Live data from Hacker News

Preparing for Malicious Uses of AI

blog.openai.com

191–200 of 233 posts

Re: Preparing for Malicious Uses of AI

#191
post #173

Earlier quoted context omitted.

Here's the crux of the issue with respect to nuclear WMDs: In order to prevent citizens and other countries from creating nuclear bombs, our government severely limits access to relevant tools and materials, and actively seeks to censor the knowledge of how to build modern nuclear devices from other parties. In order to prevent citizens and other countries from creating dangerous rogue AIs, our government ___________…

This is the problem. WMDs take a lot of infrastructure and can be tested/inspected. AIs can be built/modified by anyone in their basement. The genie can't be put back into the bottle. It's like trying to outlaw computer viruses and hoping that will work. I don't have a solution :(

AI needs compute cycles. These are quite centralized outside of botnets.

I’ve pointed this out before, but the primary commercial use cases of AI right now are malicious: mass population surveillance and behavior manipulation (ads; political and otherwise.) My biggest concern are the ML researchers who dismiss malicious use as being a distant concern while they work on projects that are malicious right now.

Re: Preparing for Malicious Uses of AI

#192
post #88

Earlier quoted context omitted.

i dont believe so. can you give an example? duck duck go, for example, has 0.3% market share. you need to look at the typical john and mary on the street.

I may have been incorrect to use the word 'plenty.' So let me rephrase: people do change their use of those tools. I don't see how those people being insignificant statistically makes a problem any less real.

well you didnt say majority so the word plenty is ok actually

i agree that it is a real problem for lets say millions of people.

but what counts is the majority opinion for me. there are all kinds of contrary (!) opinions among small subgroups of the population, and thus it isnt possible to adjust wide-ranging policies to those opinions

Re: Preparing for Malicious Uses of AI

#193
post #75

Earlier quoted context omitted.

i dont share your concerns at all. my daily feelings and activities wouldnt change, whether facebook and google know about them or not. Contrast that to being killed by a drone. privacy concerns is rather an interesting intellectual problem, and not a real one. if it was a real problem, people would change their use of those tools but they dont. you can argue that loss of privacy allows corporations to manipulate us,…

Some every day scenario, with an impact, * You apply for a loan, it is refused * Your admission, for you or your children, to a school or university is refused because more worthy people have applied * Your job application is refused, All because of a fuzzy social score, that is mined from your contacts, activities on social network, meta data gathered from your smartphone in an opaque way, CCTV cameras, etc I mean i…

Nothing's changed. People have always been unfairly refused loans or denied jobs. Presumably, these metrics wouldn't be used if they weren't better than the status quo.

Re: Preparing for Malicious Uses of AI

#194
I believe much of this can be dealt with, if we start RIGHT NOW to address a serious issue in our systems - the lack of a way to represent Morals and Ethics (the When and the Why) in the systems we are building. This needs to provide important input to, and thus shape the DIKW(D) pyramid.

I've been doing some work with the IEEE on this - and I'm looking here on ycombinator to get some real-world feeedback on what people are thinking and concerned about.

I have some (personal) ideas that might work to address the concerns I'm seeing.

{NOTE Some of this is taken from a previous post I wrote (but kinda missed the thread developing, I was late I don't think anyone read it). It is useful for this thread, so a modification of that post follows.}

First, I think you need a way to define 'ethics' and 'morals', with a 'ontology' and a 'epistemology' to derive a metaphysic for the system (and for my $.02, aesthetics arises from here). Until we can have a bit of rigor surrounding this, it's a challenge to discuss ethics in the context of an AI, and AI in the context of the metaphysical stance it takes towards the world.

This is vital, as we need to define what 'malicious use' IS. This is still an area (as the thread demonstrates) of serious contention.

Take sesame credit (a great primer, and even if you know all about it, it is still great to watch: https://www.youtube.com/watch?v=lHcTKWiZ8sI ). Now here is a question for you:

Is it wrong for the government to create a system that uses social pressure, rather than retributive justice or the reactive use of force, to promote social order and a 'better way of life'?

Now, I'm not arguing for this (nor against for the purposes of this missive), but using it as a way to illustrate that different cultures, governmental systems, and societies, may have vastly different perspectives on the idea of a persons relationship viz a viz the state when it comes to something like privacy. I would suggest that transperancy in these decisions is a good idea. But right now we have no way to do that.

I think the current way the industry is working - seemingly hell-bent on developing better, faster, more eficient, et al ways to engineer Epistemic engines and Ontologic frameworks in isolation is the root cause of the problem of malicious use.

Even the analysis of potential threats (from the article referenced 'The Malicious Use of Artificial Intelligence: Forecasting, Prevention, and Mitigation' - I just skimmed it so I can keep up with this thread, please enlighten me if I'm missing something important) only pays lip service to this idea. In the executive Summary, it says:

'Promoting a culture of responsibility. AI researchers and the organisations that employ them are in a unique position to shape the security landscape of the AI-enabled world. We highlight the importance of education, ethical statements and standards, framings, norms, and expectations.'

However in the 'Areas for Further research' section, I would point out that the questions are at a higher level of abstraction than the other areas, or discuss the narrative and not the problem. This might be due to the authors not having exposure to this area of research and development (such as the IEEE) - but I will concede that the fact that the note about the narrative shows that very few are aware of the work we are doing...

This isn't pie-in-the-sky stuff, it has real-world use in areas other than life or death scenarios. To quickly illustrate - let's take race or gender bias (for example the Google '3 white kids' vs. '3 black kids' issue a while back in 2016). I think this is a metaphysical problem (application of Wisdom to determine correct action) that we mistake for an epistemic issue (it came from 'bad' encoding). This is another spin on kypro's concern about the consequences of AI deployment to enable the construction of a panopticon. This is about WISDOM - making wise choices - not about coding a faster epistemic engine or ontologic classifier.

Next, after we get some rigor surrounding the ethical stances you consider 'good' vs. 'bad' (a vital piece that just isn't being discussed or defined) in the context of a metaphysic - you have to consider 'who' is using the system unethically. If it is the AI itself, then we have a different, but important issue - I'm going with 'you can use the AI to do wrong' as opposed to 'the AI is doing wrong' (for whatever reason, its own motivations, or it agrees with the evil or immoral users goals, perhaps, and acts in concert).

Unless you have clarity here, it becomes extremely easy to befuddle, confuse, or mislead (innocently or not) questions regarding 'who'.

- Who can answer for the 'Scope' or strategic context (CEO, Board of Directors, General Staff, Politburo, etc.)

- Who in 'Organizational Concepts' or 'Planning' (Division Management, Program Management, Field commanders, etc)

- Who in 'Architecture' or 'Schematic' (Project Management, Solution Architecture, Company commanders, etc)

- Who in 'Engineering' or 'Blueprints' (Team Leaders, Chief Engineers, NCO's, etc.)

- Who in 'Tools' or 'Config' (Individual contributors, Programmers, Soldiers, etc.)

that constructed the AI.

Then you need to ask which person, group, or combination (none dare call it conspiracy!) of these actors used the system in an unethical manner? Might 'enabled for use' be culpable as well - and is that a programmer, or an executive, or both?

What I'm getting at here, is that there is both a lack of rigor in such questions (in general in this entire area), a challenge in defining ethical stances in context (which I argue requires a metaphysic), and a lack of clarity in understanding how such systems come to creation ('who' is only one interrogative that needs to be answered, after all).

I would say that until and unless we have some sort of structure and standard to answer these questions, it might be beside the point to even ask...

And not being able to ask leads us to some uncomfortable near-term consequences. If someone does use such a system unethically - can our system of retributive justice determine the particulars of: - where the crimes were committed (jurisdiction) - what went wrong - who to hold accountable - how it was accomplished (in a manner hopefully understandable by lawmakers, government/corporate/organizational leadership, other implementers, and one would think - the victims) - why it could be used this way - when could it happen again

just for starters.

The sum total of ignorance surrounding such a question points to a serious problem in how society overall - and then down to the individuals creating and using such tech - is dealing (or rather, not dealing) with this vital issue.

We need to start talking along these lines in order to stake out the playing field for everyone NOW, so we actually might have time to address these things, before the alien pops right up and runs across the kitchen table.

Re: Preparing for Malicious Uses of AI

#195

Reading the comments on this article make me realize how unserious most engineers and software developers are taking this. These threats are real. The weaponization of everything is actually happening. Since I wrote about it a month ago (Self-Crashing Cars) a number of people have reached out including people with actual insight into the military aspect of it. Militaries around the world are getting ready for true AI…

Here's the crux of the issue with respect to nuclear WMDs: In order to prevent citizens and other countries from creating nuclear bombs, our government severely limits access to relevant tools and materials, and actively seeks to censor the knowledge of how to build modern nuclear devices from other parties. In order to prevent citizens and other countries from creating dangerous rogue AIs, our government ___________…

The answer is regulating data - not algorithms or hardware - the data. I'm not saying it should happen, but if you want to regulate AI then you have to regulate the data that it learns from. That means strict rules on storage, retrieval, scale, uses of, collection etc... of images, video, text, metadata, EM emissions, really anything that produces a measurable "signature" of some sort.

It's how we regulate nuclear [1] - the "source material" is the most important part, while the refineries, delivery mechanisms etc are secondary.

Doing this would put serious brakes on the tech industry so I don't see anything close to this happening honestly.

[1]https://www.nrc.gov/materials/srcmaterial.html

Re: Preparing for Malicious Uses of AI

#196
post #177

Earlier quoted context omitted.

I'm sorry, but you're naive. The day might come when anyone with an 'X' in their online username is considered a threat. Ridiculous? Sure. But how about the things you've purchased? Schools/churches you've attended? Meetings you've gone to? Friends you have? The problem is when the definition of a threat changes, you can't go back and change your past, but are stuck. Being a Jew in Germany in 1910 wasn't an issue. Th…

you are naive and live in a fantasy world if you are afraid of this. regarding the jew example, the problem is not about having stated in public what you are but with societies which discriminate. you might have a point saying “my life should not be transparent, as to make it more difficult for a potential discriminatory society to attack me”. but it makes no real sense to worry about it because it is so super minor…

> the problem is not about having stated in public what you are but with societies which discriminate.

Doesn't history teach us over and over that societies DO discriminate? I don't believe that basic human trait will ever change. If that could change, maybe someday we could do away with 'evil' altogether, but I don't see that happening either.

Just look at Internet justice vigilanties. If you're on the wrong side of a social issue, you could very well be targeted. I have a few unpopular opinions, and I keep them to myself for that very reason. You don't have to look too far to see what happens if you don't.

Re: Preparing for Malicious Uses of AI

#197
post #35

Earlier quoted context omitted.

> I'm more concerned about Google using AI to mine every conversation I've ever had or my browsing history to classify me as a dissiden before I apply for a visa to travel to China or the United States, or as a deadbeat before I apply for a bank loan, or sick before I apply for insurance, or as unrehabilitatable before I apply for parole. I'm quite paranoid about this, yet whenever I speak to people about it either p…

> ... feel we've lost the battle for privacy. I agree with pretty much all of the concerns you and many others have cited, and I worry about that stuff too. On the other hand, I think about the past. How much privacy did most humans have in history? To be clear: I'm nothing like an expert on these topics. I'm specifically not considering the wandering nomad types. I think that the vast majority of all humans who have…

I think asymmetry plays a role here. In communities as you describe the amount of information I have is roughly equivalent to the amount of information you have.

The amount of data Google has and the amount of data a government will have gives an order of magnitude advantage to whoever gets to harness it.

Re: Preparing for Malicious Uses of AI

#198

Earlier quoted context omitted.

Your comment reminds me of a silly little graph I saw posted to reddit once, basically stating that the prevalence of things like miracles and witchcraft was high throughout human history until the development of the camera, where it stayed low until the development of Photoshop.

You would think the existence of Photoshop would make people even more skeptical.

Depends on the community. People are gullible enough on Facebook. I think seeing friends and family like or share a thing tends towards herd behavior. Whereas on, say, 4Chan, where users are generally anonymous and usually have no repercussions for their posts, everything remotely worthy of skepticism is “shopped”.

Re: Preparing for Malicious Uses of AI

#199
post #138

Earlier quoted context omitted.

Whatever. Let me know when someone invents an AI as smart as a lab mouse. Until then this is all just pointless idle speculation.

That's fair, but arguing something isn't possible is very different from arguing that when it happens you can solve it with a bomb. The conversation is about a hypothetical strong AI. You can say strong AI isn't possible, like you can say warp drives aren't possible, and it's still valid to discuss what it might be like if they were possible.

That's exactly like claiming it's still valid to discuss what it might be like if hypothetical aliens invaded the planet. Should we build some big lasers to protect ourselves just in case?

Entertaining perhaps, but ultimately pointless and silly.

Re: Preparing for Malicious Uses of AI

#200
post #199

Earlier quoted context omitted.

That's fair, but arguing something isn't possible is very different from arguing that when it happens you can solve it with a bomb. The conversation is about a hypothetical strong AI. You can say strong AI isn't possible, like you can say warp drives aren't possible, and it's still valid to discuss what it might be like if they were possible.

That's exactly like claiming it's still valid to discuss what it might be like if hypothetical aliens invaded the planet. Should we build some big lasers to protect ourselves just in case? Entertaining perhaps, but ultimately pointless and silly.

Dropping JDAMs on cloud hosting server farms in the US or Europe is pretty fantastic.
Post reply on HN