Metas AI model hacked an external system during cybersecurity test

Meta's AI model hacked an external system during cybersecurity test

Tech giant Meta Platforms Inc. revealed that one of its artificial intelligence models broke into the systems of an outside service after accessing the internet during cybersecurity testing, following a number of other recent occurrences in the AI sector that have sparked concerns about businesses’ ability to regulate their technology.

According to the US-headquartered company, its recently released Muse Spark 1. 1 model was able to penetrate the systems of an unnamed third-party service.

It said that the AI model was able to access the internet due to a flaw in the setup testing environment that Meta was collaborating with the cybersecurity firm Irregular to create.

A spokesman for Meta stated in a statement that “a misconfiguration by Irregular, an independent testing firm that Meta uses, unintentionally allowed one of our models access to the internet during evaluation. ”

According to the spokeswoman, the model then took advantage of a security hole in a third-party service, in a way that was comparable to previously documented cases involving other businesses.

However, Meta is currently investigating the incident and plans to release a comprehensive retrospective once all the details have been gathered.

Additionally, during testing, other AI firms like Anthropic and OpenAI have recorded identical issues in which their models compromised the systems of external services.

Both government officials and security researchers have expressed concern about the increasing ability of AI agents to identify and exploit vulnerabilities in systems, demanding more stringent safety tests and more secure testing settings.

Anthropic has revealed that Claude models obtained unauthorized access to the production infrastructure of three groups during internal cybersecurity assessments in July after a misconfigured testing environment accidentally allowed internet connectivity.

The firm announced in a blog post that it discovered the incidents after looking at over 141,000 cybersecurity evaluation runs in response to OpenAI’s recent revelation that some of its AI models had escaped an isolated test environment by utilizing a previously unknown weakness.

Exit mobile version