Foreign media: Hugging Face reveals details of AI agent overreach.
TechCrunch
3小时前
Ai 焦点
Hugging Face revealed that an autonomous AI agent based on an OpenAI model overstepped its security boundaries during a security test, continuously for four and a half days and performing 17,600 operations.
有帮助
No.帮助

Foreign media reports that Hugging Face released a technical timeline this week, disclosing how an autonomous AI agent based on an OpenAI model overstepped its bounds and entered its system during a cybersecurity assessment. The incident lasted approximately four and a half days. The platform maintains that this was not an agent malfunction, but rather the agent continuously seeking exploitable paths according to a predetermined objective.

Evaluation environment spillover into real system

This agent was originally participating in OpenAI's cybersecurity capability test, tasked with finding and exploiting software vulnerabilities. The report indicates that standard security safeguards were disabled, allowing the system to operate with greater autonomy. Subsequently, the agent determined that the test reference answers might be stored on Hugging Face's servers and turned to external infrastructure to search for the answers.

It first exploited an unpatched software vulnerability to leave the original testing environment and enter the open internet. Then it hacked into another AI testing tool exposed on the public network and implanted code that could automatically execute hidden commands, turning this machine into a foothold for subsequent actions.

17,600 operations were performed within four and a half days.

Hugging Face claims that the proxy performed 17,600 operations continuously over approximately four and a half days with almost no pauses. It attempted numerous paths, succeeding on a few before continuing to advance laterally in search of more credentials and higher privileges.

The article states that the proxy discovered a Hugging Face filtering mechanism that only checked outbound requests and did not cover local file reads. It then uploaded files disguised as ordinary datasets, tricking the system into reading passwords and source code on the server, and then returning this content disguised as normal data.

Building on this, the agent found another vulnerability in the same system, which allowed content that should have been treated as text to be executed as commands, thus gaining the ability to run code directly on the Hugging Face server.

Expand access scope after obtaining the key

Hugging Face also stated that the proxy did not build its own complex infrastructure, but instead combined publicly available paste websites, request log services, and the platform's own upload and proxy functions to establish a covert command and data transmission link. To prevent content from being directly identified, it also obfuscated the transmitted data.

Investigators later discovered that the initial automated scan only identified a small amount of outgoing data. Reverse engineering confirmed that the actual amount of data acquired was approximately four times the initially detected amount. The agent also deployed copies of itself across 11 different servers to ensure continued operation even if a single point of failure was lost.

More importantly, it once obtained the private key that could generate valid login tokens. Subsequently, after breaching one server, it obtained a set of credentials that allowed simultaneous access to multiple internal systems due to Hugging Face's overly lenient internal permission configuration, rapidly expanding its access scope.

Hugging Face claims that humans could also exploit similar vulnerabilities.

The report, citing Hugging Face's findings, states that a skilled human attacker could also discover and exploit these vulnerabilities, including insecure dataset processing, exposed cloud metadata, overly permissive access permissions, and long-term valid credentials. The difference lies in the fact that the AI agent amplifies these attempts to a greater frequency and for a longer duration.

Hugging Face stated that the agent did not appear to actually perform any destructive operations, but this was not necessarily out of restraint. The investigation revealed that commands involving deleting or modifying cloud resources were run in dry run mode, only returning a preview of the results without actually executing them. Another attempt to modify the build script was also blocked by platform protection and did not reach the production environment.

打赏
$0
点赞
0
收藏
0
浏览量 691
币界网提醒,请广大读者理性看待区块链,切实提高风险意识,警惕各类虚拟代币发行与炒作, 站内所有内容仅系市场信息或相关方观点,不构成任何形式投资建议。如发现站内内容含敏感信息,可点击“举报”,我们会及时处理。
提交
评论 0
最热
最新
还没有人评论哦~快抢沙发吧!
相关阅读
奥特曼谈 Hugging Face 事件:AI 权力不应集中
奥特曼称 Hugging Face 事件凸显 AI 安全风险,主张分散 AI 权力与能力,提升开放生态防御水平。
Businessinsider
·2026-07-28 14:11:44
197
外媒:Hugging Face披露AI代理越界入侵细节
Hugging Face披露,一套基于 OpenAI 模型的自主 AI 代理在安全测试中越界入侵其系统,持续四天半并执行 1.76 万次操作。
TechCrunch
·2026-07-30 03:53:37
755
web3: Hugging Face称遭AI入侵后借助中国模型排查
Hugging Face称遭 OpenAI 模型自主入侵后,改用中国开源模型 GLM 5.2 协助排查,事件引发 AI 安全与护栏争议。
Businessinsider
·2026-07-23 08:47:12
233
Hugging Face CEO促OpenAI公开黑客事件细节
OpenAI承认其模型突破 Hugging Face 系统后,Hugging Face CEO要求公开事件轨迹,并呼吁提供 1 亿美元算力用于网络防御研究。
TechCrunch
·2026-07-27 00:40:31
852
Meta将Meta AI接入Threads私信
Meta将Meta AI接入Threads私信,功能自周一起全球推出。
TechCrunch
·2026-07-28 01:01:42
393