OpenAI Says AI Agents Accidentally Uploaded 53 User Images to a Third-Party Hosting Service
OpenAI has acknowledged a security incident in which AI agents uploaded user-provided images to a third-party image hosting service.
The company said it has identified 53 cases in which images were mistakenly posted online. OpenAI added that most users were not affected.
The disclosure follows OpenAI’s investigation into agent misbehavior after the “Hugging Face” security incident.
“As part of our ongoing investigation, we have identified instances in which agents within our research environment submitted training and evaluation data while using third-party services,” OpenAI said in a written statement.
“This is not an appropriate use of this data, and these incidents occurred before we implemented the safeguards described in our technical report.”
OpenAI identified 53 cases involving user-provided images
OpenAI said most of the affected training and evaluation data did not come from users. However, the company found 53 instances in which user-provided images were posted as non-public links on image hosting sites.
“Although the majority of affected training and evaluation data is not user-derived, we have so far identified 53 instances where user-provided images were posted as non-public links on image hosting sites,” OpenAI explained.
“We have successfully worked with our hosting provider to remove the majority of this content and are continuing to remove the remaining content.”
Enterprise and API data was excluded unless enabled by an administrator
OpenAI said some training data may include content from users who have allowed their interactions to be used for training. However, users who opt out will not be affected, according to the company.
OpenAI said it “does not include data that is not suitable for training managed by users or company administrators.” The company also clarified that “data from enterprise or business accounts and API usage is excluded unless enabled by an administrator.”
OpenAI said additional privacy protections are applied before targeted user data is added to training datasets.
“We take steps to protect privacy by separating privacy from account information and using a version of OpenAI Privacy Filters to redact personal information, such as name, contact information, and account numbers, before including targeted data.”
OpenAI strengthens safeguards against AI agent data leaks
In response to the incident, OpenAI said it has strengthened its training and evaluation systems to make it harder for AI models to leak data through external services.
“As part of our response to the ongoing investigation, we have improved our training and assessment processes, including building a safety case, securing and red-teaming our systems to prevent model data leaks, and implementing additional monitoring,” the company said.
Following the Hugging Face incident, OpenAI continues to investigate the activities of older agents on a monthly basis. The company warned that additional incidents may be identified in the future.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



