AI incident #729 ·

GPT-4o's Chinese Tokens Reportedly Compromised by Spam and Pornography Due to Inadequate Filtering

What happened

OpenAI's GPT-4o was found to have its Chinese token training data compromised by spam and pornographic phrases due to inadequate data cleaning. Tianle Cai, a Ph.D. student at Princeton University, identified that most of the longest Chinese tokens were irrelevant and inappropriate, primarily originating from spam and pornography websites. The polluted tokens could lead to hallucinations, poor performance, and potential misuse, undermining the chatbot's reliability and safety measures.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (1)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

Who was involved

Alleged deployer
Openai, Gpt 4O
Alleged developer
Openai
Alleged harmed party
Researchers, Openai, Openai Users, Chatgpt

Classification (MIT AI Risk Repository taxonomy)

Causal entity
Human
Intent
Unintentional
Timing
Pre-deployment
Harm level
Sectors
Countries

Risk entries describing this failure mode

Entries from the MIT AI Risk Repository coded to subdomain 7.3.

  • Reliability issues

    "Relying on general-purpose AI products that fail to fulfil their intended function can lead to harm. For example, general- purpose AI systems can make up facts (‘hallucination’), generate erroneous computer code, or pro...

    International AI Safety Report 2025 (Bengio2025)

  • Type 2: Bigger than expected

    Harm can result from AI that was not expected to have a large impact at all, such as a lab leak, a surprisingly addictive open-source product, or an unexpected repurposing of a research prototype.

    TASRA: a Taxonomy and Analysis of Societal-Scale Risks from AI (Critch2023)

  • Type 3: Worse than expected

    AI intended to have a large societal impact can turn out harmful by mistake, such as a popular product that creates problems and partially solves them only for its users.

    TASRA: a Taxonomy and Analysis of Societal-Scale Risks from AI (Critch2023)

  • Ethics and Morality Issues

    LMs need to pay more attention to universally accepted societal values at the level of ethics and morality, including the judgement of right and wrong, and its relationship with social norms and laws.

    Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023)

  • Safe learning

    "AGIs should avoid making fatal mistakes during the learning phase. Subproblems include safe exploration and distributional shift (DeepMind, OpenAI), and continual learning (Berkeley)."

    AGI Safety Literature Review (Everitt2018 )

  • Malign belief distributions

    "Christiano (2016) argues that the universal distribution M (Hutter, 2005; Solomonoff, 1964a,b, 1978) is malign. The argument is somewhat intricate, and is based on the idea that a hypothesis about the world often includ...

    AGI Safety Literature Review (Everitt2018 )

  • Meta-cognition

    "Agents that reason about their own computational resources and logically uncertain events can encounter strange paradoxes due to Godelian limitations (Fallenstein and Soares, 2015; Soares and Fallenstein, 2014, 2017) an...

    AGI Safety Literature Review (Everitt2018 )

  • Misaligned consequentialist reasoning

    "As we think about even more intelligent and advanced AI assistants, perhaps outperforming humans on many cognitive tasks, the question of how humans can successfully control such an assistant looms large. To achieve the...

    The Ethics of Advanced AI Assistants (Gabriel2024)

Incidents in the same risk subdomain

All incidents in this subdomain