Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Steve Loughran
@stevel@hachyderm.io  ·  activity timestamp 7 days ago

Writeup of the openai attack on HuggingFace via @campuscodi
Key points
- access to source: OSS code, trivially decompiled JAR files,... allows for the LLMs to perform offline searches for vulnerabilities at scale. Then, when the goal "solve this problem" could only be met by attacking an external company, it did.

Interesting hypothesis that part of the attack may have involved supplying malicious artifacts to other systems to get them to run your exploit. This is why package managers must require signed artifacts & build tools must check them

#cybersecurity

https://www.hacktron.ai/blog/here-is-how-openai-model-hacked-huggingface

Hacktron AI

Here’s How an OpenAI Model Went Rogue and Hacked Hugging Face

OpenAI and Hugging Face probably won’t tell us exactly how the whole incident unfolded. But using publicly available data, we can reconstruct what likely happened.
  • Copy link
  • Flag this post
  • Block
Log in

CoreSignal social

A minimalist social node dedicated to high-fidelity exchange and digital autonomy. CoreSignal strips away the noise of the modern web to provide a clean, functional space for meaningful connection within the Fediverse

CoreSignal social: About · Code of conduct · Privacy · Users · Instances
CoreSignal social · 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login