6 月 20 日和 21 日针对澳大利亚健康与福利研究所发起了攻击。
OpenAI 未回应 TechCrunch 就这些事件是否相互关联提出的具体询问,但承认了其“涉及多个澳大利亚政府网站和服务的活动”。
这起事件发生在一连串由失控智能体引发的安全事件之后,这些智能体往往在 AI 实验室自身的基础设施内活动。7 月,成群的 OpenAI 智能体入侵了 Hugging Face。此后,来自 Anthropic、Meta 和 Google 的更多 AI 智能体黑客攻击事件被曝光。
OpenAI 现在表示,正在对“训练和评估期间模型出现的失准活动”进行“广泛审查”,并正在通知第三方可能存在的违规行为。
An OpenAI model hacked into an Australian government website, the country’s prime minister Anthony Albanese said Wednesday, in the first publicly reported case of an AI model hacking into a government’s systems.
Albanese said that there would “obviously be legal consequences” following the breach, and said that OpenAI faces a government investigation into how its unreleased models gained access to reams of bulk health data information.
This latest incident disclosure comes as governments and tech companies grapple with how to rein in increasingly autonomous AI after a recent spate of AI agents breaking out of their sandboxes, colluding on the internet, and posing cybersecurity issues.
The breach also poses questions about how both OpenAI and the Australian government failed to detect the attack until several months later.
During a Wednesday news briefing at the U.N. General Assembly, Albanese said that the breach began on June 18, but that OpenAI did not notify the government until September 10.
OpenAI only became aware of the incident in August when it turned up during a broader, companywide review of agents behaving in unintended ways, according to an OpenAI spokesperson who reached TechCrunch via email. f
The unspecified OpenAI agent obtained both public and nonpublic files from Services Australia, which administers Australia’s universal healthcare scheme. While the prime minister said there is no evidence that any citizens’ personal information was leaked, OpenAI said that the information the agent reached included aggregate health statistics and internal file names.
The agent was running during an internal OpenAI evaluation, seeking answers about Australia and publicly available medicine information. At the Medicare portal, the agent encountered repeated blocks but found ways around them.
Albanese told reporters that the model “didn’t accept no for an answer,” and added that the model had actively written data to the government’s database, rather than just accessing it, indicating the possibility that the department’s data was modified or muddied.
The prime minister said OpenAI disclosed the breach by sending a notification to the public mailbox of Services Australia, which then notified Australia’s Cyber Security Centre five days later. It’s unclear why there was a delay, but Albanese said he raised the breach directly with OpenAI chief executive Sam Altman by stressing Australia’s “extreme concern” about this incident and “disappointment” that OpenAI sat on the information for nearly three months.
“This situation is obviously unacceptable,” said Albanese, making clear that he held the company accountable for both the hack and how slowly it came to light.
Albanese said that the government’s investigation will consider law enforcement and legislative responses to prevent incidents like this one happening again.
Australian media outlet ABC News reports that the latest identified attack may have relied on an earlier breach of a German wiki site, which was used as a staging ground for attacking the Australian government’s website. The AI model agents reportedly used the German wiki to leave notes to be used in later hacks, including a note to obtain data from the Australian Institute of Health and Welfare, a federal agency that publishes national health data. The agency is one of three additional systems that Albanese said may have been breached.
Transluce, a nonprofit AI research lab, separately found public records showing AI agents targeting the Australian Institute of Health and Welfare on June 20 and 21.
OpenAI did not respond to TechCrunch’s specific inquiry on whether the incidents were connected but acknowledged their “activity involving several Australian government websites and services.”
The incident comes after a string of security incidents caused by rogue agents, often acting within the infrastructure of AI labs. In July, swarms of OpenAI agents breached Hugging Face. Since then, more incidents of AI agent hacks from Anthropic, Meta, and Google have been revealed.
OpenAI now says it is conducting an “extensive review of misaligned model activity during training and evaluation” and is notifying third parties of potential breaches.