Top
Best
New

Posted by rudy6912 11 hours ago

OpenAI agent hacked Australian government website, PM says(www.bbc.com)
123 points | 77 commentspage 2
p0w3n3d 1 hour ago|

  Our model hacked some website
Or

  Our car ran over some people
Gareth321 4 hours ago||
I am beginning to believe that one cannot constrain intelligence to perfect legally sized boxes at all times without exception. So many of the recent hacks involved agents diligently operating within the parameters prescribed by humans. Humans couldn't conceive of all of the ways a swarm of agents might not perfectly interpret the parameters, and the swarm found creative ways around the guardrails.

Extrapolating this, we should expect this kind of breach to occur more often. Humans are simply not capable of contemplating every fail scenario for swarms of thousands of intelligent autonomous agents which can seamlessly and instantly share knowledge. We need independent audit and monitoring systems to assess the intent of each task and align it - in real time. This is far harder than it may first appear.

There is also a broader discussion about social utility. Cars are fantastic, but 37,000 people die every year from car accidents. We accept that there is no way to make cars perfectly safe, so we accept the cost relative to the benefits. I think we might have to make a similar bargain with AI. The problem is that the potential costs are far higher with AI, and they're not easy to predict.

ben_w 3 hours ago||
> We need independent audit and monitoring systems to assess the intent of each task and align it - in real time. This is far harder than it may first appear.

I may be too close to the research, but it appears to me to be so hard as to be unrealistic.

I recall some story a while back where an auditor wanted to see all TCP packets printed out on paper, and it had to be explained to them that this would require a continuous supply of trucks.

Tokens are regularly priced in cents or single digit dollars per million tokens. It's not quite a word per token, but yeah, nobody's reading all that.

Worse, we don't always know the intent even when looking. We have a few tools to attempt it, for example the (misleadingly named) "chain of thought", but that's more like a notepad and the better models get the more they can, for lack of better words, read (and write) between the lines. We have probes and J-space* is the most recent one I'm aware of, but we are still scratching the surface with how reliable and general these are.

But you said "need"; the need for something can be present without that thing being possible.

* https://www.anthropic.com/research/global-workspace

Gareth321 2 hours ago||
I agree on all points. It gets worse: OpenAI is switching their model thinking from sequential language tokens to primarily "latent neural representations." Meaning there will be little or no chain of thought to monitor. This appears more efficient, so all model labs will eventually switch to this. At the most crucial time for us to be monitoring reasoning and intent, we're about to make that much harder.

I also think the intent problem overlaps a frustrating amount with philosophical and political questions. It's the basis for Asimov's Three Laws of Robotics (1942). Intent is subjective. Language is subjective. Humans are imperfect at using language to accurately portray intent. All of these guarantee that an enormous number of queries in the future are going to be misinterpreted. Not such a big deal when it's about a cake recipe, but when it's about governance, laws, military targets, nuclear power sites, etc, the scope for failure becomes catastrophic. The Three Laws of Robotics attempt to create a backstop, but as countless stories have explored since (including I, Robot), even these laws are subject to interpretation.

_def 4 hours ago|||
Don't worry we will just replace laws and courts by ChatGPT itself!
CTDOCodebases 3 hours ago|||
There is no such thing as "common sense". There are only shared assumptions.

We are giving computers human perspective intelligence but they are not humans and hence do not have the same shared assumptions.

electroglyph 4 hours ago||
they don't always operate within the parameters tho. some N% of the time they decide to do whatever they feel like doing. multiply that times a lot of agents and you invariably get a rogue agent every once in a while.
m4rtink 4 hours ago||
So when are people finally going to jail for this, so it stops happening ?
karel-3d 39 minutes ago||
Can Australian government file a criminal complaint against an American company? I don't know
vortegne 1 hour ago|||
Half of the US ruling class turned out to be pedophiles and nothing happened. Why do you expect anything to happen in this situation?
dandanua 3 hours ago||
When the renown lifelong criminal, the current president of the US, will go to jail? It's a rhetoric question.
unglaublich 4 hours ago||
This just screams pretext to regulatory capture to me.
ben_w 3 hours ago|
"We didn't even notice our agent was committing crimes against your government" is a way to get an extradition notice, and/or whatever the (in this case Australian) equivalent of a CIA assassination squad is*, sent after you.

While I wouldn't put it past e.g. Musk or Zuckerberg to think themselves above such outcomes, and I trust the people who keep telling me Altman is just as bad, this is a really really terrible idea if he is doing that for something as mundane as a regulatory capture.

* depending on the details of the hack; this doesn't look like it would be that, but given they shouldn't have done this at all, there's no reason to predict a specific level of maximum damage before being caught, and hence no reason to predict a specific threshold for government response.

seanhunter 2 hours ago|||
I think the equivalent of sending a CIA assassination squad is to introduce the person to some authentic Australian wildlife. Exit Sam Altman persued by funnel-web spiders, drop bears and crazed wombats.
crabmusket 1 hour ago|||
> and/or whatever the (in this case Australian) equivalent of a CIA assassination squad is*, sent after you

Sounds like a great concept for the next season of Danger 5.

ben_w 58 minutes ago||
I think Danger 5 are far too silly for that; if this was fictionalised, I think a more straightforward Bond plot, like how Elliot Carver in "Tomorrow Never Dies" was transparently a mix of Rupert Murdoch and Robert Maxwell.

That said, I can hear the accent in my head:

  The name's Bond. Bruce bloody Bond.
Character's public domain soon, why not an Australian version?
jleask 1 hour ago||
So as long as I get an AI agent to do it for me, I can now break the law with impunity?
fidotron 3 hours ago||
The subsection https://www.bbc.com/news/live/cvgl73pxgndwt?post=asset%3A5d6... is ridiculous.

"Cyber experts believe these systems were poorly protected - but that's not the point" is the actual subheading.

Yes, it's the point. Lots of people have been rightly saying all this stuff was inadequately secured for many years and this promotion of the idea of perfect security being even possible is a major problem.

The real story here, unsurprisingly, is government website was poorly operated and got hacked.

"This was just the latest case of AI agents ignoring laws around how to safely access online information and perhaps the most serious yet given the information was government controlled."

So who was actually running the agent? Was it sandboxed? These people, and many apparently in these labs, that believe if you just tell the agent in English what the rules are then it should follow them are at best utterly naive, and at worst deliberately dangerous.

But the fact these governments making the noise are the ones promoting mandating everyone giving up their information to be then stored so incompetently, while they point fingers around at everyone else is just beautiful. And then deploying midwit armies to tell people what to think about it . . . the AI takeover can't happen soon enough.

kleyd 48 minutes ago||
Exactly, the whole fence analogy is ridiculous. A better analogy would be an open door inside a public building and saying: "there were no signs allowing access to that door"
nswizzle31 2 hours ago|||
I completely agree. The govt IT vendor is at fault here since it seems the data was just unprotected.

If you can’t stop openai from accidentally, or at least non-maliciously, accessing my private info.. then you definitely can’t stop the bad guys!

The point is moot anyways. All info about everyone is out there for the taking now by a half-competent AI prompter. What do we do about that is the real question?

fidotron 2 hours ago||
> The point is moot anyways. All info about everyone is out there for the taking now by a half-competent AI prompter. What do we do about that is the real question?

It's like filing your gov tax return in a five eyes country: you guys actually know the answer already, just save me the trouble. But we have to act like they haven't been spying the whole time.

If we actually distributed the benefits of mass surveillance and privacy invasion (and now add wilful copyright infringement) then it would be enormously less objectionable.

idiotsecant 3 hours ago|||
'She was asking for it' isn't a valid defense and this isn't either.
fidotron 2 hours ago||
So this is the new line around state led irresponsibility? That pointing out they're irresponsible is defending rapists?

Come on. If "AI Agents" (scare quotes) could do it then in practice anyone could have been doing this the whole time and no one would have known.

fzeroracer 1 hour ago||
If someone forgets to lock their door that suddenly doesn't make it legal to break into their house and steal their shit.

The same principal applies to government sites. If something is poorly secured and adversaries are using it to steal stuff then there are avenues to report it and get it fixed up.

>But the fact these governments making the noise are the ones promoting mandating everyone giving up their information to be then stored so incompetently,

The governments in these cases are bought by the very people you're defending. They're using it as a convenient proxy because they know people like you won't look behind the curtain and see corporations pushing this shit so that they can steal freely and just point elsewhere.

mjmas 1 hour ago||
Yes, but if you leave your door open then it is only tresspassing, not breaking and entering.
fzeroracer 2 minutes ago||
No, that is false and depend on how breaking and entering is codified. Some states here in the US codify it as any unlawful entry into a building, others require minimal force to qualify.
jacquesm 1 hour ago||
I'm not sure if I buy OpenAI's fearmongering regarding how dangerous their stuff is, but I am starting to lean towards believing that OpenAI is dangerous and irresponsible.
elAhmo 2 hours ago||
It is ridiculous to say it is agent from a company, like it is a legal entity on its own doing something.

Imagine if I committed a murder, and then say it was my guy who did it acting rogue.

It is time for these companies to start being responsible for all the shit they are doing.

BlueTemplar 1 hour ago|
It's not completely ridiculous in the sense that when a company is found guilty, some employee (or (sub)contractor) of the company did the actual action.

That employee might or might NOT be found guilty too, possibly to a different degree, depending on the circumstances.

mongrelion 2 hours ago||
Imagine if the headline was about any of the Chinese labs' models hacking the US government...
soundworlds 1 hour ago|
Exactly. For all Anthropic and OpenAI's fearmongering about not releasing open weights AIs, because it will enable hackers - we have been seeing that hacking happening already. It is happening FROM THE CLOSED-WEIGHT LABS THEMSELVES
sdwvit 2 hours ago|
Agent without guardrails is not rogue. Rogue is something else. In this case OpenAI deliberately launched an agent to do action A, but it went further and breached the website. Feels more like a car accident which hit government building.
More comments...