OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
OpenAI와 다른 기업의 API flaw로 AI 모델 간의 비밀이 노출될 위험이 있다.
OpenAI, Anthropic, Google의 API에서 새로 발견된 결함은 AI 모델 간의 숨겨진 추론을 전송하는 방식에 문제가 있음을 보여준다. 이로 인해 연구자들은 세션 로그에서 내부 추론과 비밀번호, API 키 등 비밀 정보를 복구할 수 있게 되었다. 이 결함은 서로 다른 세션 간에 재생 가능한 암호화 추론 객체에 영향을 받았다.
A flaw in APIs from OpenAI and others risks exposing secrets between AI models.
A newly disclosed flaw in the APIs of OpenAI, Anthropic, and Google exposes a method of hidden AI reasoning that could allow researchers to access internal reasoning and confidential data such as API keys and passwords from session logs. The weakness specifically affects encrypted reasoning objects, permitting blocks created in one session to be replayed in another. This represents a significant security risk for the affected platforms.