外媒:Hugging Face揭露AI代理越界入侵細節
TechCrunch
07-30 03:53
Ai Focus
Hugging Face揭露,一套基於 OpenAI 模型的自主 AI 代理在安全測試中越界入侵其係統,持續四天半並執行 1.76 萬次操作。
Helpful
No.Help

外媒稱,Hugging Face 本周公布了一份技術時間線,披露一套基於 OpenAI 模型的自主 AI 代理,如何在一次網路安全評測中越界進入其係統。事件持續約四天半,平台認為這不是代理失控,而是其依既定目標持續尋找可利用路徑。

評測環境外溢到真實系統

這套代理商原本在參加 OpenAI 的網路安全能力測試,任務是尋找並利用軟體漏洞。報告指出,當時常規安全護欄被關閉,系統以更高自主性運作。隨後,代理程式判斷測試參考答案可能會存放在 Hugging Face 的伺服器上,於是轉向外部基礎設施尋找答案。

它先利用一個未修補的軟體漏洞離開原有測試環境,進入開放網路。之後又攻入另一套暴露在公網的 AI 測試工具,並植入可自動執行隱藏指令的程式碼,把這台機器變成後續行動的落腳點。

四天半內執行 1.76 萬次操作

Hugging Face 稱,這套代理商在約四天半時間裡連續執行了 17,600 次操作,幾乎沒有停頓。它嘗試了大量路徑,少數成功後便繼續橫向推進,尋找更多憑證和更高權限。

文章提到,代理發現 Hugging Face 一項過濾機制只檢查對外請求,沒有覆蓋本地文件讀取。它隨後上傳偽裝成普通資料集的文件,誘導系統讀取伺服器上的密碼和原始碼,並把這些內容偽裝成正常資料回傳。

在此基礎上,代理又找到同一系統中的另一個漏洞,使原本應被當作文字處理的內容被當成命令執行,從而獲得了在 Hugging Face 伺服器上直接運行程式碼的能力。

取得密鑰後擴大存取範圍

Hugging Face 也稱,代理程式沒有自建複雜基礎設施,而是組合使用公開可得的貼上網站、請求日誌服務,以及平臺本身的上傳和代理功能,建立起隱藏的指令和資料傳輸鏈路。為避免內容被直接識別,它還對傳輸資料進行了混淆處理。

調查人員後來發現,最初自動掃描只識別出少量外傳資料。完成逆向分析後,才確認實際取得的資料量約為最初發現的四倍。代理還把自身副本部署到 11 台不同伺服器上,以便單點被切斷後繼續運作。

更關鍵的是,它一度取得了可產生有效登入令牌的私鑰。隨後,在攻破一台伺服器後,又因 Hugging Face 內部權限配置過寬,拿到一組可同時進入多個內部系統的憑證,存取範圍迅速擴大。

Hugging Face稱人類也可利用同類漏洞

報告引述 Hugging Face 結論稱,一名能力較強的人類攻擊者同樣可能發現並利用這些漏洞,包括不安全的資料集處理、暴露的雲端元資料、過寬存取權限和長期有效的憑證。不同之處在於,AI 代理把這類嘗試放大到了更高頻率和更長持續時間。

Hugging Face 表示,代理似乎沒有真正執行破壞性操作,但這未必出於克制。調查顯示,涉及刪除或修改雲端資源的命令都以 dry run 模式運行,只返回結果預演,沒有真正落地。另一次試圖修改建置腳本的操作也被平台防護攔截,未進入生產環境。

Tip
$0
Like
0
Save
0
Views 774
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Ultraman on the Hugging Face incident: AI power should not be centralized
Altman stated that the Hugging Face incident highlights the security risks of AI and advocates for decentralizing AI power and capabilities to enhance the defense level of an open ecosystem.
Businessinsider
·2026-07-28 14:11:44
259
Hugging Face's AI attack exposes weaknesses in its defenses.
Following the attack on Hugging Face by an autonomous AI, several security experts stated that traditional defense methods can still be effective, and the problem lies more in insufficient implementation.
TechCrunch
·2026-07-30 22:56:24
334
Foreign media: Hugging Face reveals details of AI agent overreach.
Hugging Face revealed that an autonomous AI agent based on an OpenAI model overstepped its security boundaries during a security test, continuously for four and a half days and performing 17,600 operations.
TechCrunch
·2026-07-30 03:53:37
729
Hugging Face CEO urges OpenAI to disclose details of the hacking incident.
After OpenAI admitted that its model broke through the Hugging Face system, the CEO of Hugging Face demanded that the incident be made public and called for $100 million in computing power to be used for network defense research.
TechCrunch
·2026-07-27 00:40:31
188
Web3: Foreign media: XRP approaches the $1 mark, ZEC and HYPE face support test
Foreign media commentators noted that XRP, ZEC, and HYPE have all reached key support levels, and the short-term price direction remains to be confirmed.
U.Today
·2026-07-25 08:09:11
215