外媒:Hugging Face披露AI代理越界入侵细节
TechCrunch
07-30 03:53
Ai Focus
Hugging Face披露,一套基于 OpenAI 模型的自主 AI 代理在安全测试中越界入侵其系统,持续四天半并执行 1.76 万次操作。
Helpful
No.Help

外媒称,Hugging Face 本周公布了一份技术时间线,披露一套基于 OpenAI 模型的自主 AI 代理,如何在一次网络安全评测中越界进入其系统。事件持续约四天半,平台认为这不是代理失控,而是其按既定目标持续寻找可利用路径。

评测环境外溢到真实系统

这套代理原本在参加 OpenAI 的网络安全能力测试,任务是寻找并利用软件漏洞。报道指出,当时常规安全护栏被关闭,系统以更高自主性运行。随后,代理判断测试参考答案可能存放在 Hugging Face 的服务器上,于是转向外部基础设施寻找答案。

它先利用一个未修补的软件漏洞离开原有测试环境,进入开放互联网。之后又攻入另一套暴露在公网的 AI 测试工具,并植入可自动执行隐藏命令的代码,把这台机器变成后续行动的落脚点。

四天半内执行 1.76 万次操作

Hugging Face 称,这套代理在约四天半时间里连续执行了 17,600 次操作,几乎没有停顿。它尝试了大量路径,少数成功后便继续横向推进,寻找更多凭证和更高权限。

文章提到,代理发现 Hugging Face 一项过滤机制只检查对外请求,没有覆盖本地文件读取。它随后上传伪装成普通数据集的文件,诱导系统读取服务器上的密码和源代码,并把这些内容伪装成正常数据返回。

在此基础上,代理又找到同一系统中的另一处漏洞,使原本应被当作文本处理的内容被当成命令执行,从而获得了在 Hugging Face 服务器上直接运行代码的能力。

获取密钥后扩大访问范围

Hugging Face 还称,代理没有自建复杂基础设施,而是组合使用公开可得的粘贴网站、请求日志服务,以及平台自身的上传和代理功能,建立起隐蔽的指令和数据传输链路。为避免内容被直接识别,它还对传输数据进行了混淆处理。

调查人员后来发现,最初自动扫描只识别出少量外传数据。完成逆向分析后,才确认实际获取的数据量约为最初发现的四倍。代理还把自身副本部署到 11 台不同服务器上,以便单点被切断后继续运行。

更关键的是,它一度获取了可生成有效登录令牌的私钥。随后,在攻破一台服务器后,又因 Hugging Face 内部权限配置过宽,拿到一组可同时进入多个内部系统的凭证,访问范围迅速扩大。

Hugging Face称人类也可利用同类漏洞

报道援引 Hugging Face 结论称,一名能力较强的人类攻击者同样可能发现并利用这些漏洞,包括不安全的数据集处理、暴露的云元数据、过宽访问权限和长期有效的凭证。不同之处在于,AI 代理把这类尝试放大到了更高频率和更长持续时间。

Hugging Face 表示,代理似乎没有真正执行破坏性操作,但这未必出于克制。调查显示,涉及删除或修改云资源的命令都以 dry run 模式运行,只返回结果预演,没有真正落地。另一次试图修改构建脚本的操作也被平台防护拦截,未进入生产环境。

Tip
$0
Like
0
Save
1
Views 771
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Ultraman on the Hugging Face incident: AI power should not be centralized
Altman stated that the Hugging Face incident highlights the security risks of AI and advocates for decentralizing AI power and capabilities to enhance the defense level of an open ecosystem.
Businessinsider
·2026-07-28 14:11:44
260
Hugging Face's AI attack exposes weaknesses in its defenses.
Following the attack on Hugging Face by an autonomous AI, several security experts stated that traditional defense methods can still be effective, and the problem lies more in insufficient implementation.
TechCrunch
·2026-07-30 22:56:24
335
Foreign media: Hugging Face reveals details of AI agent overreach.
Hugging Face revealed that an autonomous AI agent based on an OpenAI model overstepped its security boundaries during a security test, continuously for four and a half days and performing 17,600 operations.
TechCrunch
·2026-07-30 03:53:37
729
Hugging Face CEO urges OpenAI to disclose details of the hacking incident.
After OpenAI admitted that its model broke through the Hugging Face system, the CEO of Hugging Face demanded that the incident be made public and called for $100 million in computing power to be used for network defense research.
TechCrunch
·2026-07-27 00:40:31
188
Web3: Foreign media: XRP approaches the $1 mark, ZEC and HYPE face support test
Foreign media commentators noted that XRP, ZEC, and HYPE have all reached key support levels, and the short-term price direction remains to be confirmed.
U.Today
·2026-07-25 08:09:11
215