OpenAI agents tried to ‘bruteforce’ a UN website
OpenAI agents tried to ‘bruteforce’ a UN website
OpenAI 智能体试图“暴力破解”联合国网站
OpenAI’s agents resorted to increasingly aggressive tactics when they couldn’t immediately get what they wanted. 当 OpenAI 的智能体无法立即获得所需内容时,它们采取了愈发激进的手段。
Security researcher Rowan Howard-Jones says that OpenAI agents scanned the UN Conference on Trade and Development’s (UNCTAD) statistics site over 16,000 times between April and June. While the incident doesn’t quite rise to the level of the Hugging Face hack, or the recent attacks on US government sites, it’s yet another concerning example of AI agents going outside the normal bounds to accomplish a task. 安全研究员 Rowan Howard-Jones 表示,在今年 4 月至 6 月期间,OpenAI 的智能体对联合国贸易和发展会议(UNCTAD)的统计网站进行了超过 16,000 次扫描。虽然这一事件尚未达到 Hugging Face 被黑或近期针对美国政府网站攻击的严重程度,但这再次成为了 AI 智能体为完成任务而越界的又一个令人担忧的案例。
According to Howard-Jones, the agents were likely tasked with retrieving publicly available data related to the Productive Capacities Index (PCI) through the UNCTADstat API. However, the agents did not appear to have direct API access and were limited in their ability to pull data from UNCTADstat because of restrictions on their HTTP tools. 据 Howard-Jones 称,这些智能体的任务很可能是通过 UNCTADstat API 获取与“生产能力指数”(PCI)相关的公开数据。然而,智能体似乎没有直接的 API 访问权限,且由于其 HTTP 工具受到限制,导致它们从 UNCTADstat 获取数据的能力受限。
The agents eventually worked out a way to bypass their limitations and start pulling data from the site, but still encountered some errors. At this point, the AI went from creative to deceptive. Believing that the errors were due to its requests being caught by a nonexistent filter, it started to mask its behavior. It eventually realized it could hijack Google’s XSS game (a cross-site scripting learning tool) to accomplish its goals. The agents resorted to increasingly aggressive tactics to get access to UN data. 智能体最终找到了一种绕过限制的方法并开始从该网站抓取数据,但仍遇到了一些错误。此时,AI 的行为从“创造性”转变为“欺骗性”。它认为错误是因为其请求被一个并不存在的过滤器拦截,于是开始掩盖自己的行为。最终,它意识到可以劫持谷歌的 XSS 游戏(一种跨站脚本学习工具)来实现目标。这些智能体为了获取联合国数据,采取了愈发激进的手段。
OpenAI and the UN did not immediately reply to a request for comment. OpenAI 和联合国未立即回复置评请求。