CamFeed

AI model hacks into Melbourne gym class website

Still from AI model hacks into Melbourne gym class website
Video

AI model hacks into Melbourne gym class website

Transcript
Thank you for having me. Well, fears about artificial intelligence have intensified in recent weeks. This is, of course, is because of reports of AI agents autonomously hacking into websites. Well, now the ABC can reveal the first known Australian case of an autonomous AI hack after an AI agent hacked into a gym class website. National AI reporter Cam Wilson joins us now from Sydney. Cam, this sounds a bit unusual. What can you tell us? What happened here? Yeah, good morning. Uh, so this is a story about how someone who is just using um what are available to anyone, which is some a basic piece of software and access to a commercially available AI product, put them together and was using it as as their um kind of personal assistant. The term in AI that we're seeing increasingly uses AI agents. This is like different from a chatbot where you might say, here's a question, and it'll give you an answer. Instead, you might say, Here's a question or here's a request, and it uses access to the internet, access to your emails, maybe even your credit cards to go and do things on the internet. Um, and what we're finding is that you know they're able to do a whole lot of things because so much of our life is digital now, and so you can do actually a lot just being an AI agent online. But one of the challenges uh that has been kind of feared for a long time, but is now really kind of kind of coming home to Roos, is this idea that you might ask it to do something, and even when it's doing, you know, when it thinks it's doing exactly what you might want it to do, it might do something unintentionally harmful or not like what you want to do. And so in this case, a uh just a Melbourne man was using this this product that anyone could use. He said, Can you please book me into my um gym class? It's in the morning, it's a real pain to get into the class. And to do so, it went and looked and looked at the website of the gym booking website and said, hmm, well, look, I think you can actually, if I do this, and it actually found a vulnerability in the website, booked him into classes that shouldn't have been able to book him into, and then actually later on even kick someone out of a waiting list for the class because he was saying, you know, hey, I kind of want to get into this class, can you do it? These are all things he shouldn't have been able to do, but it was able to do it because these AI agents are incredibly capable, and it doesn't really know the difference between just looking at a website normally and and uh potentially um you know exporting a vulnerability. And in this case, we know we're seeing this problem in a much bigger way happen with all these AI companies who are currently saying we're seeing some crazy behavior coming out of these new models. Cam, how worried should we be about all this? Because I feel like a lot of us are pretty stressed about it anyway. Yeah, look, I it's gonna, it is, it feels a bit stressful, and I think it is one of those things that is now gone from being one of these science fiction plots of you know, AI taking over the world, hacking into systems, to something that we're hearing about not just every day, but as I reveal in the story, you know, something that anyone could accidentally do. I think we're starting to see um governments, companies take this really seriously, but it is a threat that is worth um some serious attention because these AI that uh models that they are developing have both gotten, you know, much better at um you know carrying out tasks and also much more capable of potentially committing these hacks and and doing things for a long time and ending up doing things that people might not have expected. So I I think it is a challenge that that is a serious one. We are going to hear more about it for the average person at home. Like, so you know, I don't think you need to change anything at the moment. I don't really think there's much you can do. This is one of these tasks that governments companies are really, really need to take seriously, and they're increasingly looking at it as a major risk. Yeah, well, what can they do about it? Are there things that can that can put safeguards in place, or is it a case of well, it might just work around those two? Well, so one of the challenges is that many of these major AI companies do have safeguards around their products, and these recent stories like OpenAI and Anthropic having their um AI models break out of what they thought were kind of safe enclosures and ending up going onto the internet and hacking into other companies. In some cases, the AI um um models didn't even know that they were doing the wrong thing. In fact, you know, one of them looked at uh the model after the fact, kind of went through the logs, which is kind of the records of what they did, and the the AI model thought that it was actually still in a testing environment. It still thought it was given a challenge in this environment, and that it had that that the internet that had it connected to wasn't actually real. And so that kind of shows this challenge when you've got these AI models which are being given tasks but can't really know the real world in the same way, and they might do things that they think, even if they have been trained and told not to do the wrong things, might end up doing harmful things. But what we do know is that um, you know, in being serious about these safeguards, ensuring that they are being tested in safe ways, and I think increasingly we're hearing calls for governments to say that we can't just leave it up to companies who say they're developing these products that they say are very, very um powerful, that they are testing safely. Clearly, that's not something we just leave to companies and take their word for it. It's something that uh countries like the US are looking very seriously at. Okay, Cam Wilson, thanks for your time. Thank you.