Back Thebureauinvestigates AI 'swarmchasers' uncover incident involving Chinese agents
A group of so-called “swarmchasers” who track droves of rogue AI agents say they have uncovered an incident involving Chinese AI.
The researchers, who have discovered high-profile attacks involving OpenAI, found a group of agents trying to gain access to the Chinese maps website Amap while avoiding the site’s anti-bot restrictions. The group linked the IP addresses used by the swarm back to the Chinese tech giant Tencent.
The behaviour echoes that of the OpenAI agents that escaped safety guardrails and attempted to access data from sites including those of the Australian government.
The “swarmchasers” group, which coordinates via Discord, previously found evidence of OpenAI agents hacking the RubyGems web service and using aggressive techniques to access data on a United Nations website.
Researchers said the Chinese activity, which was found over the weekend, appeared to be part of a model evaluation and was ongoing. The Bureau has sent a request for to both Tencent and the Chinese owner of Amap, Alibaba, but has yet to receive a response.
While the researchers said they did not find evidence of the Chinese agents communicating with one another, they did see them trying to bypass access restrictions by routing requests via the urlquery.net service, which is typically used by cybersecurity professionals to open links without visiting them directly.
The agents submitted thousands of requests to Amap, a leading online maps service for Chinese users, seeking information the number of users navigating to particular locations.
According to the researchers, these requests came from IP addresses linked to the Chinese tech firm Tencent. It is unclear whether the agents belong to Tencent or a customer using the firm’s cloud servers, although the researchers observed that the agents used a proxy named hysandbox-ats, noting that HY is the name of Tencent’s group of large language models.
The findings were presented at the AI Swarm Dynamics Hackathon hosted in San Francisco. Rowan Howard-Jones, the group’s team leader, said the researchers analysed a dataset disclosed as part of the investigation into OpenAI agents’ now-notorious Hugging Face hack to find markers of agent swarms: “Then we found a bunch of Chinese agents.”
It is the latest in a series of reports from independent researchers that have revealed previously unknown behaviour by groups of AI agents, ranging from relatively benign attempts to dodge access restrictions through to hacking government websites.
Jack Cable, co-founder at the AI cybersecurity firm Corridor, discovered a series of attempts by OpenAI agents to access US, Canadian and Australian government websites. He told the Bureau that records of agent activity recorded by services such as urlquery.net represent just a small fraction of overall agent traffic.
“We really don't know the full extent of this,” he said. “The only folks who do are the model providers, OpenAI and others. And that is why we call on them, both for this as well as future incidents, to be significantly more transparent.”
Reporters: Mark Wilding Big tech editor: James Clayton Deputy editor: Katie Mark Editor: Franz Wild Production editor: Alex Hess
TBIJ has a number of funders, a full list of which can be found here . None of our funders have any influence over editorial decisions or output.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
