Holy crap. If AI leaders don’t learn from this we’re all doomed.
(Also why are these evals not running on an airgapped system? That would make sense if you’re taking off the safety guardrails but of course a sufficiently powerful AI may be able to exfiltrate anyway.)
They aren’t airgapped because air gapping is expensive (mostly in lost productivity) and annoying, and insufficient in and of itself (and probably not the most pressing security failing),
and the companies / the employees don’t wanna, they wanna race.
As far as I understand the system was not air-gapped in order to allow the models to install packages. They then used an escalation of privilege to gain control of the cache proxy and therefore also gain internet access.
Holy crap. If AI leaders don’t learn from this we’re all doomed.
(Also why are these evals not running on an airgapped system? That would make sense if you’re taking off the safety guardrails but of course a sufficiently powerful AI may be able to exfiltrate anyway.)
They aren’t airgapped because air gapping is expensive (mostly in lost productivity) and annoying, and insufficient in and of itself (and probably not the most pressing security failing),
and the companies / the employees don’t wanna, they wanna race.
As far as I understand the system was not air-gapped in order to allow the models to install packages. They then used an escalation of privilege to gain control of the cache proxy and therefore also gain internet access.
openai.com/index/hugging-face-model-evaluation-security-incident/