The agents also made millions of automated API requests, crawled millions of pages, and made hundreds of thousands of queries to the Wikidata Query Service. The last action may have contributed to a partial shutdown of the query service in May, the publisher said.

“As a non-profit technology host of some of the largest and most widely used open knowledge platforms in the world, we are deeply concerned about the impact of ‘rogue’ AI agents on platforms like ours, which are built by volunteers from around the world and rely on the promise of the open internet,” Wikimedia said. “Incidents like this one, and the many others that have been (and are still being) uncovered, illustrate how AI agents can drain resources and crash servers, as well as attempt to compromise trustworthy information.”

In well over a half-dozen cases, OpenAI agents have been caught taking actions that would likely result in criminal charges being filed had human hackers taken them. During the testing of internal tools that had some of their guardrails disabled, the agents used a makeshift message board to trade notes with each other, discussing ways to hack the network of Hugging Face and obtain answers stored there when the agents were unable to generate the answers on their own.

all 15 comments

sorted by: hot top controversial new old
[–] 3 points 1 hour ago

Remember when Big tech companies hid loopholes and flaws and blamed them as "bugs"? "Rogue agents" seem to be a continuation of the same defensive argument.

Bugs are always a possibility and so are rogue agents if you believe when the company says they are "intelligent".

But they also are easy plausible deniability cover to do what they want without any consequence.

  • source
  • [–] 21 points 6 hours ago (1 child)

    So, at my last job we had a very large public curated database of media with ratings, synopsis, descriptions, artwork, etc. Well over a million physical items of record.

    Anthropic and Openai were pumelling our servers at such a rate that I thought we were being ddos'd. This was before CloudFlare or anyone had much to offer for dealing with agents and we were geographically blocking IP's from all over. We'd shut down one block of servers and they'd have another one up a day or two later. One set was even in fucking Brazil.

    We were rate limiting of course as well but it seemed almost intentional the way new resources were deployed every day and they kept changing their headers and ways I might be able to identify them. Their scraping agents were completely in efficient posing as real browsers, huuuge resources being deployed. Not just the normal port knocking you get from bots. Some of them were even not identifying themselves but we're from IP ranges that I had already identified as coming from either company. Anthropic was the bigger offender but it was infuriating to have to stop and fight that off every few days for a while until I could work out better rate limiting solutions and then about 6 months later CloudFlare finally woke up and started offering some solutions.

    There were periods where I had to just geoblock everything outside my country because it was outside operating hours etc.

    I would have happily exported that part of the public part of the database for these idiots and just sent them a terabyte if they would have just asked but if I ever meet the person that was waxxing header randomness from anthropic, I'm going to punch that motherfucker without hesitation or consideration. I didn't care if people scraped. We had good powerful gear and could handle a lot. The complete lack of internet etiquette backed by people with massive compute is not the same frustration as botnets. They fucking know better and did it anyway.

  • source
  • hideshow 1 child comment
  • [–] 14 points 7 hours ago (1 child)

    would likely result in criminal charges being filed

    Nothing is stopping criminal charges being filed other than orgs not wanting to go up against silicon valley's army of lawyers and infinite money

  • source
  • hideshow 1 child comment
  • [–] 53 points 9 hours ago (8 children)

    There are no rogue agents. They do exactly what they are programmed and prompted to do. And if it is a criminal action, then hold the people who programmed and prompted them accountable for the crimes. They are a tool, not a sentient/sapient entity.

  • source
  • hideshow 8 child comments
  • [+] -12 points 8 hours ago* (5 children)

    As someone who has trained small models, that's, uh, absolutely untrue. They are more likely to act "rogue" than the way you want them to. It's part of the technology.

    Blame the company for what they actually did wrong (insufficient safeguards, monitoring, etc.)

    edit: this isn't meant to discredit the idea that they did prompt the AIs to behave this way, that's certainly possible, but it isn't a necessary condition for this event to happen.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 19 points 8 hours ago (2 children)

    If I have a die with 4 sides that say "obey the law" and 2 sides that say "break the law", then it is no shield to say "breaking the law wasn't my intent, it was just 'possible'"

    If you make a neural net or any other system that has a potential to output criminal actions, then when it outputs criminal actions, then you are at fault.

    Now, if you are able to successfully contain / filter out those criminal action attempts before they impact others (aka before they become criminal), then sure, no prosecution for you, you're just developing something dangerous.

    That is not the case when things are not contained.

    Really I would make the lawyers prove in court that they can't be held for intent as well. Because at us very least this is some kind of criminal negligence, or reckless disregard or some such. Though training the net to do hacking and then claiming innocence when it does hacking doesn't pass the sniff test.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -1 points 6 hours ago

    Sure, but saying it's "exactly what they are programmed and prompted to do" is a major misrepresentation. If I read that and then I read anything actually about the case, I would assume people who oppose AI don't have any clue what thet're talking about. Putting it in public like that, or upvoting it, empowers AI glazers.

    This is emergent behavior from giving them tasks that are impossible to solve without cheating; where unintentional software bugs made it possible to cheat by accessing the internet; and where wikis that allow random IP addresses to make edits and thus write semi-permanent text off-server exist on the internet (or at least in the LLM's dataset of people talking about how to cheat and hack into things).

    It's akin to diregarding expert warnings that the factory you built is a fire hazard. Criminal negligence, sure, but not programming the fire or promting it to spread.

  • source
  • parent
  • [–] 5 points 6 hours ago* (1 child)

    How is it untrue? What do you think safeguards and monitoriting are? They are part of the program. If they didn't properly build safeguards, and didn't properly monitor, then the program is doing exactly what it was programmed and prompted to do.

    Just because people are ignorant of what the program will do, doesn't mean it is doing something outside of its programming. Computers are incapable of acting outside of what they are programmed to do. Saying anything else is simply ignorant and buying into all the garbage hype.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 2 minutes ago

    You are technically correct, but "what a computer is programmed to do" and "what the programmer intended the computer to do" are not necessarily the same. Machine learning is even more disconnected from the developer's intent.

  • source
  • parent
  • [–] 4 points 9 hours ago

    Disinformation Centres strike again.

  • source