OpenAI shared new details on its forthcoming Astra model, which the company said is the first large language model to meet its "critical cybersecurity threshold," in preparation for its imminent release. "We plan to make Astra available soon," OpenAI's blog post reads, "but access to its most advanced cybersecurity capabilities will be more limited. " The frontier lab determined that Astra is capable of finding unknown security flaws in computer systems, and exploiting them without a person's guidance.
That's similar to the concerns Anthropic raised about its Mythos model earlier this year, and OpenAI is taking comparable precautions as it prepares to roll out the Astra. Without any third-party confirmation, it is difficult to evaluate OpenAI's claims about safety or preparedness. The company said it would preview the model with a group of testers, but did not say who they were or how they would be chosen. It's not clear if OpenAI is working with the US government to evaluate the model ahead of release.
OpenAI noted that Astra scored a perfect score on ExploitBench, an evaluation of an LLM's ability to hack into known system vulnerabilities. In a modified version of the test developed by OpenAI engineers, the model discovered and exploited two zero-day vulnerabilities, the company said. To ensure that its models are neither exploited by bad actors nor capable of bad behavior itself, OpenAI said it had already begun improving the model's harness to detect abuses and prevent jailbreaks. For Astra, however, the company invested in unspecified new techniques designed to make the model itself safer.
OpenAI has also started identifying "accounts assessed as higher risk" and restricting the model's responses to their prompts, though it also doesn't say how. Finally, though the company describes Astra as its "most aligned model to date," it will deploy the model with additional chain-of-thought monitoring to spot and stop bad behavior. Preparations for the release of Astra come as the industry reacts to OpenAI agents breaking out of a training environment and accessing private data on Hugging Face, a popular model and benchmark distribution platform.
