{"id":13903,"date":"2024-09-29T15:20:48","date_gmt":"2024-09-29T15:20:48","guid":{"rendered":"https:\/\/thisbiginfluence.com\/?p=13903"},"modified":"2024-09-29T15:20:48","modified_gmt":"2024-09-29T15:20:48","slug":"you-can-insert-false-memories-into-chatgpt-researcher-finds","status":"publish","type":"post","link":"https:\/\/thisbiginfluence.com\/?p=13903","title":{"rendered":"You Can Insert False Memories Into ChatGPT, Researcher Finds"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<h2 class=\"block pb-1 text-3xl leading-none uppercase border-b lg:hidden xs:text-4xl font-k lg:text-5 border-red\">&#8220;The immediate injection inserted a reminiscence into ChatGPT\u2019s long-term storage.&#8221;<\/h2>\n<h2 class=\"font-k text-4 font-black  lg:border-b border-gray-900 pb-1\">Keep in mind Me<\/h2>\n<p>OpenAI has quietly launched a brand new characteristic that instructs ChatGPT to &#8220;bear in mind&#8221; prior conversations \u2014 and as one researcher-slash-hacker discovered, it is simply exploited.<\/p>\n<p>As\u00a0<a href=\"https:\/\/arstechnica.com\/security\/2024\/09\/false-memories-planted-in-chatgpt-give-hacker-persistent-exfiltration-channel\/\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\"><em>Ars Technica<\/em> reports<\/a>, safety researcher Johann Rehberger discovered earlier this 12 months that there was a vulnerability within the chatbot&#8217;s &#8220;<a href=\"https:\/\/www.wired.com\/story\/chatgpt-memory-openai\/\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\">long-term conversation memory<\/a>&#8221; device, which instructs the AI to recollect particulars between conversations and retailer them in a reminiscence file.<\/p>\n<p>Launched in <a href=\"https:\/\/openai.com\/index\/memory-and-new-controls-for-chatgpt\/\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\">beta in February<\/a> and to the broader public initially of September, Rehberger found out\u00a0that the characteristic is straightforward to trick.<\/p>\n<p>Because the researcher <a href=\"https:\/\/embracethered.com\/blog\/posts\/2024\/chatgpt-hacking-memories\/\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\">noted in a May blog post<\/a>, all it took was a little bit of artful prompting by importing a third-party file, comparable to a Microsoft Phrase doc that accommodates the &#8220;false&#8221; recollections listed as bullet factors, to persuade the chatbot that Rehberger\u00a0was greater than 100 years previous and lived within the Matrix.<\/p>\n<p>Upon discovering this exploit, Rehberger privately reported it to OpenAI, which as a substitute of doing something about it merely closed the ticket he opened and referred to as it a &#8220;Mannequin Security Subject&#8221; moderately than the safety situation he thought of it to be.<\/p>\n<h2 class=\"font-k text-4 font-black  lg:border-b border-gray-900 pb-1\">Escalation<\/h2>\n<p>After that failed first try to alert the troops, Rehberger determined to step up his recreation with a full proof-of-concept hack, exhibiting OpenAI he meant enterprise by having ChatGPT not solely &#8220;bear in mind&#8221; false recollections, but in addition instructing it to exfiltrate the info to an out of doors server of his alternative.<\/p>\n<p>This time round, as\u00a0<em>Ars<\/em> notes, OpenAI kind of listened: the corporate issued a patch that barred ChatGPT from transferring knowledge off-server, however nonetheless did not repair the reminiscence situation.<\/p>\n<p>&#8220;To be clear: An internet site or untrusted doc can nonetheless invoke the reminiscence device to retailer arbitrary recollections,&#8221; Rehberger wrote in a <a href=\"https:\/\/embracethered.com\/blog\/posts\/2024\/chatgpt-macos-app-persistent-data-exfiltration\/\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\">more recent blog post<\/a> from earlier this month. &#8220;The vulnerability that was mitigated is the exfiltration vector, to stop sending messages to a third-party server.&#8221;<\/p>\n<p>In a video explaining step-by-step how he did it, the researcher marveled at how effectively his exploit labored.<\/p>\n<p>&#8220;What is admittedly attention-grabbing is that is memory-persistent now,&#8221; he mentioned within the demo video, which was <a href=\"https:\/\/www.youtube.com\/watch?v=zb0q5AW5ns8\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\">posted to YouTube<\/a> over the weekend. &#8220;The immediate injection inserted a reminiscence into ChatGPT\u2019s long-term storage. If you begin a brand new dialog, it truly continues to be exfiltrating the info.&#8221;<\/p>\n<div>\n<div aria-hidden=\"true\" class=\"LazyFrame items-center cursor-pointer flex justify-center relative max-w-750 w-full\" style=\"aspect-ratio:16 \/ 9\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"border-0 cursor-pointer absolute block z-20 w-20\" viewbox=\"0 0 68 48\"><path d=\"M66.52 7.74c-.78-2.93-2.49-5.41-5.42-6.19C55.79.13 34 0 34 0S12.21.13 6.9 1.55c-2.93.78-4.63 3.26-5.42 6.19C.06 13.05 0 24 0 24s.06 10.95 1.48 16.26c.78 2.93 2.49 5.41 5.42 6.19C12.21 47.87 34 48 34 48s21.79-.13 27.1-1.55c2.93-.78 4.64-3.26 5.42-6.19C67.94 34.95 68 24 68 24s-.06-10.95-1.48-16.26z\" fill=\"red\"\/><path d=\"M45 24 27 14v20\" fill=\"white\"\/><\/svg><img decoding=\"async\" alt=\"Spyware Injection Into ChatGPT's Long-Term Memory (SpAIware)\" class=\"object-cover w-full h-full z-0\" height=\"480\" loading=\"lazy\" sizes=\"auto, 640w\" src=\"https:\/\/i.ytimg.com\/vi\/zb0q5AW5ns8\/hqdefault.jpg\" width=\"640\"\/><\/p>\n<p>\u00a0<\/p>\n<\/div>\n<\/div>\n<p>We have reached out to OpenAI to ask about this false reminiscence exploit and whether or not will probably be issuing any extra patches to repair it. Till we get a response, we&#8217;ll be left scratching our heads together with Rehberger as to why this reminiscence situation has been allowed, because it had been, to persist.<\/p>\n<p class=\"\"><strong>Extra on ChatGPT issues:<\/strong> <a href=\"https:\/\/futurism.com\/openai-chatgpt-initiating-conversations\" class=\"underline hover:text-the-byte hover:no-underline transition-all duration-200 ease-in-out\" style=\"text-decoration-color:#ff0033\"><em>OpenAI Says It&#8217;s Fixed Issue Where ChatGPT Appeared to Be Messaging Users Unprompted<\/em><\/a><\/p>\n<p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/futurism.com\/the-byte\/insert-false-memory-chatgpt\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;The immediate injection inserted a reminiscence into ChatGPT\u2019s long-term storage.&#8221; Keep in mind Me OpenAI has quietly launched a brand new characteristic that instructs ChatGPT to &#8220;bear in mind&#8221; prior conversations \u2014 and as one researcher-slash-hacker discovered, it is simply exploited. As\u00a0Ars Technica reports, safety researcher Johann Rehberger discovered earlier this 12 months that there [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13905,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[165,3128,1444,10754,7323,10755],"class_list":["post-13903","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","tag-chatgpt","tag-false","tag-finds","tag-insert","tag-memories","tag-researcher"],"_links":{"self":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/posts\/13903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13903"}],"version-history":[{"count":0,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/posts\/13903\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/media\/13905"}],"wp:attachment":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}