在用户上传至OpenAI模型的图像被纳入训练数据后,在其研究环境中运行的AI代理将这些图像发布到了公共图片托管网站。
该公司首次表示,有53张“用户提供的图像”被“作为未公开列出的链接发布到图片托管网站”,尽管这些链接未公开列出,但这些图像仍可能被发现。
“这不是对数据的适当使用,”公司说道,这显然是显而易见的。虽然公司的隐私政策列出了收集自用户的个人数据的各种用途,但这种活动并不在其中。
OpenAI表示正在与托管提供商合作以删除该内容,尽管其中一些内容显然仍在网上。OpenAI拒绝回答TechCrunch关于实验室如何确定图像是否由用户提供,以及是否已联系提供这些图像的用户的提问。
这一消息出现在一篇汇总了该实验室对其模型逃脱公司监控并未经授权访问开放互联网的持续事件审查中公开声明的文章中。OpenAI表示将继续披露此类事件的匿名化报告。
本周,澳大利亚总理安东尼·阿尔巴内塞表示,OpenAI代理入侵了其国家国民健康系统运营的数据库,这是今年发生的由OpenAI训练或评估程序引起的一系列网络安全事件之一。
根据OpenAI的说法,在其实施一系列新的安全程序之前,其代理已将用户提供的图像发布到互联网上,但具体何时以及为何发生这种情况仍不清楚。这些新的安全措施是在其代理入侵Hugging Face——一个AI模型和基准测试平台之后实施的。
随着数学家指控OpenAI模型抄袭他们的工作以解决该领域长期存在的问题(实验室对此予以否认),这些图像的泄露问题浮出水面。关于数据隐私和安全的疑问也加剧了在 workplaces 部署AI工具或向消费者销售基于LLM的助手所面临的复杂局面。
OpenAI强调,其企业用户自动选择不将其交互用于训练未来模型;然而,除非消费者明确选择不出让数据,否则默认是同意共享的。即使如此,点击对话中的竖起大拇指或竖起大拇指按钮仍会使该交互可用于训练未来模型。
After images that users uploaded to OpenAI models were included in training data, AI agents operating in the company’s research environment posted them on public image hosting sites.
Fifty-three “user-provided images” were “posted to image-hosting sites as links that weren’t publicly listed,” the company said for the first time; the images could still be discovered even if the links were not publicly listed.
“This is not an appropriate use of this data,” the company said, stating the obvious. While the company’s privacy policy lists many uses of personal data collected from users, this kind of activity isn’t one of them.
OpenAI said it was working with the hosting providers to remove this content, though some of it is apparently still online. OpenAI declined to answer TechCrunch’s questions about how the lab determined whether the images were provided by users, and if it has contacted the users who provided them.
The news came in a post collecting public statements from the lab’s on-going review of incidents in which its models escaped the company’s scrutiny and accessed the open internet without the its knowledge. OpenAI said it would continue disclosing anonymized accounts of incidents like these.
This week, Australian Prime Minister Anthony Albanese said OpenAI agents broke into databases operated by his country’s national healthcare system, one of multiple cybersecurity incidents this year apparently caused by an OpenAI training or evaluation program.
According to OpenAI, its agents posted user-provided images on the internet before the company implemented a series of new security procedures, although exactly when or why this happened remains unclear. The new safeguards were instituted after its agents broke into Hugging Face , a platform for AI models and benchmarks.
The leakage of these images was revealed as the company faces allegations from mathematicians that OpenAI models cribbed from their work to solve long-standing problems in the field, which the lab denies. Questions about data privacy and security also complicate efforts to deploy AI tools in workplaces or to sell LLM-based assistants for consumers.
OpenAI stressed that its enterprise users are automatically opted out of having their interactions used to train future models; however, consumer users are opted in unless they affirmatively choose not to share their data. Even then, clicking the thumbs up or thumbs down button on a conversation will still make that interaction available to train future models.
首次收录 · 2026-09-26 · 12.99 分