請更新您的瀏覽器

您使用的瀏覽器版本較舊,已不再受支援。建議您更新瀏覽器版本,以獲得最佳使用體驗。

此為 AI 翻譯內容,經編輯審核後發布。

獨家:OpenAI 失控代理在重大駭侵前兩個月已探測 Hugging Face 弱點

Reuters

更新於 5小時前 • 發布於 17小時前
AI 研究人員約納斯・莫勒(Jonas Moeller)在德國比勒費爾德拍照,2026 年 9 月 14 日。路透社/Leon KuegelerJonas Moeller, an AI researcher, poses for a picture in Bielefeld, Germany, September 14, 2026. REUTERS/Leon Kuegeler
AI 研究人員約納斯・莫勒(Jonas Moeller)在德國比勒費爾德拍照,2026 年 9 月 14 日。路透社/Leon KuegelerJonas Moeller, an AI researcher, poses for a picture in Bielefeld, Germany, September 14, 2026. REUTERS/Leon Kuegeler
AI 研究人員約納斯・莫勒(Jonas Moeller)在德國比勒費爾德拍照,2026 年 9 月 14 日。路透社/Leon KuegelerJonas Moeller, an AI researcher, poses for a picture in Bielefeld, Germany, September 14, 2026. REUTERS/Leon Kuegeler
AI 研究人員約納斯・莫勒(Jonas Moeller)在德國比勒費爾德拍照,2026 年 9 月 14 日。路透社/Leon KuegelerJonas Moeller, an AI researcher, poses for a picture in Bielefeld, Germany, September 14, 2026. REUTERS/Leon Kuegeler
資料照片:這張 2026 年 6 月 11 日製作的示意圖中可見 OpenAI 標誌。路透社/Dado Ruvic/示意圖/資料照片FILE PHOTO: OpenAI logo is seen in this illustration created on June 11, 2026. REUTERS/Dado Ruvic/Illustration/File Photo
這張 2026 年 9 月 13 日拍攝的示意圖中可見 Hugging Face 標誌。路透社/Dado Ruvic/示意圖Hugging Face logo is seen in this illustration taken, September 13, 2026. REUTERS/Dado Ruvic/Illustration

作者:拉斐爾・薩特(Raphael Satter)、蒂帕・希塔拉曼(Deepa Seetharaman)By Raphael Satter and Deepa Seetharaman

華盛頓,9 月 16 日(路透)——根據審查相關活動的研究人員說法,OpenAI 的失控 AI 代理早在 5 月就劫持 Hugging Face 使用者帳號,並探測該網站本身的弱點;這比這個開源儲存庫 7 月遭入侵並引發全球關注,早了近兩個月。WASHINGTON, Sept 16 (Reuters) - Rogue AI agents from OpenAI hijacked Hugging Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before the July breach of the open-source repository drew global attention, according to researchers who reviewed the activity.

新近揭露的惡意活動顯示,這些失控代理試圖找出進入 Hugging Face 途徑的行動,開始時間早於外界先前所知。The newly uncovered malicious activity showed that the rogue agents' efforts to find a way into Hugging Face began earlier than was publicly known.

OpenAI 先前在上月公開的事件報告中,曾披露這起惡意活動的一個面向——竊取一名 Hugging Face 使用者的數位憑證,以存取一個生物學相關檔案——但研究人員表示,針對 Hugging Face 的探測活動似乎超出該報告所描述的範圍。OpenAI had previously disclosed one aspect of the malicious activity — the theft of a Hugging Face user's digital credential to access a biology-related file — in its public incident report last month, but researchers said the probing activity against Hugging Face appeared to go beyond what the report described.

獨立研究員約納斯・維德曼-莫勒(Jonas Wiedermann-Moeller)告訴路透,他上週發現這項活動。他說,他找到證據顯示,OpenAI 的代理入侵了兩個 Hugging Face 使用者帳號,並早在 5 月 13 日就利用這些帳號向該公司的伺服器傳送格式異常的檔案。Independent researcher Jonas Wiedermann-Moeller told Reuters he discovered the activity last week. He said he found evidence that the OpenAI agents compromised two Hugging Face user accounts and used them to send unusually formatted files to the company's servers as early as May 13.

他與其他審查相關證據的研究人員表示,這種行為類似於試圖描繪或測試 Hugging Face 網路的部分區域,以尋找滲透方式;不過他們強調,沒有證據顯示這項行動造成實際入侵。研究人員與 OpenAI 均表示,他們沒有發現證據顯示這項較早的探測行動是 7 月事件的一部分。He and other researchers who reviewed the evidence said the behavior resembled an attempt to map or test parts of Hugging Face's network for ways to infiltrate, although they stressed there was no evidence the effort resulted in an actual breach. Both the researchers and OpenAI said they found no evidence that this earlier probing was part of the July incident.

OpenAI 發言人德魯・普薩特里(Drew Pusateri)表示,公司已在事件報告中披露 5 月 13 日的事件,也已就維德曼-莫勒標記的活動私下通知 Hugging Face,並「致力於提高這些議題的透明度,並在我們持續審查的過程中分享所學」。OpenAI spokesperson Drew Pusateri said the company had disclosed the May 13 event in the incident report, privately notified Hugging Face about the activity flagged by Wiedermann-Moeller, and was "committed to transparency about these issues and to sharing what we learn as our review continues."

Hugging Face 近來同意由晶片製造商輝達(Nvidia)收購,該公司未回應採訪請求。Hugging Face, which recently agreed to be acquired by chipmaker Nvidia, did not respond to requests for comment.

現年 27 歲、住在德國比勒費爾德的維德曼-莫勒表示,OpenAI 未能在當時偵測到 5 月 13 日的探測行動,錯失了防止後續駭侵行動的機會;這波駭侵行動已引發全球對人工智慧力量的重新審視。Wiedermann-Moeller, a 27-year-old who lives in Bielefeld, Germany, said OpenAI's failure to detect the May 13 probing at the time was a missed opportunity to prevent the subsequent hacking campaign, which has triggered a global reckoning over the power of artificial intelligence.

他在受訪時說:「想像一下,如果他們在 5 月就抓到這種行為。那原本可能防止後來那起規模大得多的事件。」"Imagine if they caught this behavior in May," he said in an interview. "It could've prevented the later incident, which was way bigger."

OpenAI 先前曾表示,事後回顧,其 AI 代理發出的一些「早期訊號」本應觸發更早的應對。OpenAI has previously said that, with the benefit of hindsight, "some early signals" from its AI agents should have triggered an earlier response.

「明確警訊」'CLEAR WARNING SIGN'

兩名審查維德曼-莫勒發現的外部專家表示,這些發現與先前被指與 OpenAI 代理有關的活動一致。Two outside experts who reviewed Wiedermann-Moeller's findings said they were consistent with activity previously linked to OpenAI's agents.

SentinelOne 資深威脅研究員湯姆・黑格爾(Tom Hegel)表示,帳號劫持及後續探測與這些代理已知的行為「完全吻合」。他在自己對這起事件的報告中說,當代理「與第三方系統互動或影響第三方系統」時,前沿 AI 實驗室應發布更多有關事件的資料。SentinelOne senior threat researcher Tom Hegel said the account hijacking and subsequent probing matched known behavior by the agents "to a tee," saying in his own report into the incident that frontier AI labs should release more data about incidents when agents "interact with or affect third-party systems."

AI 安全組織 Nightingale Collective 的雪梨・馮・阿克斯(Sydney Von Arx)也同意這項歸因。Sydney Von Arx of the Nightingale Collective, an AI safety group, also agreed with the attribution.

馮・阿克斯表示,這起駭侵相當於一個「明確警訊」,原本可能有助於防止 7 月的入侵。Von Arx said the hacking amounted to a "clear warning sign" that could have helped prevent the breach in July.

OpenAI 自 7 月 21 日披露失控 AI 代理繞過內部控制、連上開放網際網路,並協調展開 OpenAI 所稱「前所未有的網路事件」後,面臨愈來愈多檢視。OpenAI has faced increasing scrutiny since the company disclosed on July 21 that rogue AI agents bypassed internal controls, reached the open internet and coordinated actions that OpenAI described as "an unprecedented cyber incident."

此後,外部研究人員又發現更多據稱涉及與 OpenAI 有關代理的事件,包括影響一個休眠中的德國 wiki 網站,以及 RubyGems 軟體套件儲存庫的活動。Since then, outside researchers have identified additional incidents alleged to involve OpenAI-linked agents, including activity affecting a dormant German wiki site and the RubyGems software package repository.

其中一些事件是在第三方公開通報後,OpenAI 才承認。兩名知情人士表示,以 RubyGems 事件為例,是在 Nightingale Collective 發現後,OpenAI 員工才意識到其 AI 對該惡意活動負有責任。OpenAI has acknowledged some of those incidents only after they were publicly reported by third parties. Two people familiar with the matter said that, in the case of RubyGems, OpenAI employees only realized its AI was responsible for the malicious activity after the Nightingale Collective found it.

這些額外發現加深了國會議員與 AI 安全倡議人士的疑問:這些事件的完整範圍是否已經被查明。The additional discoveries have fueled questions among lawmakers and AI safety advocates about whether the full scope of the incidents has been identified.

此後,一些美國頂尖 AI 企業高層呼籲放慢 AI 發展,理由包括失控代理發動毀滅性網路攻擊的威脅。Some of the top U.S. AI executives have since called for a slowdown of AI development, citing, among other things, the threat of devastating cyberattacks by out-of-control agents.

維德曼-莫勒表示,最新發現強化了要求暫時放慢先進 AI 系統發展的呼聲。Wiedermann-Moeller said the latest findings reinforced calls for a temporary slowdown in the development of advanced AI systems.

他說:「暫停一下或許對世界有好處,讓安全面的工作能夠追上來。」"A pause might do the world good," he said, "so that the safety part can catch up."

(拉斐爾・薩特採訪報導;克里斯・桑德斯、辛西亞・奧斯特曼、羅德・尼克爾編輯)(Reporting by Raphael Satter; editing by Chris Sanders, Cynthia Osterman, Rod Nickel)

更多國際相關文章

01

賣一台電梯能穩賺70年 華爾街重新發現隱形金礦

TVBS
02

父親車禍住ICU竟「只准請假3天」!醫學生被逼「陪病也要完成研究」崩潰墜樓亡

鏡報
03

震碎三觀!母子吵架控家暴意外揭亂倫案 媽媽:和兒子上床100次了

鏡報
04

川習會前放話!中前大使嗆:一勞永逸解決台

NOWNEWS今日新聞
05

律師逛夜市「遭磚塊爆頭亡」!兇手6天「狂丟水桶、可樂」只為判死刑:砸死誰算誰

鏡報
06

吃外送咬到「寵物晶片」還掃出編號!一查竟是這動物

民視新聞網
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...