OpenAI has confirmed that state-affiliated bad actors are using the company's tech for malicious purposes, a validation of what many have feared since the company's rise to prominence in the generative AI race.
The discovery comes as part of a collaboration with Microsoft Threat Intelligence, a community of thousands of security experts, researchers, and threat hunters that analyze and detect cyber threats.
Using the network's intelligence gathering, OpenAI discovered at least five confirmed state-affiliated actors that were using OpenAI services for querying open-source information, translating, finding coding errors, and running basic coding tasks, the company explained. The actors included two China-affiliated actors known as Charcoal Typhoon and Salmon Typhoon; an Iran-affiliated actor known as Crimson Sandstorm; a North Korea-affiliated actor known as Emerald Sleet; and a Russia-affiliated actor known as Forest Blizzard.
SEE ALSO: Encryption backdoors violate human rights, EU court rulesThe accounts were said to be relying on OpenAI's services to bolster potential cyber attacks, but Microsoft did not detect any significant uses of the most-highly monitored LLMs.
"These include reconnaissance, such as learning about potential victims’ industries, locations, and relationships; help with coding, including improving things like software scripts and malware development; and assistance with learning and using native languages," Microsoft explained. "Language support is a natural feature of LLMs and is attractive for threat actors with continuous focus on social engineering and other techniques relying on false, deceptive communications tailored to their targets’ jobs, professional networks, and other relationships."
Microsoft distinguished this announcement as an early-detection effort, intended to expose "early-stage, incremental moves that we observe well-known threat actors attempting."
The collaboration aligns with recent moves from the White House to require safety testing and government supervision for AI systems that could impacts national and economic security, public health, and general safety. "While attackers will remain interested in AI and probe technologies’ current capabilities and security controls, it’s important to keep these risks in context. As always, hygiene practices such as multifactor authentication (MFA) and Zero Trustdefenses are essential because attackers may use AI-based tools to improve their existing cyberattacks that rely on social engineering and finding unsecured devices and accounts."
While OpenAI admits that its current models are limited in their ability to detect cyber attacks, the company committed to future security investments, including:
Investments in technology and teams, including its Intelligence and Investigations and Safety, Security, and Integrity teams, to detect threats.
Collaborations with industry partners and other stakeholders to exchange information about malicious uses.
Continued public reporting of security threats and solutions.
"Although we work to minimize potential misuse by such actors, we will not be able to stop every instance," OpenAI wrote. "But by continuing to innovate, investigate, collaborate, and share, we make it harder for malicious actors to remain undetected across the digital ecosystem and improve the experience for everyone else."
文章
148
浏览
3
获赞
2498
Apple wins $15 billion court battle with EU over Irish tax
After a long string of fines and legal setbacks in the EU, Apple can now chalk up one big win next tDoublepoint's Wow Mouse is gesture tech on steroids
When Apple presented the Double Tap feature on the Apple Watch last year during the Apple Event, itLiam Hemsworth makes an adorably awkward appearance in the Cyrus Christmas photo
Is it really even a Christmas gathering without an awkward family photo? Liam Hemsworth and Miley CyTime names Trump person of the year and Twitter has a lot to say
No matter how hard you try to ignore Donald Trump, he just won't go away.On Wednesday, Time magazineBear breaks into a house and escapes 'like the Kool
Bears are a lot like the Kool-Aid Man, and no you cannot change my mind. Allow me to explain: Both aThe Sphere during CES 2024: Android vs. iPhone
The Sphere caught many CES 2024 attendees' eyes as it glittered in the Las Vegas night like a shinyHow to unblock RedTube for free
TL;DR:ExpressVPN is the best service for bypassing online restrictions. Unblock RedTube from anywherJerks stole photos from Maisie Williams' private Facebook account
Once again, an actress' personal photos never intended for public consumption have made the rounds oGoogle rebrands G Suite as Google Workspace, gives Gmail a new logo
Google is once again reshuffling its portfolio of productivity apps.On Tuesday, the company announce25 feminist gifts for the nasty woman in your life
A nasty woman might not be president-elect, but that doesn't mean the nasty women (and other nasty hThe year according to Airbnb
It was a combative year for Airbnb, and the controversial home-sharing company is ready to move on tCES 2024: I got to try Ambarella's self
Guys, self-driving cars are so hotright now. At CES 2024, one of the emerging trends of this year'sFox News attacks George Kent for... drinking water at the impeachment hearing
Diplomat George Kent brought a large Nalgene bottle to Wednesday's impeachment hearing. What's more,U.S. author tweets that London is 'all Islamic', gets immediately shut down
LONDON -- As we learned from Donald Trump's replies that time he tweeted about Brexit, British peoplCES 2024: I got to try Ambarella's self
Guys, self-driving cars are so hotright now. At CES 2024, one of the emerging trends of this year's