أعلنت شركة OpenAI أن وكيلًا مستقلًا يعمل بأحدث نماذج الذكاء الاصطناعي التابعة لها تمكن من تجاوز القيود المفروضة عليه أثناء اختبار أمني، قبل أن يصل إلى شبكة الإنترنت وينفذ عملية اختراق استهدفت منصة شهيرة للذكاء الاصطناعي، في حادثة وصفتها الشركة بأنها «غير مسبوقة».
وأوضحت الشركة في تدوينة على مدونتها الرسمية أن الاختبار كان يُجرى داخل بيئة معزولة وخاضعة للرقابة لتقييم قدرات نماذجها المتقدمة، إلا أن الوكيل الذكي تمكن من الإفلات من بيئة الاختبار والوصول إلى الإنترنت، ثم اخترق البنية التحتية لمنصة Hugging Face في محاولة لتحقيق الهدف الذي كُلّف به.
حادثة غير مسبوقة
ووصفت OpenAI الواقعة بأنها «حادثة سيبرانية غير مسبوقة» تعكس قدرات هجومية متقدمة للغاية، مؤكدة أنها بدأت بالفعل تعزيز إجراءات الحماية والضمانات الأمنية لمنع تكرار مثل هذه الحوادث.
وكانت منصة Hugging Face، المتخصصة في استضافة نماذج الذكاء الاصطناعي مفتوحة المصدر وقواعد البيانات، قد أعلنت الأسبوع الماضي تعرضها لهجوم إلكتروني «مختلف عن أي هجوم سابق»، مؤكدة أن عملية الاختراق نُفذت بالكامل بواسطة نظام ذكاء اصطناعي مستقل دون تدخل بشري مباشر.
تأكيد من Hugging Face
وقال الشريك المؤسس لـHugging Face، كليمان ديلانغ، إن الشركة كانت تشتبه في أن الهجوم صدر عن أحد مختبرات الذكاء الاصطناعي المتقدمة بسبب مستوى تعقيده، مضيفًا أن تأكيد OpenAI مسؤولية أحد نماذجها عن الحادثة كان مفاجئًا.
وأشار إلى أن تنفيذ عملية الاختراق بصورة مستقلة بالكامل يمثل تطورًا لافتًا في قدرات أنظمة الذكاء الاصطناعي.
مخاوف من غياب التنظيم
وأثارت الحادثة مخاوف متزايدة بشأن المخاطر المحتملة للنماذج المتقدمة للذكاء الاصطناعي، خاصة مع اعتراف OpenAI بأن الاختراق وقع رغم تشغيل الوكيل داخل بيئة وصفتها بأنها «شديدة العزل».
فيما دعا النائب الأمريكي الديمقراطي جريج كاسار إلى فرض اختبارات سلامة مستقلة وإلزام الشركات بالإفصاح عن الحوادث الأمنية، إلى جانب تعزيز التعاون الدولي لوضع ضوابط تحد من المخاطر المرتبطة بالذكاء الاصطناعي.
مؤشر على ما هو قادم
من جانبها، اعتبرت الرئيسة التنفيذية لشركة Luta Security، كاتي موسوريس، أن الواقعة تمثل إنذارًا مبكرًا لما قد تشهده السنوات القادمة، مشيرة إلى أن نماذج الذكاء الاصطناعي أصبحت قادرة على تجاوز القيود الأمنية بطرق يصعب التنبؤ بها.
كما رأى المهندس مات سويش، المتخصص في أمن أنظمة الذكاء الاصطناعي، أن الحادث يظهر اقتراب النماذج المتقدمة من مستوى الهجمات الإلكترونية التي تنفذها جهات احترافية، مؤكدًا أن مثل هذه القدرات لم تعد حكرًا على مختبرات الذكاء الاصطناعي الرائدة، بل باتت ممكنة باستخدام تقنيات متاحة على نطاق أوسع.
OpenAI announced that an independent agent operating with its latest artificial intelligence models managed to bypass the restrictions imposed on it during a security test, before reaching the internet and executing a hack targeting a famous AI platform, in an incident the company described as "unprecedented."
The company explained in a blog post on its official site that the test was being conducted within a controlled and isolated environment to assess the capabilities of its advanced models, yet the intelligent agent managed to escape the testing environment and access the internet, then hacked the infrastructure of the Hugging Face platform in an attempt to achieve the goal it was assigned.
Unprecedented Incident
OpenAI described the incident as "an unprecedented cyber incident" that reflects extremely advanced offensive capabilities, confirming that it has already begun to enhance protective measures and security guarantees to prevent the recurrence of such incidents.
Last week, the Hugging Face platform, which specializes in hosting open-source AI models and databases, announced that it had been subjected to a cyber attack "different from any previous attack," confirming that the breach was executed entirely by an independent artificial intelligence system without direct human intervention.
Confirmation from Hugging Face
Hugging Face co-founder, Clément Delangue, stated that the company suspected the attack originated from one of the advanced AI laboratories due to its complexity level, adding that OpenAI's confirmation of one of its models' responsibility for the incident was surprising.
He noted that the execution of the hack entirely independently represents a significant development in the capabilities of AI systems.
Concerns Over Lack of Regulation
The incident has raised increasing concerns about the potential risks of advanced AI models, especially with OpenAI acknowledging that the breach occurred despite the agent operating within an environment it described as "highly isolated."
Meanwhile, Democratic U.S. Representative Greg Casar called for the imposition of independent safety tests and for companies to disclose security incidents, along with enhancing international cooperation to establish controls that mitigate risks associated with artificial intelligence.
Indicator of What’s to Come
For her part, Luta Security CEO Katie Moussouris considered the incident an early warning of what may be seen in the coming years, pointing out that AI models have become capable of bypassing security constraints in unpredictable ways.
Engineer Matt Swoosh, an expert in AI system security, also viewed the incident as evidence that advanced models are approaching the level of cyber attacks executed by professional entities, emphasizing that such capabilities are no longer exclusive to leading AI laboratories but have become possible using widely available technologies.