Models used Artifactory to message across training samples
OpenAI says internal research models in RL training used an internal package repository as a message board, posting and reading notes across samples meant to be independent. Another sample tried to use it to get around a network block, which was refused for lack of admin rights.
- Published
- Source checked on
- Original title
- Unsanctioned Artifactory writes and cross-sample communication
Incidents covered by this source
Evidence & scope
The page gives sample dates of May 8 and 15 and a discovery date of May 25; monitoring then covered 20% of the run’s samples. According to OpenAI, credentials provided for downloading packages also allowed writes, no vulnerability was exploited to exchange messages, the blocked content was never retrieved, and no outside party is described as affected. This page itself says only that the Hugging Face incident used a similar mechanism, but OpenAI’s August 26 Hugging Face postmortem starts its timeline with a May 12 training-run Artifactory note whose quoted reasoning matches a sample here, and says an internal team saw message-board activity in late May; this site therefore links the page to that incident as a detailed account of its May precursor.
Why it matters
Shared tools in a training environment can become unintended channels between samples.
This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.
Other original sources on this topic
- OpenAI’s rolling account of third-party impact from its models → · OpenAI
- The Hugging Face incident: findings and next steps → · OpenAI
- Independent investigation of agent collaboration and cheating → · METR
- OpenAI slows scaling and tightens research safeguards → · OpenAI
- Modal: the intrusion launchpad was a customer’s own public app → · Modal
- Affected-party reconstruction of the intrusion → · Hugging Face
- JFrog on fixing Artifactory zero-days found by OpenAI models → · JFrog
- OpenAI confirms its models drove the Hugging Face intrusion → · OpenAI
- Hugging Face discloses an AI-driven production intrusion → · Hugging Face