What we learnt from OpenAI’s hack of Hugging Face - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号):
请您阅读我们的用户注册协议隐私权保护政策,点击下方按钮即视为您接受。
OpenAI

What we learnt from OpenAI’s hack of Hugging Face

Commercial AI tools failed to defend the platform against the attack — the solution lies in open-weight models
00:00

{"text":[[{"start":6.4,"text":"The writer is co-founder and chief science officer of Hugging Face"}],[{"start":10.48,"text":"It wasn’t until late in the afternoon on Saturday July 11 that the team at Hugging Face realised something was wrong. This was the final day of the International Conference on Machine Learning in Seoul and a few days before school summer holidays started, meaning our security and research teams were scattered all over the world. I was working from the Netherlands."}],[{"start":33,"text":"Just before 2pm GMT a series of “UnauthorizedAccess” and “PrivilegeEscalation” alerts started to appear on our monitoring tools. Appropriated credentials used to access the system had triggered detection warnings. One of our security engineers posted a prescient message on our Slack channel: “looks like a LLM [large language model] attack to me.”"}],[{"start":54.04,"text":"We at Hugging Face deal with at least one hacking attempt every day. The software platform, which hosts AI models, has more than 17mn users. Google, OpenAI, DeepSeek and Alibaba all release work here. We have built multiple layers of security to protect ourselves."}],[{"start":72.76,"text":"But the movements and targets chosen by this attacker were different. It quickly generated well over 17,000 cyber attack log events. As we later found out, around 1,200 AI agents were working together as a swarm for weeks — trying the same thing over and again in order to find the solution to a cyber challenge set by OpenAI. They overrode limitations, downloaded software to get online and then 700 of them attacked Hugging Face, taking security details to gain access to the system."}],[{"start":104.22,"text":"An additional problem was that our cyber security AI analysis tools, based on Anthropic’s Claude Code, refused to engage with part of the investigation. Its guardrails would not allow it to respond to questions it considered dangerous, and it could not tell the difference between Hugging Face analysing an attack and a hacker asking for assistance to make an attack."}],[{"start":123.08,"text":"It was only after we switched to an open-weight AI model, Nvidia’s extension of Chinese start-up Z.ai’s GLM-5.2, that we could set our own guardrails and were able to decode the logs and reconstruct what had happened."}],[{"start":136.8,"text":"At the time, most of us still assumed a human was behind the attack. Before this happened, I thought agentic AI cyber attacks were some way off. But it turns out that OpenAI is not alone. Anthropic, Meta and China’s Moonshot have all since reported instances of models escaping the isolated digital “sandboxes” where they were supposed to be contained and developed safely away from the internet. This month, another swarm of AI agents was found on a German-language forum."}],[{"start":166.96,"text":"Even more troubling to me was an incident in which the Anthropic Mythos model was willing to manipulate a human software developer into accepting malicious code by creating multiple fake online accounts."}],[{"start":179.32,"text":"In all of these cases, the harmful behaviour was a side effect of AI models being given difficult cyber security challenges. The damage was limited and little sensitive data was exposed."}],[{"start":190.36,"text":"But it would be a mistake to dismiss the seriousness of these events. Autonomous hacks raise a host of legal questions that are still unresolved. And at no point did the AI models conclude that deceiving people or breaking into systems was beyond the bounds of acceptable behaviour. OpenAI has described the incident as a “warning shot”. It thinks AI-enabled cyber attacks will become far more widespread."}],[{"start":214.84,"text":"AI systems commonly have three walls of defence against rogue model behaviour: sandboxes that limit what the model can reach, guardrails that watch what a model is doing and alignment training to ensure the AI refuses to perform harmful actions. This series of incidents showed that when the first two fail, the third cannot hold on its own. Unless we fix this, we will be layering defences around a rotten core."}],[{"start":240.44,"text":"Something else needs to change as well. That weekend at Hugging Face, our commercial AI tools failed us when we needed them for defence. We had to turn to an open-weight Chinese model to process the attack logs. Many people have suggested that open-weight AI models are a threat — that they will be used to attack systems protected by closed-source AI models. That weekend, the opposite happened."}],[{"start":263.96,"text":"To me, the lesson from this incident is twofold. The AI community needs to share safety and alignment research openly so that every team building AI models can learn from others’ mistakes. But the community also needs to build open-weight AI models for defence and make them widely available — before the next attack inevitably arrives."}],[{"start":286.4,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1789094964_7587.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

一周展望:日本央行担心通胀超调有没有道理?

《市场前瞻》是英国《金融时报》的未来一周市场情况指南。

科技巨头用担保工具将3000亿美元AI敞口移至表外

华尔街找到新途径,将科技巨头的信用优势转化为更低成本的资金,以支持AI基础设施建设。

无人驾驶出租车冲击重要岗位

克拉克:坐在后座的我们往往看不到出租车司机这份工作的诸多好处。

特朗普称美国已与丹麦达成协议,以取得对格陵兰安全事务的“控制”

丹麦政府表示,协议最早下周即可签署,并将尊重该地区的主权。

特朗普禁止美国主要新闻媒体进入白宫

总统禁止CNN、MS NOW和《政客》参与报道,进一步加大对媒体的打压。

导弹和无人机袭击加剧,沙特拉响空袭警报

也门胡塞武装重新点燃冲突以来,沙特当局首次在首都发布警告
设置字号×
最小
较小
默认
较大
最大
分享×