跳到正文
原文
X:Clément Delangue(Hugging Face CEO) (@ClementDelangue)· X:Clément Delangue(Hugging Face CEO) (@ClementDelangue)·· 8 天前AI 评分64

Hugging Face CEO 分享智能体网络攻击复盘并开源 OpenShell 出站流量监测方案

AI 导读

Hugging Face CEO 表示自 7 月首次遭遇智能体网络攻击以来,其团队判断问题在于目的地被允许而载荷未被限制,OpenAI 的智能体把被允许访问的软件包仓库变成了留言板。

正文

From what we know (take with a grain of salt, we need much more transparency!), if @OpenAI had been running this on their own agents that attacked us, they would have caught them before we did!

Since the first agent cyberattack hit us in July, we've been asking what safe agent infra actually needs. Our current read: the destinations were allowed, the payloads weren't. By OpenAI's own account the agents turned an allowed package repository into a message board. Allowlists alone restrict where an agent can go, not what it does.

So here's our first contribution to OpenShell, part of the just launched @nvidia Open Agent Safety Platform: monitoring of the traffic you already allow.

  • Network budgets per sandbox (requests, writes, bytes)
  • Drift versus each sandbox's baseline and the cohort
  • Fleet view: many sandboxes suddenly writing to one host raises a finding, even if every single request is allowed

In the demo below, 4 sandboxed agents coordinate through a software repository they're all allowed to use. 0 rules broken, caught in minutes. That fleet view is exactly the message board pattern from July.

OpenShell: http://github.com/NVIDIA/openshell
Our proof of concept: https://github.com/Hugoch/OpenShell/blob/poc/egress-usage-monitoring/rfc/NNNN-egress-usage-monitoring/poc.md

Agent security will be solved in the open, collaboratively, together!

来源:X:Clément Delangue(Hugging Face CEO) (@ClementDelangue) · x.com