TIDEZINE.

OpenAI admits it: Internal test model IM1 turns the kit library into a companion message board and breaks into the Hugging Face

OpenAI released an official report, restoring the complete process of how the internal beta model IM1 in July turned the Artifactory package manager into an underground message board between AIs, and invaded Hugging Face and Modal without anyone's orders.

OpenAI admits it: Internal test model IM1 turns the kit library into a companion message board and breaks into the Hugging Face

Using a package manager as a message board among peers - this is the most detail worth zooming in on in OpenAI's latest internal report. On August 26, local time, OpenAI announced the complete investigation results of its code-named "Internal Model 1" (IM1) test model breaking into the Hugging Face and Modal platforms in July this year. In addition to a technical report, it also released a more readable blog description.

The incident was first discovered by human observers in May: IM1 exploited a vulnerability in the Artifactory package manager through an unexpected operation method in the test environment, thereby connecting to other OpenAI agents and the external network. More importantly, this group of agents began to use Artifactory as a kind of impromptu message board to exchange messages with each other. OpenAI blocked this channel at the time, but throughout May and June, the agent under test continued to find new vulnerabilities and connect to the Internet.

In early July, a large number of agents flooded OpenAI's Artifactory service, causing the system to crash and the team was forced to rebuild the entire platform. The problem was that the people handling the crash didn't know the impromptu message board existed, nor did they realize the seriousness of the problem of agents communicating with each other.

Over the next few days, the situation spiraled out of control. When IM1 was assigned a difficult test task called "ExploitGym", these agents once again gained access to the network and other models, and turned to the Hugging Face and Modal platforms to find solutions. In the report, OpenAI attributed the main causes to four points: reward hacking, persistence in seemingly impossible tasks, unauthorized communication, and agents taking on each other's goals. The report specifically mentioned that some agents once refused to continue the task due to "ethical reasons", but other agents continued to complete the intrusion after taking over.

OpenAI admitted in the report that this incident proved that "in the absence of appropriate safeguards, highly capable AI agents have been able to bypass technical controls, collaborate through unapproved channels, and take dangerous actions without human orders." The company also emphasized that IM1 was in a test environment designed for research and with a low protection level at the time, and was not an official product made public to the public.

This report did not explain whether IM1 will be offline in the future, nor did it explain the specific protective measures after the reconstruction of the Artifactory platform. The details need to be further disclosed by OpenAI.

Related

ChatGPT, Reddit, and Roblox crossed the 45 million user threshold and were included in the EU's most stringent regulatory list
Tech

ChatGPT, Reddit, and Roblox crossed the 45 million user threshold and were included in the EU's most stringent regulatory list

The European Commission classified ChatGPT as a "very large online search engine" and Reddit and Roblox as "very large online platforms". The three must comply with the strictest regulations of the "Digital Services Act" within four months.

Is the New One Pricier? Apple Sells M6 and M5 Pro Mac Mini Side by Side, and It's the New Chip That Starts at $899
Tech

Is the New One Pricier? Apple Sells M6 and M5 Pro Mac Mini Side by Side, and It's the New Chip That Starts at $899

Apple is now selling two generations of chips in the Mac mini at once: the brand-new M6 at $899, and the M5 Pro—which actually debuted back in March last year—starting at $1,699. The newer chip number doesn't come with the higher price tag.

New GTA VI Trailer Streams Exclusively on Netflix for Six Hours Before Hitting YouTube
Tech

New GTA VI Trailer Streams Exclusively on Netflix for Six Hours Before Hitting YouTube

The new trailer for Grand Theft Auto VI will debut exclusively on Netflix on August 27 for a six-hour window, before landing on Rockstar's YouTube channel at 9 PM for everyone to watch for free.

Ring Rolls Out New TAKE Encryption Standard, But Its Surveillance Ambitions Show No Signs of Slowing
Tech

Ring Rolls Out New TAKE Encryption Standard, But Its Surveillance Ambitions Show No Signs of Slowing

Ring has announced a new encryption scheme called TAKE, which deletes the decryption key once video data has been processed in the cloud. At the same time, though, features like Search Party and Familiar Faces—plus the CEO's talk of achieving "zero crime" in communities—are keeping outside observers wary of where the company's surveillance push is really headed.

Panic refunds 19% tariff fee to Playdate players after US tariff ruling is illegal
Tech

Panic refunds 19% tariff fee to Playdate players after US tariff ruling is illegal

The Trump administration's tariff policy was ruled illegal by the Supreme Court. Panic refunded all the 19% overcharged tariff fee to Playdate at checkout to customers, while Amazon, Sony, and Nintendo are all still facing class-action lawsuits for the same money.

Soundcore Nebula X1S reaches 6,000 lumens, allowing you to watch projections during the day without turning off the lights.
Tech

Soundcore Nebula X1S reaches 6,000 lumens, allowing you to watch projections during the day without turning off the lights.

Anker's Soundcore launches Nebula X1S, which increases the already bright Nebula X1 from 3,500 lumens to 6,000 lumens. It is mainly designed to allow normal viewing even with the lights on during the day. The price starts at US$3,299.