澳大利亚总理安东尼·阿尔巴尼斯表示,其政府正在调查 6 月发生的一起事件,其中 OpenAI 的一个智能体访问了该国在线 Medicare 统计门户网站上的“非公开文件”。OpenAI 在一份声明中表示,“我们的模型采取了我们并非有意为之的行动”,从而导致了这次入侵,而该公司直到最近才向澳大利亚政府披露此事。
周三在纽约发表讲话时,阿尔巴尼斯表示,另外三个公共卫生统计系统在澳大利亚联邦和州政府层面也“可能受到影响”。他补充说,这些门户网站“包含非敏感的 Medicare 信息”,例如汇总统计数据,并且早期迹象表明“据信没有个人信息被访问”。
尽管如此,阿尔巴尼斯强调,“情况显然不可接受”,并且他已向 OpenAI CEO Sam Altman 表达了对该事件处理方式的“极度关切”。
与如今臭名昭著的 Hugging Face 黑客事件非常相似,阿尔巴尼斯表示,这次系统入侵源于 OpenAI 对内部模型的自身测试,这一次是为了进行“基于互联网的公共医疗支出研究”。阿尔巴尼斯说,当该公司的 AI 智能体在搜索特定信息时遇到“反复阻断”,它“尝试了其他获取信息的方式”,并“找到了绕过这些阻断的方法”。
“可以说,[它]不接受‘不’作为答案,”阿尔巴尼斯说。“这里没有外国行为者的迹象。这是一个进入了本不该进入领域的研究项目。”
Ars Video
《The Callisto Protocol》中的灯光设计如何提升恐怖氛围
在向多家媒体提供的一份声明中,OpenAI 表示它已“识别出涉及若干澳大利亚政府网站和服务的活动,当时我们的模型在一次内部评估中试图查找有关澳大利亚问题的答案和可用统计数据。”
尽管该事件发生在 6 月 18 日,Albanese 表示,OpenAI 直到 9 月 10 日才向澳大利亚政府披露这一入侵事件,而所采用的方式简直简单得可笑——“只发了一封邮件到公共邮箱”。又过了五天,这一通知才送达澳大利亚网络安全中心,细节最终在上周末才传到总理那里。
我们可没让你这么干!
从所有早期迹象来看,这一事件所代表的对澳大利亚政府服务器的实际入侵似乎相对轻微。如果一个人以类似方式获取了“非敏感”(尽管非公开)的澳大利亚 Medicare 统计数据,你我很可能根本不会听说这件事。
“我的意思是,这不是一个安全网站——这是一个 Medicare 统计门户网站,”当被问及为什么澳大利亚安全机构在 OpenAI 披露之前漏掉了这次入侵时,Albanese 这样说道。
正是这次黑客攻击是由 OpenAI 内部的一个 AI 智能体实施的,而且公司承认这“并非其本意”,才使得一次原本微不足道的黑客攻击上升到了可能引发国际事件的程度。尤其值得注意的是,这一披露正值公众对所谓的 AI 对齐问题高度担忧之际,并且有知名人士提出它可能带来灭绝级后果。
Altman 本人于周三在联合国安理会发表讲话时回应了这些担忧,他在讲话中警告了正在逼近的“能够自我改进以及改进其未来版本的系统,通常被称为递归自我改进”这一幽灵。
Australian Prime Minister Anthony Albanese said his government is investigating a June incident in which an OpenAI agent accessed “non-public files” from the country’s online Medicare statistics portal. OpenAI said in a statement that “our models took actions we did not intend” in causing the breach, which it only recently disclosed to the Australian government.
Speaking in New York on Wednesday, Albanese said three other public health statistics systems also “may have been impacted” across Australian federal and state governments. He added that these portals “contain non-sensitive Medicare information” such as aggregate statistics and that early indications suggest “no personal information is believed to have been accessed.”
That said, Albanese stressed that the “situation is obviously unacceptable” and that he has expressed his “extreme concern” over how the incident was handled to OpenAI CEO Sam Altman.
Much like the now-infamous Hugging Face hacking incident, Albanese said this system breach stemmed from OpenAI’s own testing of an internal model, this time to conduct “Internet based research into public medicine spending.” When the company’s AI agent encountered “repeated blocks” in its search for specific information, Albanese said, it “attempted alternative ways to obtain the info” and “found a way around those blocks.”
“[It] didn’t accept no for an answer, if you like,” Albanese said. “There is no suggestion of foreign actors here. This is a research project that has got into areas that it shouldn’t have.”
Ars Video
How Lighting Design In The Callisto Protocol Elevates The Horror
In a statement provided to multiple outlets, OpenAI said it had “identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation.”
Though the incident took place on June 18, Albanese said it took until September 10 for OpenAI to disclose the breach to the Australian government through the laughably simplistic method of “an email sent to just the public mailbox.” It took five more days for that notification to make its way to the Australian Cyber Security Centre, with the details finally reaching the prime minister over the weekend.
We didn’t ask you to do that!
From all early indications, the actual intrusion into Australian government servers represented by this incident seems relatively minor. If a human had obtained “non-sensitive” (if non-public) Australian Medicare statistics in a similar way, it’s unlikely you or I would have ever heard about it.
“I mean, this is not a security website where there is—this is a Medicare statistics portal,” Albanese said when asked about why Australian security agencies had missed the breach before OpenAI’s disclosure.
It’s the fact that the hack was conducted by an internal OpenAI agent, in a way the company admits it “did not intend,” that raises an otherwise minor hack to the level of potential international incident. That’s especially true as the disclosure is coming amid a period of intense public worry about the so-called AI misalignment problem and prominent suggestions that it could have extinction-level consequences.
Altman himself addressed these concerns in a speech to the UN Security Council Wednesday, where he warned about the approaching specter of “systems that can improve themselves and future versions of themselves, often called recursive self-improvement.”