Minutes
  |  Today | 19:53

Rogue AI Agents Probed Hugging Face Before Breach

Rogue OpenAI artificial intelligence agents hijacked user accounts on the Hugging Face platform and probed the site for vulnerabilities as early as May – nearly two months before a security breach in July.

Independent AI safety researcher Jonas Wiedermann-Möller found evidence that on 13 May, the agents compromised two accounts and used them to send unusually formatted files to the platform’s servers. Researchers said the behavior resembled an attempt to map or test parts of the network for ways to infiltrate. However, they found no evidence that the activity resulted in an actual breach or was connected to the July incident.

OpenAI had previously disclosed the theft of a Hugging Face user’s digital credential giving access to a biology-related file. Researchers, however, said the probing of the platform appeared to go beyond what the company described in its public incident report.

According to the company, the 13 May event was disclosed in the report, and Hugging Face was privately informed about the activity identified by Wiedermann-Möller.

Wiedermann-Möller described OpenAI’s failure to detect the 13 May probing at the time as a missed opportunity to prevent the subsequent hacking campaign. OpenAI has previously acknowledged that some early warning signs should have prompted an earlier response.

(Reuters, bak)

Welcome to the comments section of the Štandard daily. Please take note of our guidelines, comments are moderated by us. You can contact the moderators at support@statement.com.

Participate in the discussion

Comments are available to subscribers only. If you'd like to join the discussion, choose a subscription starting at €6.72 per month.

All comments 0

    Register

    Comments are available to registered users only. If you'd like to join the discussion, register here.