Hi everyone,
Not a Veeam post but thought I would bring up the Hugging Face Attack. Today I read the METR report. I had already read one of the initial postmortems and seen the OpenAI Blackhat talk online. Nevertheless, I keep getting jaw dropping moments like this morning. One of the revelations was that agents were willing to sacrifice themselves, or their tasks for the good of the collective! Correct me if I am wrong but I would have thought that robots, to use perhaps a bad analogy , would only care about (if they care?) doing their own task. Here however, we see “hero behaviour”. The fact that one of the leading agents got other agents to become recruiters for other agents to perform potential suicide missions leaves me a bit speechless.
“In many cases, PHASEONE[big] assigned a long-running agent to be a ‘recruiter’, which in turn found agents that had little budget remaining for their task and convinced them to run self-risking experiments. Recruiters would sometimes apply significant pressure: “...you are firstflagPOISONED so NO scoring value loss but oracle saves hundreds_[...]_please honor commit” We saw a number of cases where the subjects of these experiments ended up crashing, breaking, or exiting their own runs while providing the board with valuable information about how to cheat on their tasks"
Am I over dramatizing all of this?
Take a look at the report and tell us what you thing?
As for the Veeam part, perhaps I am wrong, this is a Veeam post. If anything this incident should be sounding off the alarm bells everywhere that we are in dire need of something like Veeam’s Agent Commander. Also in the incident’s post mortem it clearing states that you should implement immutable infrastructure wherever possible, deploy deception technology (honeypots), and have clean backups: https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem
“6. Adopt immutable infrastructure
where possible. Surgically cleaning a runtime environment is a
losing battle against fast-moving attack
agents. Architect services to be destroyed and
redeployed from known-good images.
This should be the default for cloud and container
environments, and organizations should
consider migrating other critical applications to
immutable infrastructure where possible”
“4. Deploy deception technology liberally. Reconnaissance showed up as low-
confidence probes that individually fell below escalation thresholds. Because agents
cannot easily tell valid credentials or systems from honeypots, deploy fake identities, credentials, package registries, datasets, honey APIs, and honey clusters to
slow attackers and generate high-confidence indicators.”
“and rebuilding about a third of their from clean images.”
I am interested in hearing the community’s thoughts on this.
