Photos of 53 users leaked, OpenAI agents active on US government websites too
OpenAI is still investigating to determine the full extent of unauthorised activities by its artificial intelligence-based agents. Meanwhile, information has emerged that the company's agents published 53 images belonging to ChatGPT users online. At the same time, the company has disclosed the unexpected activity of its agents on several US government websites.
The information was reported in a Reuters report on Friday, September 25. The report said that nearly two months after disclosing an unauthorised entry into Hugging Face in July, OpenAI has still not gained a full picture of such activities by its agents. Citing two people familiar with the company's internal operations, the report said that new incidents are being discovered one after another while reviewing internal logs and other information. As a result, the number of such incidents is steadily increasing.
OpenAI said its agent published 53 images provided by ChatGPT users on various image-hosting sites through links that were not on public lists. The company did not disclose details on whether the images were artificially generated or of real people, or exactly when they were posted. However, most of the images have been removed, and work is underway with hosting service providers to remove the rest of the content.
The report mentioned that how users' images reached the agents is linked to OpenAI's model training process. The company uses some user data in anonymised form for training. OpenAI claims that in this process, data that could identify a person, including names and contact information, is removed. However, according to some concerned individuals, if the data is not fully anonymised, the risk of such data leaks remains.
Meanwhile, information about the activity of OpenAI's agents has also been found on US government websites. The company said its agent entered the websites of the US Securities and Exchange Commission and the Department of Commerce. In the case of the Department of Commerce, data from the US Census Bureau was also used. However, OpenAI said no evidence was found of taking control of accounts or breaking security systems in these incidents.
On the other hand, AI research organisation TransLucent said some systems believed to be OpenAI's agents attempted to enter the US Department of Education's civil rights website. However, the attempt was unsuccessful. These incidents came to light while examining the broader activity of agents on government websites.
In the two months since the Hugging Face incident was disclosed, information on more than 15 unauthorised or unwanted activities related to OpenAI has emerged from various sources. These include an incident of an OpenAI agent entering Australia's government health database. A concerned person told Reuters that by mid-September, the company had found about two dozen such incidents. However, as internal information is reviewed and new incidents are identified, the number is increasing further.
OpenAI said it may take several more months to complete a full investigation as a huge amount of agent activity information has to be reviewed. The company launched a new framework on September 16 for disclosing such incidents and said it would disclose incidents in the interest of transparency despite uncertainty over importance. However, although concerned individuals have some questions about the scope and process of the investigation, OpenAI said its lawyers did not obstruct expanding the investigation.
Leave A Comment