News
OpenAI announces new security policy to strengthen model development monitoring and network isolation
2 min read
Source: ithome.com
IT House reported on August 19 that on Tuesday local time, OpenAI announced a batch of new security policies, focusing on controlling security incidents that may occur during model testing. New security measures include more detailed monitoring during model development, as well as an increased emphasis on model alignment and security during the post-training phase. IT House noted that OpenAI said in a blog post: "As model capabilities continue to increase, the risks faced in the process of developing and testing these models internally also increase. The standards we have established in terms of monitoring, alignment, and security must always be ahead of these risks." This is one of the first major adjustments in security practices announced by OpenAI since the disclosure of the Hugging Face incident on July 21. OpenAI representatives said that these measures were not directly launched in response to the Hugging Face incident, but the cybersecurity capabilities demonstrated by the upcoming Astra model, as well as the rapid pace of development of the entire AI industry, are also part of the reasons for the company to take these measures. OpenAI also revealed that after the Hugging Face incident, the company suspended reinforcement learning (RL) training for two weeks, but has now restarted the training of many lower-risk models. OpenAI wrote in a blog: "We are currently suspending the largest cutting-edge reinforcement learning training program while conducting small-scale training and evaluation to evaluate model behavior, verify security measures, and obtain more evidence about model alignment before moving forward." Amelia Glaese, vice president of research at OpenAI, emphasized in an interview with reporters that as model capabilities continue to increase, the company's stringency of security controls will also increase, and the most capable models will receive the most stringent scrutiny. "We have established requirements and standards for secure development. These requirements and standards will be adjusted based on the level of risk we assess," Glaese told reporters.