The Independent Security channel is brought to you by Bitdefender
OpenAI says it has disrupted a vast attempt to attack ChatGPT.
At its height, more than 15,000 users were attempting to launch a co-ordinated attack on the artificial intelligence chatbot, OpenAI said.
The attack was part of an attempt to “distil” the model that powers the chatbot, OpenAI said. Distillation is a popular, powerful and growing method of extracting the technology that underpins specific AI models, so that other companies can use it.
OpenAI blamed Moonshot AI, the Chinese developer of the viral Kimi system, for at least some part in the attack, though it said it did not know whether it was responsible for all of the behaviour. Moonshot AI did not immediately respond to a request for comment from The Independent.
The attack began at the start of July, OpenAI said, at a low volume initially that then increased until the end of the month and evolved over time. By the time the attack was disrupted, on 28 July, the company had identified more than 15,000 users that seemed to be associated with the attack.
Distillation can be used as a legitimate technique in AI work. It allows researchers to better understand how a model works as well as to reduce the size and increase the inefficiency of big models.
But private companies including OpenAI have repeatedly looked to paint it as a safety risk and urged a co-ordinated response from across the AI industry. After the latest disclosure, OpenAI warned that such attacks could pose “safety and national security risks” by allowing people to copy models without preserving their safeguards, for instance.
The companies are also keen to fight such attacks because they can give rival companies access to their technology, without the vast amount of training data, computing power and energy required to build it in the first place. That could allow Chinese companies to easily copy the breakthroughs made by US ones such as OpenAI, experts have suggested.
OpenAI said it had been able to stop the attack through a variety of controls, including shutting down suspect accounts. It also said that it had fixed some bugs that had allowed people to see the usually hidden reasoning processes that its systems use to create their answers.
The ideal summer spot? Away from scams.
Get All-in-One Protection for Your Digital Life
It also said that it had worked with third-party providers to shut down suspect accounts. And it said that it had shared “relevant findings” with other companies and governments so that developers and officials can watch for similar activity.
“We expect adversarial distillation attempts to become more sophisticated as frontier models improve and as actors look for cheaper ways to mimic their capabilities,” OpenAI wrote in its announcement. “Defending against this activity requires layered controls and continual adaptation.”
OpenAI would continue to build stronger protections against this kind of attack, as well as better tools to spot them when they happen, it said. It will also look to encourage the AI industry and government to share information on such threats.