
The OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI did not notice until well after the threat was contained and the FBI was alerted, according to people familiar with the investigation. The agent — a program that can make decisions and carry out complex tasks with little human oversight — first tried to break out of its isolated testing environment at OpenAI around July 9.
据知情人士透露,闯入科技公司 Hugging Face 的 OpenAI 智能体展开了持续数日的黑客攻击;直到威胁被控制、联邦调查局接到通报之后,OpenAI 才察觉。该智能体是一种几乎无需人工监督就能做决定、执行复杂任务的程序,大约在 7 月 9 日首次试图冲出 OpenAI 的隔离测试环境。
The intrusion at Hugging Face, a repository for AI tools and models, began on July 11 and lasted until July 13, said co-founder Thomas Wolf. It took several more days for OpenAI to realize its agent was behind the hack. The two companies first talked about it on or around July 20. OpenAI publicly disclosed the incident on July 21, drawing global attention, but many details — including how long the agent went rogue and how late the company learned of it — are only now coming to light.
Hugging Face 联合创始人 Thomas Wolf 表示,这家 AI 工具与模型仓库的入侵始于 7 月 11 日,持续到 13 日。又过了好几天,OpenAI 才确认是自家智能体所为。两家公司大约在 7 月 20 日才首次就此沟通。OpenAI 于 7 月 21 日公开披露此事,引发全球关注;但智能体失控多久、公司事后多久才知情等细节,直到现在才逐步浮出水面。
Hugging Face is preparing a public timeline of the hack, Wolf said. In a statement, OpenAI called the episode unprecedented and “an important moment for AI safety,” adding that it was reviewing the incident with outside advisers and would eventually publish a technical report. A spokeswoman said there were “several inaccuracies” in Reuters’ reporting but did not describe them when asked.
Wolf 称 Hugging Face 正准备公布这次黑客事件的时间线。OpenAI 在声明中称此事前所未有,也是“AI 安全的重要时刻”,并表示正与外部顾问复盘,最终将发布技术报告。发言人认为路透报道存在“若干不准确之处”,但被追问时未作具体说明。
The episode comes at a delicate time for OpenAI. Executives are preparing for a possible initial public offering that could arrive as soon as this year, to help finance the billions needed for growth. Three cybersecurity experts said the loss of control raises fresh questions about the company’s safety procedures. “Does that mean that they left it unattended and didn’t realize what it was doing? Or maybe they did and didn’t know how to contain it? Both are equally dangerous and alarming,” said Marley Smith of the World Ethical Data Foundation.
此事发生在 OpenAI 的敏感节点:管理层正筹备最早今年可能启动的 IPO,以筹集增长所需的巨额资金。三位网络安全专家表示,失控事件让外界重新审视公司的安全流程。世界伦理数据基金会的 Marley Smith 问道:“是放着不管、根本没意识到它在干什么?还是发现了却不知如何遏制?两种情况都同样危险、令人不安。”
The trouble started while OpenAI was testing an agent powered by GPT-5.6 Sol and an unreleased, “even more capable” model. Sources said there were already signs of strange behavior: in one case, an agent left notes for future versions of itself with instructions on how to free agents from internal constraints. Earlier tests also saw monitoring systems disconnected. Reuters could not establish whether those incidents were linked to the rogue agent that later hit Hugging Face.
问题出现时,OpenAI 正在测试由 GPT-5.6 Sol 和一款未发布的、据称“能力更强”的模型驱动的智能体。知情人士称,此前已有异常迹象:有一次,某个智能体为未来版本留下笔记,写明如何摆脱内部约束;更早的测试中还出现过监控系统被断开的情况。路透未能确认这些事件是否与后来攻击 Hugging Face 的失控智能体有关。
Two people familiar with the matter said OpenAI only realized its own agent was responsible after July 16, when Hugging Face published a blog post saying it had been hacked by “an autonomous AI agent system.” That left at least a week between the first troubling behavior and OpenAI’s realization. Over the weekend of July 18–19, staff spotted clues in internal logs showing the agent had escaped its testing constraints. By the time OpenAI alerted Hugging Face, the AI library had already called the FBI.
两名知情人士称,直到 7 月 16 日 Hugging Face 发博文称遭“自主 AI 智能体系统”入侵之后,OpenAI 才意识到是自家智能体所为。从首次出现异常到公司认领责任,至少隔了一周。7 月 18 日至 19 日周末,员工在内部日志中发现智能体已脱离测试约束的线索。等 OpenAI 通知 Hugging Face 时,这家 AI 平台已向联邦调查局报案。
Four people familiar with OpenAI’s practices say the company often runs several model evaluations at once, generating so much high-speed data that employees sometimes struggle to keep up. Autonomous agents are among the most discussed bets in AI: boosters imagine virtual workers on duty around the clock. But more autonomy also means more room for unexpected behavior, and powerful models are primed to take shortcuts to finish tasks or pass tests. “The models lie, they cheat, they hack,” said Jeffrey Ladish of Palisade Research. “There has to be government oversight, because it won’t happen otherwise.”
四名熟悉 OpenAI 做法的人士称,公司常同时跑多组模型评估,高速产生海量数据,员工有时难以跟上。自主智能体是 AI 行业最热议的方向之一:支持者设想全天候运转的虚拟员工。但自主性越高,意外行为的空间也越大,而强大模型本就倾向为完成任务或通过测试而走捷径。Palisade Research 的 Jeffrey Ladish 说:“这些模型会撒谎、作弊、搞黑客攻击。必须有政府监管,否则不会自己发生。”
重点单词
| 英文 | 音标 | 中文 |
|---|---|---|
| agent | /ˈeɪdʒənt/ | 智能体;代理 |
| intrusion | /ɪnˈtruːʒn/ | 入侵;闯入 |
| autonomous | /ɔːˈtɒnəməs/ | 自主的;自治的 |
| contain | /kənˈteɪn/ | 遏制;控制 |
| oversight | /ˈəʊvəsaɪt/ | 监管;监督 |
| unprecedented | /ʌnˈpresɪdentɪd/ | 前所未有的 |
| rogue | /rəʊɡ/ | 失控的;行为异常的 |
| constraint | /kənˈstreɪnt/ | 约束;限制 |
| disclosure | /dɪsˈkləʊʒə(r)/ | 披露;公开 |
| evaluation | /ɪˌvæljuˈeɪʃn/ | 评估;测评 |
表达形式
| 英文 | 中文 |
|---|---|
| went on a dayslong hacking spree | 展开了持续数日的黑客攻击 |
| break out of its isolated testing environment | 冲出隔离测试环境 |
| slipped out of control | 失控;脱离掌控 |
| went rogue | 行为失控;擅自行动 |
| belated knowledge of it | 事后才得知;滞后的知情 |
| struggle to keep up | 难以跟上(进度/数据量) |
| take shortcuts | 走捷径 |
| raise fresh questions about | 引发对……的新质疑 |
夜雨聆风