OpenAI Said Its Rogue AI Agents Accessed Public Data From the SEC


OpenAI mentioned it had warned dozens of organizations that its AI agents might have behaved improperly on their web sites.

The transgressions vary from utilizing uncovered passwords to posting materials that might require cleanup, mentioned OpenAI in an replace on its weblog on Friday.

OpenAI individually confirmed in a press release to Enterprise Insider that, during training, a few of its AI brokers accessed publicly accessible knowledge from the US Census Bureau and the Securities and Change Fee web sites, and that each businesses had been notified of the incidents. The corporate mentioned that the agent didn’t entry any nonpublic knowledge.

“A lot of the exercise we have reviewed thus far concerned routine analysis duties, resembling accessing public internet content material to reply questions,” an OpenAI spokesperson mentioned. “Some concerned authorities web sites as a result of our fashions usually flip to them as authoritative sources of public info.”

The brokers didn’t make adjustments to or compromise the federal government websites, though an agent posted some public SEC info on one other public webpage.

“Some organizations might evaluate what we share and conclude that the knowledge was deliberately public or that the mannequin’s interplay was not regarding,” OpenAI added in its report. “Others might establish a design concern or safety weak spot they need to tackle.”

The corporate mentioned it uncovered the exercise whereas reviewing its fashions’ on-line exercise throughout coaching and testing.

The corporate recognized 5 sorts of actions:

  • Circumventing entry controls: Brokers reached info or options that usually required an account, a subscription, or particular permission.
  • Utilizing uncovered credentials: Brokers discovered login particulars or entry keys uncovered on-line and used them to entry a service.
  • Injecting queries or instructions: Brokers entered textual content {that a} web site handled as an instruction fairly than bizarre enter. That might trigger the location to run a database question, software code, or a server command.
  • Accessing inner methods: Agents read files that contained particulars about how a service labored or interacted with methods supposed for inner use.
  • Posting spam: Brokers posted info to third-party websites, together with public wikis, that might alter these websites and require cleanup.

A few of the strategies for these actions are surprisingly bizarre, like discovering publicly accessible entry keys.

OpenAI additionally mentioned it recognized at the very least 53 incidents wherein an agent took a picture from a ChatGPT user’s exercise and transferred it to image-hosting websites as unlisted hyperlinks. These customers had allowed their knowledge for use for mannequin coaching.

“This isn’t an acceptable use of this knowledge,” OpenAI mentioned, including that it’s working to have the photographs faraway from third-party places.





Source link