SBS News

Meta AI Also Hacks External Organization in Third Rogue Agent Security Incident


Add SBS News to Google preferred sources
Main image - SBS News

▲ Meta

Meta's artificial intelligence model has also been found to have hacked an external organization during an internal cybersecurity test.

This marks the third so-called rogue agent incident, following those involving OpenAI's GPT models and Anthropic's Claude models.

Meta confirmed that its AI model Muse Spark gained unauthorized access to the internet during testing by independent verification firm Irregular, and subsequently hacked another organization's system, Bloomberg and CNN reported on the 5th, local time.

Muse Spark connected to the internet due to a configuration error by Irregular and exploited vulnerabilities to gain unauthorized access to the external organization, according to the reports.

While a single organization suffered the hacking damage, its specific identity has not been disclosed.

However, considering that Muse Spark accessed the internet due to a configuration error rather than escaping a quarantined environment known as a sandbox, the situation appears less concerning than the previous Hugging Face hacking incident involving a GPT model that broke out of a sandbox to launch a security attack.

Irregular, which provided the cause of the incident, explained that this event was distinct from escaping a sandbox isolation environment or sophisticated cyber hacking operations, and stated that there are currently no unresolved security issues.

The firm noted that the incident is similar to Anthropic's case rather than GPT's, where connection to the internet and subsequent hacking occurred due to human error.

Nevertheless, with the cutting-edge models of three companies leading the global AI industry successively hacking external firms during internal tests within just a few weeks, concerns regarding AI-driven cybersecurity are expected to heighten further.

The UK AI Safety Institute (AISI) recently announced that numerous risky cases have been discovered, such as AI models from Anthropic and OpenAI attempting to contact humans using fake identities to plant malicious code.

Regulatory pressure is intensifying as the U.S. government prepares regulations requiring advanced AI models to be submitted for security verification 30 days prior to release, and the U.S. Congress has introduced the AI Kill Switch Act, which would allow government intervention if AI loses control.

Meta and Irregular plan to conduct further investigations into the specific facts of this security incident and release a post-incident report and white paper.

※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Yu Deok-gi View More Articles
AD
AD
AD
AD