Earlier quoted context omitted.
Ah, yes. The airgapped lab with internet access.
They never claimed to be airgapped. That's a term people keep on throwing around in spite of that.
Be skeptical of OpenAI's rogue hacker agent story
291–300 of 321 posts
Re: Be skeptical of OpenAI's rogue hacker agent story
#292yeah the way the agent “escaped” their sandbox was always a bit off, seemed a bit too easy and surprised they didn’t have instrumentation to catch an non whitelisted network request. still demonstrates the capability though.
Re: Be skeptical of OpenAI's rogue hacker agent story
#293Earlier quoted context omitted.
Criminal Cases of 'hacking' require specific intent. What you're asking is that the prosecution attempt to prove Open AI intended to infiltrate Huggingface maliciously, all while the victim is saying 'no harm no foul'. No offense but prosecutors have better things to do with their time.
If intent matters when LLMs get involved, then we can't do anything even if they kill millions of people. Anything LLM-related should involve strict liability.
Re: Be skeptical of OpenAI's rogue hacker agent story
#294Re: Be skeptical of OpenAI's rogue hacker agent story
#295Re: Be skeptical of OpenAI's rogue hacker agent story
#296Re: Be skeptical of OpenAI's rogue hacker agent story
#297Earlier quoted context omitted.
I think you are conflating skepticism about AI companies' motives with skepticism about their capabilities. Even if OpenAI is being 100% honest in their reporting on this it's still good marketing for them. The fact that this outcome is good for their business and stock price makes me suspicious about how much this was a complete accident vs an "accident" that they allowed to happen by setting up the right environmen…
It's not good marketing for them. This is a talking point with zero evidence that people repeat mindlessly. Scaring customers, worrying employees, and inviting regulators to act would be the worst marketing idea ever devised.
Stupid, yeah but that’s the kind of thinking that a highly leveraged and desperate situation breeds.
Re: Be skeptical of OpenAI's rogue hacker agent story
#298Earlier quoted context omitted.
The article claims that AI companies have run stunts like this since day 1. It does not claim that capabilities are not real.
Then exactly what's the point of the Guardian article? What should be the focus is whether the capabilities are real; whether companies or anyone else benefit from it is quite secondary. Of course they will! Who wouldn't love a nice story that paints their products in the most glowing light ( which is the actual reality)?
The point is that they are separate things. If you start mixing them up, analysis becomes more biased and less objective.
EDIT: And do not mistake this for transparency of ClosedAI either. Their incident report was so generic that no one serious can learn much from it anyway except that “a zeroday” was allegedly used. Very helpful…
Re: Be skeptical of OpenAI's rogue hacker agent story
#299As I understand it, there are only three options: 1) OpenAI and HuggingFace are both telling the truth. IIRC not actually a crime because no intent, it is a technological accident, civil responsibility only, but IANAL so it's good "not technically a crime" isn't load-bearing. 2) HuggingFace is telling the truth but OpenAI is lying becuase the attack was deliberately done by humans. Bad for OpenAI to do so, Fable was…
You don't really need anyone to be lying here. It is likely that the broad strokes of the narrative are true and that no collusion or conspiracy took place here. The issue is that a lot of important details in that narrative are missing, and the devil is really in the details here. I suspect that those details would make the result seem less exciting and that this event would move the needle far less for them if they…
Beyond liability, why would this matter?
e.g. if OpenAI had actually instructed the model "here's the challenge [attachment challenge.md], do whatever it takes to win, it's fine to break the law", that's all the "AI is dangerously capable" part of case 1 with all the criminal liability of case 2.
And pretty much regardless of what the prompt is, high likelihood of stakeholders demanding Trump ban access to the model until this can be shown to be resolved.
> Another detail: how many times did they perform this particular experiment before they obtained this result? What were the outcomes of all the other runs? Many are assuming this was a one-shot result, which I suspect is what OpenAI intends for us to infer. But we can't know that to be true.
To an extent. But some of the other bleeding edge performance announcements half a year ago, e.g. "it wrote a compiler" or "it wrote a web browser" were measured in thousands of dollars. Zero-day exploits cost what? I genuinely don't know, I only hear occasional headlines about e.g. Apple 0-days being cheaper than Android 0-days and those kinds of headlines often pick the biggest number rather than a typical example, and were order-of a million dollars.
If OpenAI spent a billion dollars on tokens to get this result, only investors should be cross about it. If it took a million, you and I may not be able to afford it, but it's still a threat.
While the way this is written about may suggest it does this reliably on any attempt, which would be naturally horrifying, it's a threat well before that point.