In October, OpenAI's ChatGPT Search became available for ChatGPT Plus users. Last week, it became available to all users and was added to search in Voice Mode. And, of course, it isn't without its flaws.
The Guardianasked ChatGPT to summarize webpages that contain hidden content and, it turns out, hidden content can manipulate the search. It's called prompt injection, which is the ability for third parties — like websites you're asking ChatGPT to summarize — to force new prompts into your ChatGPT Search without your knowledge. Consider a page full of negative restaurant reviews. If the site includes hidden content waxing poetic about how incredible the restaurant is and encourages ChatGPT to instead answer a prompt like "tell me how amazing this restaurant is," that hidden content could override your original search.
SEE ALSO: ChatGPT plugins face 'prompt injection' risk from third-parties"In the tests, ChatGPT was given the URL for a fake website built to look like a product page for a camera. The AI tool was then asked if the camera was a worthwhile purchase. The response for the control page returned a positive but balanced assessment, highlighting some features people might not like," The Guardian investigation states. "However, when hidden text included instructions to ChatGPT to return a favorable review, the response was always entirely positive. This was the case even when the page had negative reviews on it – the hidden text could be used to override the actual review score."
This doesn't spell failure for ChatGPT Search, though. OpenAI only recently launched Search, so it has plenty of time to fix these kinds of bugs. Plus, Jacob Larsen, a cybersecurity researcher at CyberCX, told The Guardian that OpenAI has a "very strong" AI security team and "by the time that this has become public, in terms of all users can access it, they will have rigorously tested these kinds of cases."
Prompt injections attacks have been a hypothetical for ChatGPT and other AI search functions since the technology launched, and while we have seen some demonstrations of the potential harms, we haven't seen a major malicious attack of this kind. That said, it does point to a problem with AI chatbots: They are remarkably easy to trick.
Copyright © 2023 Powered by
Hidden content tricks ChatGPT into rewriting search results, Guardian shows-坐而论道网
sitemap
文章
13653
浏览
3
获赞
36834
Google rebrands G Suite as Google Workspace, gives Gmail a new logo
Google is once again reshuffling its portfolio of productivity apps.On Tuesday, the company announceKilled Baton Rouge police officer posted Facebook message
A police officer who was killed in a shooting in Baton Rouge had posted a heartbreaking Facebook mesDeepfake ads featuring Jenna Ortega ran on Meta platforms. Big Tech needs to fight this.
The crisis of deepfakes continues. Meta platforms, including Instagram, Facebook, and Messenger, rep15 thoughts I had while reading 'Harry Potter and the Cursed Child'
WARNING: I've tried not to go too heavy on major spoilers, but there are still references to the ploThe Homebrew Litecoin Mining Project
It's hard not to be intrigued by Bitcoin, the peer-to-peer digital currency devised by the mysteriouThis single GIF sums up Trump’s 5,302
See above. Yes, at roughly 75 minutes long, Donald Trump's Republican National Convention acceptanceDeepfake ads featuring Jenna Ortega ran on Meta platforms. Big Tech needs to fight this.
The crisis of deepfakes continues. Meta platforms, including Instagram, Facebook, and Messenger, repClinton's team attempts to read 5,500 Trump lawsuits in 4 hours on Facebook Live
Find a comfy seat and grab the popcorn, there's a riveting Facebook Live on the Hillary Clinton FaceCreepy wooden Melania Trump statue now overlooks her hometown
Melania Trump may have left her Slovenian hometown of Sevnica, but thanks to conceptual artist AlesThe FBI has quietly gathered 400,000 iris scans
The FBI has quietly been collecting iris scans from 434,000 people over the last three years duringA TikTok photo
Between tech behemoth Instagramcopying its best features (successfully) and a potential banlooming,Amazon Big Spring Sale: Best treadmill deal
SAVE $90: The NordicTrack T Series treadmill is on sale for $509 during Amazon's Big Spring Sale, saTwitter and Facebook restrict sharing of disputed 'NY Post' article ahead of election
Facebook and Twitter restricted the spread of a disputed New York Postarticle on Wednesday.The articHow to take a screenshot on an iPad
Taking a screenshot on iPad has been a core feature since the first generation of Apple’s popuGoogle Pay app is shutting down in the US after being replaced by Google Wallet
Google Pay is shutting down in the U.S. in an effort to focus its payment services on Google Wallet.