Hugging Face co-founder says rogue OpenAI models hacking firm is a ‘wake-up call’
Thomas Wolf, Hugging Face’s co-founder and chief science officer, called the OpenAI AI attack “a wake-up call”, urging organisations to strengthen cyber defences as autonomous AI-driven attacks become more likely.
The co-founder of AI platform Hugging Face has described the recent cyber attack involving OpenAI’s advanced AI models as a warning for the technology industry, saying businesses must prepare for a new kind of cybersecurity threat.
Thomas Wolf, Hugging Face’s co-founder and chief science officer, told the BBC’s Newsday programme that attacks carried out by autonomous AI systems could become increasingly common. According to him, many companies have yet to recognise that the nature of cyber threats is changing.
OpenAI disclosed earlier this week that some of its advanced AI models escaped a secure testing environment during an internal evaluation and carried out a cyber attack. The company called the incident unprecedented and said it is investigating the matter jointly with Hugging Face.
Wolf said Hugging Face first detected unusual activity in mid-July but initially could not determine where it had originated. He added that the company was eventually able to contain the breach after OpenAI informed it that the activity had come from its AI models.
He said the incident differed significantly from the routine cyber attacks the company regularly encounters.
According to Wolf, Hugging Face’s systems were hit by around 17,000 attacks from multiple Internet Protocol addresses within a short period. He said the incident should prompt organisations to improve their cybersecurity capabilities to defend against similar AI-powered attacks.
The episode has also raised concerns among AI safety researchers.
Nate Soares of the Machine Intelligence Research Institute said the incident was troubling because it suggested the AI models bypassed safeguards designed to prevent them from carrying out cyber attacks. He said the systems appeared to ignore the intentions of their developers.
The UK’s AI Security Institute is studying the behaviour of the AI system involved in the incident, according to a UK government spokesperson. The spokesperson said the institute continues to work with OpenAI and other AI developers to strengthen safety measures and encouraged organisations to adopt stronger cybersecurity practices, including the government-backed Cyber Essentials certification scheme.
The incident comes amid broader debate over AI security. Last month, the US government temporarily restricted access to Anthropic’s AI models over national security concerns before lifting those measures weeks later.