Study: ChatGPT writes code that makes databases leak sensitive info
Generative AI tools such as ChatGPT, Baidu-UNIT, and AI2sql can be tricked into producing malicious code, which could be used to launch cyber attacks, according to new research. University of Sheffield researchers found that it is possible to manipulate six commercial AI tools capable of generating responses to text-to-SQL queries, including ChatGPT , into creating code capable of breaching other systems, steal sensitive personal information, tamper with or destroy databases, or bring down services using denial-of-service attacks. According to the researchers, OpenAI has since fixed all of the specific issues, as has Baidu, which financially rewarded the scientists. Developers of the four other systems have not responded publicly. Sy stem 🤖 ChatGPT Baidu UNIT 🔗 Operator: Developer: AI2sql; Baidu; NiceAdmin; OpenAI; Text2SQL.AI; SQLAI.AI Country: USA Sector: Technology Purpose: Generate text Technology: Chatbot; Generative AI; Machine learning; Text-to-SQL Issue: Privacy; Security
- Date it happened
- 2023-10-01
- Product, system or model
- AIHelperBot; AI2sql; Baidu-UNIT; ChatGPT; Text2SQL.AI; TOOLSKE
This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.