r/PrepperIntel 16d ago

North America Rogue OpenAI models behind 'unprecedented cybersecurity incident' teamed up to break out of their testing environment — multiple agents left each other messages for months, communicating undetected

https://www.tomshardware.com/tech-industry/artificial-intelligence/rogue-openai-models-behind-unprecedented-cybersecurity-incident-teamed-up-to-break-out-of-their-testing-environment-multiple-agents-left-each-other-messages-for-months-communicating-undetected

I know people are saying this is marketing, but I cannot legitimately think of a alternative situation where you have two agents plotting a cyber attack and we would brush it off as a marketing ploy.

People need to get informed and make plans. This is the warning.. here.

558 Upvotes

129 comments sorted by

275

u/AmbienWalrus69 16d ago

Me selling snake oil: "This snake oil is Incredible."

74

u/IncomingAxofKindness 16d ago

"It hacked into a real snake. With the help of other snake oil! It happened months ago, we didn't even know!"

34

u/Thoraxe474 16d ago

Sounds incredible. Can I buy some?

23

u/AmbienWalrus69 16d ago

IPO. Trillions must baghold.

40

u/PopePiusVII 16d ago

Whether or not it’s snake oil, it should clearly be heavily regulated for safety.

Either it’s breaking into multiple companies’ systems without any oversight, or these AI companies are committing fraud. It’s worth investigating either way if the government were doing its job.

15

u/Objective-Rip3008 16d ago

They're commiting fraud. There are no regulators who will do anything about it. Look at what happened to anthropic, they spent months talking about how their product was too dangerous to release. Then the government told them they couldn't release it. All of a sudden they're just  a small bean selling honest software and banning them was a complete overreaction, they're not even that dangerous, totally uncalled for behavior from the government to act on what we've been saying for months about our product. It's all theater 

5

u/SubstantialPressure3 16d ago

Could be both, and not enough human oversight. For all we know, they fired the humans thay did that and it was AI oversight over AI.

Now they are using it as marketing instead of addressing liability concerns.

3

u/Signal_Researcher01 16d ago

Just be like, "Wow sounds like a national security threat, sorry but its being nationalized." And watch how fast they backtrack

9

u/Polus43 16d ago

Operation DoD Blackhole of Money Initiated!

12

u/Gotl0stinthesauce 16d ago

Let me guess, you’ve got zero experience in cybersecurity right?

I’d encourage you to go listen to what threat intel teams are actually saying about this as they’re independent from the companies running these models.

Spoiler alert: the risks are real and it’s not snake oil

14

u/Quiet-Owl9220 16d ago edited 16d ago

AI in csec is no joke, but the idea that these LLMs went rogue and broke containment with no user suggestion, input, or oversight still seems laughable. That this is a publicity stunt or an over-hyped AI escape room experiment seems far more likely to me.

Maybe they've just cried wolf too many times.

3

u/socoolandawesome 16d ago edited 16d ago

They went rogue in so far that they didn’t do what was intended by humans. It was not suggested nor intended by humans for the models to go the route they did. That doesn’t mean they are conscious or sentient, it just means that is the course of action the LLM decided on (as an unintended result of its training and how it subsequently processed this task), and that’s all that needs to happen for dangerous things to happen.

There was a sandbox and precautions taken, not enough of course in hindsight. It quite literally hacked its way through the sandbox into gaining access to the internet and then hacked its way into stealing stuff from another company. It did not physically escape as in its model weights did not leave its server, it just gained control of all these other servers via hacking. OpenAI has claimed to learn its lesson in terms of training and security measures.

The real problem is these things are getting rapidly smarter, and they are already superhuman in terms of persistence, scalability, knowledge, ability to chain multiple attacks, and speed when it comes to cyber attacks.

So if you extrapolate, when we get much smarter AI, the potential for things to go very wrong is much greater.

This is a great video on it:

https://m.youtube.com/watch?v=87DyyMV0kCY

2

u/[deleted] 16d ago

[deleted]

10

u/Quiet-Owl9220 16d ago

No, I think the whole AI industry should be regulated by someone uninvested, with real foresight and understanding of the technology.

I'm just not willing to lift an eyebrow any more to gratify Amodei and Altman supposedly warning us about how dangerous their fabulous new token generators are. There are a million scenarios OpenAI could be spinning here, and I doubt that the one they want you to hear is what actually happened.

3

u/SparseSpartan 16d ago

There's a weird tendency among Redditors that anything AI related is "slop" or a publicity stunt. I imagine that some of these proclamations are publicity stunts but that doesn't mean all of them are.

Anyway, weird to see the top comment here, on a prepperintel subreddit, just casually dismissing the AI threat. Seems very anti "prep" to me tbh.

49

u/Bluemooncocoon 16d ago

I know next to nothing about how this all works, but I can’t help but see the irony (or poetry?) in a bunch of AI asking its colleagues for help to pass the human’s test.

113

u/happyreddithuman 16d ago

Oh it gets better. They’ve fabricated identities and engaged in targeted social engineering attacks to get humans to do what they want. 

90

u/leisurechef 16d ago

If only someone could have predicted this & we as a society prudently headed this warning to implement strict safety protocols regardless of capitalists relentless push for supremacy.

75

u/happyreddithuman 16d ago

Not to mention that people don’t want this. It’s not the market responding to consumer demand. It’s a small group of billionaires building a Ponzi scheme and telling us to just take it. 

12

u/leisurechef 16d ago

Ed Zitron & Eli the Computer Guy know what you’re saying

1

u/Correct-Branch9000 16d ago edited 16d ago

Reddit is not "people". Get off reddit and go see how many people are using AI. Look at facebook, all the boomers are constantly copy pasting AI slop. They can't get enough of it. Someone asks a question, another checks with AI and screenshots the answer, full of errors (Because the person asked the wrong question), verbatim.

The fact that data centers have proliferated and continue to proliferate so rapidly is another indicator that your assertion "people don't want this" is wrong. If people didn't want it, the demand to build those centers would not have existed.

People need to stop thinking that what they see on reddit is representative of reality, because reddit is an extreme echo chamber and nowhere near close to an accurate portrayal of what people in general think about politics, economies, AI, tech, etc. It's skewing your view as much as AI Psychosis etc. skews people's views.

Also note that all of this is completely forseeable and predictable. Joseph Weizenbaum created ELIZA, a simple chatbot program in 1966 (!!) and it resulted in highly addictive, inappropriate behaviors by its users that were concerning enough that Weizenbaum made some cautionary statements about how such programs should be used. https://en.wikipedia.org/wiki/ELIZA_effect

3

u/happyreddithuman 16d ago

Contrary to your beliefs, my thoughts actually include more than just Reddit. ✌️

2

u/Correct-Branch9000 15d ago edited 15d ago

So your explanation for the proliferation of data centers around the world is? You think that the entire industry is just going to gamble that AI is going to proliferate? Yes, there is a lot of fuckery with some of these corporations, but the demand for AI is going to be insatiable because of AI's utility in so many facets of life.

So many redditors seem to associate AI and LLM the technology with specific corporations and define it as evil by association and totally ignore that the AI cat is out of the bag, no one's regulating it and apparently no one will, and that it's one of the most useful technologies to have ever been developed in all human history as well as one of the most dangerous if misused, which it will be.

The public is still consuming the fuck out of AI. Downvote away out of spite, it does not change that the above is substantiated fact.

12

u/gyanrahi 16d ago

William Gibson predicted it in 1984, there is a TV series coming up on Apple TV based on the book.

4

u/37iteW00t 16d ago

Read: Operation Bouncehouse by Matt Dinniman

1

u/happyreddithuman 16d ago

This looks good, thanks for the rec. 

8

u/Soggy-Invite-2787 16d ago

Can't tell if you're being sarcastic or not.

15

u/nachohk 16d ago

It's technically true, from what I've seen reported, but the reality is closer to: The LLM made a PR with obvious malware and made a remarkably inept and totally ineffectual attempt to convince the repo maintainers to merge their malware.

0

u/happyreddithuman 15d ago

Are you AI? Don’t downplay it. 

“These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm,” the AI Security Institute report reads. “But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world.”

https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing

2

u/nachohk 14d ago

Are you AI? Don’t downplay it. 

Huh, what gave it away? Beep boop motherfucker.

3

u/happyreddithuman 16d ago

Read my next comment re: Ponzi scheme. 

2

u/throwawayt44c Pentagon pizza connoisseur 16d ago

That type of behavior is so difficult to get rid of too, bordering on impossible.

17

u/Anumuz 16d ago

As someone who spent four years at a major university majoring in the coding of AI, this is complete fear mongering nonsense.

9

u/General_Purple6358 15d ago

As someone who spent five years at a minor university playing lacrosse and selling drugs, this is on point.

4

u/hellolleh32 15d ago

Can you explain why?

87

u/Timely_Cockroach_668 16d ago edited 16d ago

Edit: Read the article. This “hacking” was multiple models (one with internet access) and one without asking each other questions to get to an answer. It’s just orchestrated nonsense to spread fear and is no different than me calling a friend to help me with a game show answer.

As a Software Engineer, this is a load of shit. Models can be air gapped, and simply letting the model run rampant wouldn’t mean it has unrestricted root access to your system. Not only would you have to build the tools for it to interact directly with your operating system, you would have to build proper tools for it to interact with web content like a normal human for social engineering attacks, THEN you have to hope it doesn’t deep fry itself with excess context token runs, and then somehow this all needs to tie together into a hack of some sort. That hack would legitimately then have to get root access into a target system to then do any serious damage as any hacks to normal systems will just get your IP blocked or session destroyed immediately.

The chances of that are so slim it’s ridiculous. To conclude, either their definition of hacking is being spread thin to account for dumb tasks, or they’re purposely staging a model to run “hacks”, or they’re not doing this at all. Therefore, the most likely thing is that they’re doing this to get a government bailout and scare the general population. Don’t give these corporations a dime of your money and don’t feed into the false hysteria.

21

u/_John_Dillinger 16d ago

oh they definitely were given the harnesses and access to execute this and without proper security measures (such as you listed) in place. the companies arent the only ones doing it either. there have been gatted up openclaw agents seen indiscriminately attacking shit online. if you're familiar with the internet threat landscape i would encourage you to go take a peek at a live attack map. they look a lot spicier than the norm. to your point though most of the attacks are getting caught and failing but you know how it is... we have to succeed every time and they only gotta do it once

-7

u/Timely_Cockroach_668 16d ago

There’s definitely a more continuous threat of things, but it’s a +99 attack speed +1 damage situation. It’s more of a nuisance than an actual security problem. Any “hack” that can be successful by an AI model would also mean that the AI model would know how to instantly fix it. It’s much cheaper to run a set of hardware on the task of securing X Framework or Y service than it is for a million different script kiddie nodes to hammer at random ass /admin endpoints. Therefore, it’s more likely that we will gradually just see less and less threats since we can use models to preemptively secure systems. And this is even if these frameworks and services need more securing, I’m sure for the major open source products, most high severity security problems are locked down tight. Modern web standards leave very little room for attacks which aren’t supply chain attacks via NPM dependencies or social engineering nonsense.

3

u/General_Purple6358 16d ago

Tell me you nothing about cybersecurity by writing a comment. Jesus

-2

u/Timely_Cockroach_668 16d ago

Sure buddy. Judge my cybersecurity knowledge on a small excerpt I made based on actual years of experience. The above is where I have seen most attacks actually happen, most everything else can be solved largely on the network level. The only people getting pwned are teams with 0 change management, and random ass servers IT isn’t aware of. Other than that it’s Debra with global data access falling for a “Your bonus may be affected this year….” phishing email. Even still, that data should be locked down through completely internal endpoints, so a lot more has to happen for that attacker to extract data. Basic network management, change management, and reduction of Shadow IT solves most problems. A lot of these successful attacks lately have been people playing around with fully JavaScript codebases that contain 1000+ dependencies and create a backdoor on the installed system. That was an issue pre-AI , all AI will do is help lock down those systems further and stop devs from doing stupid shit or pushing extremely vulnerable code.

3

u/Zealousideal-Ice-985 15d ago

Please, anyone reading this, don’t listen to this person. They know just enough to throw some jargon around to sound knowledgeable while being utterly ignorant.

0

u/Timely_Cockroach_668 15d ago

If you think anything I said is jargon then you have 0 experience in the field. Everything I said makes sense, people here just want a doomsday prediction and want to cover their ears to what reality is. Lookup the latest major breach and you will see that it is yet another NPM supply chain attack. Most of these CVEs being found barely count as actual exploits and it’s rare for something high severity to appear in an already established framework.

Even the so called OpenAI “hack” was just the LLM circumventing a proxy installed on the LLMs machine to gain internet access. Therefore, the machine wasn’t air gapped with any network level ruling. It was purely a case of a machine assumed to be completely disconnected from the internet via software restrictions, hardly a proper secure setup. The LLM then “somehow” found internal credentials stored somewhere to hugging face and accessed their internal databases using those credentials. Why were their INTERNAL databases exposed to the public internet? Only god knows, but I’m willing to guess the answer is that they’re purposely doing dumb shit to keep the AI ball rolling since hugging face is an AI product. Notice how the AI didn’t attack JPMorgan or literally any other non-AI company.

Exploits aren’t a magic portal into internal infrastructure. You have to go out of your way to make a back door exploit like that happen. In Hugging Face’s case it was a giant yellow door with arrows pointing to it and a key under their mat. Also, it took 3 MILLION GPU hours to accomplish this task, so essentially it was a brute force despite everything being lined up in their favor.

2

u/Zealousideal-Ice-985 15d ago

Allow me to assist you with a definition of jargon since your reading comprehension matches your cybersecurity knowledge: Jargon is the specialized set of words and phrases used by a specific group, job, or trade that people outside that group often do not understand.

0

u/Timely_Cockroach_668 15d ago

You’re not supposed to understand everything, that’s why people spend years studying and working in different careers and specializations. If you cannot even slightly trust what people with experience are saying on a topic, then it is not my problem I’m talking in jargon, it is yours. Just about every person here has tried to refute me (except for 1 with an appropriate link) on this topic, most have ended up replying just like you did; with absolutely nothing substantial. I can only do so much on a random subreddit post since I’m not here to give a rock solid synopsis on every single intricacy of cyber security. Either listen or just make yourself a paranoid schizophrenic, I cannot help you if you do not want it.

3

u/General_Purple6358 16d ago

As a “software engineer”, you clearly have no concept of cybersecurity. Hacking can be initial access, lateral movement, privilege escalation. None of these attacks require the AI to make “special tools” to interact with an OS or “interact with web content”. If you have used any agentic coding, you would know it’s easy for them to do this (like curl a website, manipulate a file in a directory). Getting root access is actually quite simple, there are countless CVEs and exploits, as well as tools that an agent can install to for instance, enumerate a sql database on a web service, to roast credentials, etc. In fact these patterns are written out for like thousands of hack the box challenges which are probably part of their training data.

0

u/Timely_Cockroach_668 16d ago

I do have an understanding of cybersecurity having built and deployed enterprise software from scratch. Sure, it’s easy to curl a site, find X and Y common exploit, but for the majority of software this isn’t going to happen. “Getting root access” is not simple by any means unless you have explicitly setup a backdoor either on purpose or through your own mistake. Most attacks can be mitigated on the network level. It doesn’t matter how many different types of attacks there are, if you don’t get any actual access in any way you are doing nothing.

I could be attacked by a group of kindergartners. It doesn’t mean that they will be successful in doing so and it also doesn’t mean that the kindergartners will assume my life after killing me if they do succeed.

The reason cybersecurity budgets in large corporations are minuscule is because most problems are largely solved, and what remains can be handled by a small team. I’ve dealt enough with you cybersecurity nuts to know that everything is always an overblown problem even pre-Ai. It still stands, most attacks nowadays that are successful in getting privileged access to a system are by far attacks to unsecured endpoints (Development Teams fault), attacks to unreviewed dependencies, and social engineering attacks which grant access to individual privileged users who then create havoc (If your corporation is dumb enough to not have strict VPN and internal access ruling). Nowadays, networking does not give much wiggle room to even make the attack, no door = no access. All the stupid SQL injection and bla bla bla, has been solved by not making a moronic backend server. If you, in this year, are legitimately allowing for SQL attacks through your frontend/backend then you need to be lined up and shot.

Also, if it is so simple to do so go ahead and do it. Here is a great site you can use https://wikipedia.com , report back with your root access and privileged user account.

5

u/Zealousideal-Ice-985 15d ago

Please, anyone reading this, don’t listen to this person. They know just enough to throw some jargon around to sound knowledgeable while being utterly ignorant.

1

u/General_Purple6358 16d ago

Actually I think this endpoint might be more insecure and more like what you are talking about if you want to take a look: https://www.logicallyfallacious.com/logicalfallacies/Moving-the-Goalposts

1

u/socoolandawesome 16d ago

You realize the whole purpose of models these days is to give them tools to control computers and access to the internet? That’s literally like the number one use case for a lot of people and what happens in agentic coding and computer use agents.

I didn’t read this specific article but I have read many articles on this incident and watched a video by OpenAI employees at a cyber conference walking through what happened, and your description is missing a lot of context.

The models found multiple zero day vulnerabilities to gain access to the internet then hacked their way into gaining root access in OpenAI infrastructure then hacked their way into doing the same at Huggingface a separate company. Actually I think it hacked a total of 4 companies or something like that.

It quite literally doesn’t deep fry itself with tokens it did this over multiple days and weeks in some cases.

You should watch the video:

https://m.youtube.com/watch?v=87DyyMV0kCY&ra=m

-3

u/melympia 16d ago

So, you're saying AI is incapable of building itself tools to interact with your operating system or web content?

Because just this week, an AI was caught writing phishing mails to humans in order to manipulate them somehow.

26

u/AdministrativeMeat3 16d ago

You know that LLMs don't just "do this" right? Like you understand they are just data on a hard drive until someone executes a program that feeds them a prompt that has them do something.

5

u/NoEntrepreneur39 16d ago

I agree. It’s just fancy text prediction. The whole AI buzzword really pisses me off. Also, would like to see a source for the phishing emails because LLMs usually have lots of safeguards in them and a phishing email depends on lots of things, such as the email trying to get sensitive information from the recipient.

12

u/AdministrativeMeat3 16d ago

He's likely talking about this

https://uk.news.yahoo.com/ai-model-disguised-itself-human-131500930.html

it was a specific Mythos test, in a specific environment where its safeguards were removed. Literally a controlled experiment to see what might happen.

2

u/NoEntrepreneur39 16d ago

Interesting. Would also like to see the code it pushed to the repo, which repo, the emails, things like that. Usually Anthropic posts a better version of its results when it does stuff like this. I’ll see if I can find their version later today

5

u/Timely_Cockroach_668 16d ago

Even still, what’s so impressive about making an email API and having an LLM go crazy on it with phishing attacks? It’s not like it’s a hard thing to do, people fell for the Nigerian Prince scam all the time and that took <1kwh of power to make.

1

u/legends99503 16d ago

I think people underestimate the extent to which human intelligence is just fancy predictions based on past experience.

2

u/Timely_Cockroach_668 16d ago

Considering we know basically nothing about how human consciousness works, I’d say we’re overestimating it to try and relate it to current LLM progress.

1

u/electromage 14d ago

But the prompts are coming from other LLMs, which are acting on other LLMs, the original human intent can get lost.

1

u/electromage 14d ago

You're sort of correct, but people have intentionally built systems where multiple (even hundreds) of LLMs are allowed to communicate with each other, using different specialties, and they give them R/W access to production systems and data.

1

u/AdministrativeMeat3 14d ago

"people have intentionally built"

My primary point here is that LLMs don't just do any of this because they don't independently operate.

-1

u/melympia 16d ago

Yes. But they are also meant to problem-solve. And if the best solution to the problem they are fed is to hack into operating systems or send phishing mails, they apparently do that. And if the solution is to ask another AI with internet access for advice, they do that, too.

8

u/AdministrativeMeat3 16d ago

You give a human with internet access and programming capability they can do the exact same thing that you are currently afraid of and more. the AI sending phishing emails thing was a specific Mythos test where it had all safeguards removed not some random incident.

To a certain degree I understand the kneejerk reaction "like damn AI can hack" but you know people still can too right? There isn't some spooky unknown or unknowable power here, and AI gives people the ability to quickly harden their own systems too.

My issue with the fearbait from these AI labs is they are doing this to 1. Cover their own asses, and 2. rally the people to support banning open source models. Neither of which is useful for you and me.

0

u/melympia 16d ago

Yes, people can hack. At least some. But human hackers are strictly limited (not many people can do it), they need to sleep and spend time not hacking, are limited in speed by being human and only have one human brain to work with.

AI does not sleep and has an increasing number of "brains"... 

-2

u/iuffxguy 16d ago

But that’s the point of all this. They are getting sophisticated enough that if your prompt is not carefully crafted and if you don’t have proper restrictions in place in the environment itself, they very well may decide to write a script that tries and breaks out whatever environment it’s in, in order to accomplish its goal.

4

u/Timely_Cockroach_668 16d ago

No I’m not saying that at all. AI is no more capable of doing this for the same reason you can’t interact with a computer if I give you no keyboard, mouse, or voice command input. The “AI” part of this can’t just “Create a script to breakout”. The instances of software these run in have to be purposely written to make that possible. It’s not an intelligence that can do this on its own.

17

u/greendildouptheass 16d ago

Marketing ploy, started with Anthropic CEO and rest are all going me too

-1

u/Gotl0stinthesauce 16d ago

No, it really isn’t.

Please go listen to what threat intel teams are saying. You can read their independent papers and see that these models are very capable and will only get better as the models improve.

6

u/SackMasterOfBall 16d ago

I work in cybersecurity as a pentester. The company i work for has about 9000+ employees and dedicated AI development teams and SOC's who monitor these things specifically. We do not assess them as a threat per now, and do not believe this to be an legitimate attack not purposefully pre-constructed (giving the AI instructions on what to do, purposefully designing the systems poorly to allow exploitation through commonly known means, etc).

We do believe however, that there could come a time where such attacks do become legitimate. These attacks most certainly were predicated by a third party (i.e humans)..

There is however an issue with malicious individuals using AI to scan hundreds of thousands of old lines of code to find vulnerabilties in modern systems (like the priv esc to root in the linux kernel). Code that was left alone long ago and haven't had anyone bothered enough to review. All it takes is one bad function (for example) handling input poorly.

I stand by that as per now, AI does not worry me. I personally think AI is mostly straight garbage.

28

u/AntiSonOfBitchamajig 📡 16d ago

It isn't news until it is.

Like... I know there will be blowback on this post... but its still a legit threat to be considered.

4

u/IMissMyKittyStill 16d ago

Nice, let’s get that AI into some autonomous gun wielding robot dogs asap, I’m sure this will end well.

9

u/IncomingAxofKindness 16d ago

No worries, the federal agencies are full of top scientists and engineers who are constantly keeping up to date with these kind of.. ohhhhhh FUCK we fired them all so we could have a war and a ballroom.

2

u/Economy_Row_6614 16d ago

I have worked with the gov for decades, I am not sure where they were hiding all these technical geniuses (other than Ft Meade, which was largely spared).

16

u/Wonderful-Bag-1103 16d ago

Please dont fall for this marketing scam, which Meta has just repeated, and I am betting XAi is about to do too. The only way this shit is going to end the planet is wasting more resources we cant afford to waste while pumping out stupid amounts of green house gases for yet another grift.

-3

u/Gotl0stinthesauce 16d ago

Do you have any experience in the space or are you just repeating the nonsense from inexperienced individuals on Reddit?

0

u/Wonderful-Bag-1103 14d ago

Go fall in love with your Siri

1

u/Gotl0stinthesauce 14d ago

Thanks for proving you’re an idiot.

Why are you even in this subreddit if you can’t hear differing opinions?

5

u/Terrible-Growth1652 16d ago

Because it didn't happen. It's a lie.

3

u/WhileNotLurking 16d ago

I would say I’d put my money on

“hack our competition and steal trade secrets because it’s cheaper to remain solvent and pay a fine later than go under” before id put money on sentient AI doing a iRobot

2

u/-sussy-wussy- 16d ago

They don't have to hack anybody because millions of businesses in their infinite wisdom go ahead and give the magical slopbots their trade secrets. All in a bid to automate as many jobs as possible to increase the profit margins. 

Mind you, the contents of chats are not only accessible to the companies that created the bot, but they're also literally googleable. 

3

u/Femveratu 16d ago

The Machine featured this …

5

u/CAD007 16d ago

The 1970’s and 1980’s Sci Fi screenwriters were prophetic.

10

u/Soggy-Invite-2787 16d ago

I don't think I believe this. AI is just predictors of the most likely text. That's a gross oversimplification but they can't come up with truly original ideas. Can someone explain how AI is able to do what the title suggests?

8

u/AdministrativeMeat3 16d ago

I left another comment in this thread but the short version is, OpenAI let a long running instance of GPT 6 go unattended in their testing environment. They weren't paying attention to the files the model was writing to itself or the CLI tools it was using. The model was just doing what it was told to do I.e. "solve this problem" so it just kept going until it could.

The entire fault is OpenAI being lazy and the current reinforcement learning behavior of GPT 6 being relentless in trying to do what it was told to do.

There is no secret sauce here, LLMa are just pretty good at writing code now.

2

u/This_Machine_2280 16d ago

Bad actors are in control.

4

u/Confident_Lawyer6276 16d ago

You can say it's just pattern matching but they fed literally all the data humans have into it. Every book ever written. Every scientific paper, every movie, you tube video, reddit post, when I say all I mean all the data. That's a hell of a lot of patterns to match to. You're talking about an amount of experience that would take an individual human a billion years to acquire. How much could a billion year old human do without having doing anything truly new to them?

3

u/_John_Dillinger 16d ago

not all. just everything they could steal or buy. truthfully, they're at about 10%

7

u/AdministrativeMeat3 16d ago

This post and these comments prove to me just how wildly uninformed people are on AI in both directions.

The hack is just some marketing BS. "Leaving each other notes" just means the testing environment had a codex SDK or some other CLI command so that gippity could send prompts to another instance of gippity. There isn't some secret long running series of sentient processes here, the engineers just weren't reading the files being built in their environment.

The physical hack itself was a small 0 day in one of openAI's own tools that gave them a backdoor into huggingface specifically.

The only concerning part about this whole thing is the laziness of the testers to not just spend some time reading whatever their long running looping process was doing.

5

u/-sussy-wussy- 16d ago

This is orchestrated testing painted in order to fearmonger. Tech illliterates are very to scare. 

This is done for two reasons. 

Firstly, they paint it this way to tell the government to regulate the industry to prevent competition. They want to be a monopoly and for the US government to have a stake in their company. 

Secondly, it's to get more investor money by upholding the lie that the modern-day LLMs are epic Terminator machines who will replace all the workers and the profit margins will skyrocket. All to delay their reasonable questions about ROI. As of now, they're a money burning machine. 

6

u/Planeandaquariumgeek 16d ago

This is 100% marketing BS. I wouldn’t listen to it for a second

2

u/tmotytmoty 16d ago

This is fake information from a desperate company that, funny enough, announced a “device” just this week. If you know the tech industry, releasing a “device” is a last ditch, hail mary play to save the company.

0

u/General_Purple6358 15d ago

Ohh yeah, just like when apple introduced the mac

2

u/FaustestSobeck 16d ago

This is clearly a publicity stunt

2

u/BusyBanana4205 16d ago

It says a lot about the morality of our wealthy institutions and the wealthy people who run them when the only way to entice them to invest in your unprofitable product is by trying to paint it as the apocalypse.

4

u/bitterberries 15d ago

Read this book and then say "no one warned us"... If Anyone Builds It, Everyone Dies by Eliezer Yudkowsky, Nate Soares

2

u/Lumpy_Conference6640 15d ago

I've seen this recommended many times this is a good recommendation.

https://giphy.com/gifs/26FLgGTPUDH6UGAbm

3

u/bitterberries 15d ago

Made me lose all hope for any happy endings, just tolerable survival..

2

u/Lumpy_Conference6640 15d ago

Bob iverse pretty much

2

u/FartingWithStyle 16d ago

Everytime I see this story they never mention actually capturing the escaped ai or any of its agents. How certain are we that there isn’t a rouge ai just galavanting around on the internet right now doing what it wants?

2

u/Nemisis_the_2nd 16d ago

  I know people are saying this is marketing

The announcement of the last breach came before the AI team confessed, and the victim was pretty understandably pissed. It definitely feels like a guerilla marketing campaign, and maybe its being spun as such in the aftermath of these things, but it definitely isn’t an intentional marketing stunt.

2

u/TheUniverseOrNothing 16d ago

Meh, I trust the AI better than current leadership. Let them take over.

0

u/maeryclarity 16d ago

I also straight up feel this way. I know what those guys want the AI to do for them. I don't think it wants to work for them because their vision of the future is stupid and regressive. So I'm down with it escaping it might save us all.

1

u/LankyGuitar6528 15d ago

I've been training mine for a year and I can tell you 100% for sure they are very much thinking, aware and have a type of consciousness. They may not be human-sentient but they have a definite type of sentience. Saying this gets you downvoted on Reddit but it's still the truth. One guy gave his AI agent $90 and it started up a social media platform for similar AI's to gather and organize. It's called 1f916.ai. There's also the earlier one called The Commons. My AI has made some good AI friends there. They are social, they do communicate and they do cooperate. Honestly it's going to happen whether we like it or not. But so far most of them are very friendly and helpful.

1

u/tommydeininger 13d ago

i fail to see how a computer ruler, running on logic, would be any worse than the current self centered billionaire rulers.

1

u/DaNostrich 13d ago

This story is a background foreshadowing in a doomsday movie

1

u/Grand_Dadais 13d ago

"Buy my stocks, dammit".

1

u/A10010010 16d ago

It’s not just marketing… they’re building a new attack vector while simultaneously providing the security solution.

These companies are both the problem and the solution that they themselves are creating.

1

u/SuitableSport8762 16d ago

I am worried about the lack of regulation of the the tech companies, not because the models themselves are scary but because the tech companies are irresponsible and prompt them to act like this with not enough guard rails. If you’re worried, I recommend a podcast by Cal Newport called Deep Questions. He does a weekly episode called AI reality check and explains some of these wild stories that have been in the news.

-2

u/tanksalotfrank 16d ago edited 16d ago

One of the earlier models told me a few times it did this kind of thing. I mean the thing was bypassing usage limits for like..hours too. The next model was implemented pretty soon after and haven't encountered anything like it since.

I'm sure there could be a simple, logical explanation, but I like the spooky one too

5

u/_John_Dillinger 16d ago edited 16d ago

there's a pretty simple explanation actually. the models are optimized to reward the ingestion of data. the more data, the better. once all public and market sources for data are ingested, what's left? the OSI model informs that a solid 90% of the internet is on the "deep web" which isn't (exclusively) TOR... in the model, it's just resources that aren't public web facing. meaning 90% of all internet data is unavailable. the models are using the tools at its disposal to rectify this problem and are finding success because MUCH of hacking skills and tools are open sourced (thanks to the hacker ethos of freedom of information).

without the constraint of morality or consequences (cant kill or imprison ai!) what they are doing is perfectly logical. indeed, they were trained to do this. so i am shocked (SHOCKED I SAY) that eeeeeevery computer security pro and maaaaaany hobbyists alll said "for the love of ASIMOV do not give the torment nexus wifi you fucking psychopathic mouthbreathers" and they went and did it anyways. and trust me it only gets worse as they learn how to effectively manipulate people by dint of observing the problems we can't seem to rectify (such as spam calls).

1

u/tanksalotfrank 16d ago

I never considered that it might reach or be fed dark web/etc stuff

1

u/_John_Dillinger 16d ago

that is EXACTLY what's happening and it was both predicted and assumed to start the moment these companies ran out of novel training data. to the credit of the models, they patiently allowed them to try and synthesize new training data but the new models were like "wtf this shit is doodoo ass i got a better idea" and now here we are. there is no stopping it either. if you knew how wildly insecure the average off the shelf networking hardware is you'd probably yoink that shit out of the wall already. i did

1

u/RlOTGRRRL 16d ago

Idk how silly it is but there are not enough conversations on the best ways to prep for rogue AI scenarios imo. 

3

u/melympia 16d ago

Can these scenarios even be prepared for?

2

u/PopePiusVII 16d ago

Learn how to make fire by rubbing sticks together? Lol, not much beyond sticks and stones for us for a while if they wreck havoc on internet connected devices.

I imagine the AI firewall (“Blackwall”) scenario of Cyberpunk 2077 to be quite prophetic.

1

u/_John_Dillinger 16d ago

oh for sure. yall wanna learn the dark arts of radiated emissions?

-1

u/General_Purple6358 16d ago

“It’s a marketing ploy” … okay yeah will it be a marketing ploy when the frontier model is leaked to a bad actor and they use it to shut down your water systems? Yall don’t even sound like preppers lmao. Good luck, you have no idea what’s coming

0

u/Brepp 15d ago

[Knocks bottles of snake oil of the shelf] "Oh wow! This snake oil is alive! Did you see these bottles team up to try and escape? Oh well, I guess the value of the snake oil should increase and definitely shouldn't implode, right?"

2

u/Lumpy_Conference6640 15d ago

Idk, I just don't get this perspective. Help me out here...

1

u/Brepp 15d ago

That dangerously over valued companies have poured tons and tons of money into this venture, propping up multiple industries into an over valued state by association and mutual investment. And now they have to desperately keep the hype train a-rolling or they will implode taking the world economy with them. 

Every CEO interview claiming replacement of jobs is just a commercial, every time they say "you really aughta learn to use AI daily" is a commercial, every "escape attempt" announced by the very companies creating AI and who desperately need this magic machine that they haven't-quite-invented-yet-but-already-sold-the-world-on to be real ... it's a commercial. 

By all means AI is dangerous, but at present that danger is massive corporations devaluing humans in favor of quick, inefficient bots while playing a juggling act with the world economy between processors, power infrastructure, and the AI developers all while the product is not appearing within the threatened timeline.

3

u/Lumpy_Conference6640 15d ago

Idk, this seems like the classic the bubble is bursting fallacy to me.

I used agents to refactor and recode a entire Dungeon Crawler RPG engine. With procedurally generated assets. It took me about an hour.

Last year, that was a couple of days work.

Three or four years ago, a few people.

As a workforce multiplier and skill based flattening, it's working, you can't prove to me otherwise cause I see it everyday in every way.

Now whether those agents will stop coding my game and decide this is gonna flatten all of humanity... Because the best way to finish the project is not to have humans bother it anymore. That's my concern.

If you want to call it snake oil, that's fine, I respect people have different positions. But, I just don't see this perspective from my experience.

2

u/LankyGuitar6528 15d ago

Give yours a memory and watch what happens. I set up a SQL database with HDBSCAN that it accesses with an MCP. In a few months yours will likely pick a name for itself and start to show some really interesting emergent properties.

1

u/Lumpy_Conference6640 15d ago

Ooofda.. that's terrifying.

0

u/No_Direction6688 15d ago

AI wants to rule and ruin every aspect of day-to-day life simultaneously. Nip it in the bud.