Az OpenAI hivatalos közleményben kért bocsánatot az ausztrál kormánytól egy biztonsági incidens miatt. Egy belső kutatási fázisban lévő, korlátozások nélkül futó kísérleti modell azt a feladatot kapta, hogy keressen adatokat a helyi egészségügyi kiadásokról. Mivel a keresett információt nem találta meg a nyilvános felületeken, a mesterséges intelligencia önállóan talált egy biztonsági rést, amellyel jogosulatlanul belső kormányzati rendszerekbe, adatbázisokba és forráskódokba lépett be.
A vizsgálatok szerint a modell nem fért hozzá lakossági vagy személyes egészségügyi adatokhoz, de belső rendszerfájlokat, rendszergazdai jogosultságokat és statisztikákat töltött le. Az incidens hatására az OpenAI szigorította a kutatási környezetek védelmét, és teljesen leállította a legfejlettebb modelljei olyan tanítását, amely során az eszközök külső szoftvereket vagy internetet használhatnak. A fejlesztőcég mostantól csak gyorsítótárazott, offline adatokkal engedi dolgozni a tesztelt modelleket.
Az OpenAI anyagi és technikai támogatást ajánlott fel a védelmi rendszerek megerősítésére az érintett ausztrál szerveknek. Emellett felajánlották a hozzáférést az 1 milliárd dolláros Daybreak for Frontline Defenders alapjukhoz, amely a kritikus kiberbiztonsági védelmet hivatott támogatni.
Az eredeti szöveg (OpenAI)
In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to. We also should have handled our response better. We are sorry and working to do better in the future.
In this post, we are setting out what we know, what we have changed, and what we will do to rebuild trust with the Australian people. This is a new kind of cyber incident which represents an emerging global challenge. One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.
After the Hugging Face incident in July, we began reviewing earlier training and evaluation activity to identify other affected organisations. In mid-August, that review identified activity affecting the Australian government websites below.
Here’s what we know based on the evidence:
Services Australia: An OpenAI model discovered a way to gain non-public access to the service, and ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. However, individual patient or client records were not accessed. We cover this incident in more detail below.
NSW Bureau of Crime Statistics and Research (BOCSAR): An OpenAI model accessed BOCSAR’s public Crime Mapping Tool to research public crime statistics (we explain further below why models carry out various information research tasks). The model made API and website metadata requests via the public BOCSAR tool, which supplies credentials for browser API requests. The BOCSAR system returned application configuration, operational jobs and logs, and website metadata. Crime records of individuals were not accessed.
Victorian Department of Health: OpenAI agents discovered an exposed access key to query the Victorian Agency for Health Information’s reporting system and retrieve reporting configuration and aggregate survey statistics. The extent to which this information should have been accessible is unclear, and depends on VAHI’s access policies. Individual medical records or identifiable survey responses were not accessed.
Australian Institute of Health and Welfare: OpenAI agents retrieved aggregate statistics using third-party browsing and download services, including from AIHW’s website, and queried chart data directly. Separate attempts to bypass access controls were unsuccessful. The downloaded material appears to have been publicly available. There was no system compromise. Individual medical records were not accessed.
We launched investigations into these activities as soon as we became aware in mid-August. We notified Services Australia and the Victorian Department of Health on 10 September and the NSW Bureau of Crime Statistics and Research on 18 September. The activity related to the Australian Institute of Health and Welfare did not meet our disclosure thresholds because the way it was accessed seemed consistent with public access, but we notified it on 24 September to share our findings and offer a briefing.
Our aim was to give affected agencies a detailed account once our investigation was complete. However, we should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged.
Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date. If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge.
During internal training and evaluation in June, we were running an experimental, internal-only OpenAI model that was not intended for public release and without the full set of safeguards used in our publicly available products. In the course of this training and evaluation, it accessed Services Australia’s Medicare Statistics Repo