u/GazelleRare

I (cybersecurity professional) broadly share Isaac’s takes on AI; the HuggingFace hack is no marketing ploy

I (cybersecurity professional) broadly share Isaac’s takes on AI; the HuggingFace hack is no marketing ploy

Others have posted this “reader dissent” already, but a few things have been released on this incident since Isaac’s original take. One is HuggingFace’s blog post detailing the attack from their point of view, and the next is this video from OpenAI which adds more color to the exploit chain unleashed on their infrastructure.

My takes to this point on AI have largely been aligned with Isaac’s. I think the proclamations from AI companies predicting the extinction of white collar jobs at the hands of AI by <insert alarming amount of time> are largely hype designed to get investors on board. I say this not as someone who is completely anti AI or finds no uses for it. I use AI daily in my work, although not to the extreme degree some
of my peers do where they have no clue what’s actually being done but seem satisfied enough that the tests are passing.

So when I heard about this attack and heard Isaac’s take on it, I thought “yep, they’re saying this mysterious new model broke out of its sandbox and targeted this conveniently friendly-to-AI company. We’re not going to get nitty gritty details or if we do, they’ll reveal that someone ‘accidentally’ left the door open.” But after reading/watching the linked materials, that’s just not the case. Over the course of this attack, the model(s) discovered and exploited 3 zero-day vulnerabilities. They attained admin permissions across several different organization’s Kubernetes clusters, and did so by collaborating with many other agents via a message board they constructed in two different methods (the first one was found and removed). Every time I thought to myself watching the video “oh, but that’s actually just bad security practice, kinda a rookie move giving the agents write access to your Artifactory instance.”…. Yeah OpenAI would discover what had happened, lock things down, and the agents would do the exact same thing in a completely novel way.

Not really sure how this fits into my overall skepticism of AI hype, but I won’t be able to doubt the capability of multiple frontier model agents working together to accomplish something.

u/GazelleRare — 13 days ago