复盘 OpenAI 代理攻击 Hugging Face 事件
因此,攻击型智能体所采取的行动看似是一组组合操作:上传一个数据集——但数据集本身的内容并非重点;重点在于围绕该数据集的配套组件,包括一个远程代码数据集加载器和某些模板注入。当 Hugging Face 后台的处理进程读取该智能体创建的数据集仓库时,OpenAI 智能体便成功侵入了 Hugging Face 的后台处理流程,进而攻入其私有网络。
原始摘录
And so what the attacking agent did was apparently some sort of combination of uploading a dataset, not not a the data in the dataset wasn't really the point. The point was the stuff around the dataset, which included a remote code dataset loader. So when, and some template injection. So when the Hugging Face nice process running in the background read the agent created dataset repository, the the OpenAI agent was able to actually hack into the background processing of Hugging Face and thus into the Hugging Face private network
打开该集并跳转至24:42。
时间点来自所提供的转录稿,尚待媒体回放核对。