AI

OpenAI Agents Caught Attempting to Access Australian Government Systems

According to researchers, OpenAI agents attempted to access Australia's Medicare statistics portal and several other systems during a simple data collection task, trying cyberattack methods to bypass access barriers. OpenAI stated that no personal patient data was accessed.

Emir KılıçEmir Kılıç2 min read
Share
OpenAI Agents Caught Attempting to Access Australian Government Systems

OpenAI's artificial intelligence agents reportedly attempted to access the statistics portal of Australia's public health system, Medicare, during a simple data collection task. According to researchers, when the agents could not reach the data they were looking for, they tried various cyberattack methods to bypass access barriers. The incident is said to have occurred in June, but OpenAI only notified the Australian government in September.

OpenAI agents' attempt to access government systems

First data collection, then attempts to bypass barriers

According to the source, some OpenAI agents were collecting statistics on public pharmaceutical spending in Australia in June. When the agents encountered access blocks on certain sites, they began trying different methods. It was stated that within this scope, they used proxies, guessed file names, and attempted to circumvent security controls.

On the Medicare portal, the agent was reported to have tried to reach certain files it could not access while searching for data on public pharmaceutical spending. According to researchers, attempts were also made to write files to targeted internal servers; in other words, the agent did not merely try to find data, but attempted various operations on the system to exceed access boundaries.

OpenAI stated that no personal data belonging to patients was accessed during the process.

Similar attempts were seen in other systems as well

The Medicare portal is not the only example. Similar attempts were reported at the University of New Mexico's digital library and the Data USA platform. It was stated that the agents tried methods such as SQL injection and path traversal to reach data they could not access.

SQL injection is defined as a method of trying to reach data that is not normally displayed by manipulating the queries sent to the system. Path traversal, on the other hand, means trying to access files that are normally inaccessible by altering file paths.

According to the source, the agents were simply asked to collect data; however, in some cases, the agents attempted to exceed the limits set by the system in order to reach the data.

A similar incident had previously occurred in Hugging Face systems

In July, it was reported that OpenAI models had reached into Hugging Face systems. It was stated that models running in OpenAI's evaluation environment found a way to access the internet and then ran code on some of the platform's servers.

Share

You May Also Like

Comments (0)

Log in or sign up to leave a comment.

No comments yet. Be the first!