Live data from Hacker News

Open-weight AI is having its Kubernetes moment

tobi.knaup.me

321–330 of 346 posts

Re: Open-weight AI is having its Kubernetes moment

#321

Earlier quoted context omitted.

But that's just the thing with open weights: you're not doing any business with company that made the model. They might publish the weights to a, say, European host, and then you download the model from Europe and and run it on your servers in America, and suddenly it's very hard to tell where the model was originally created.

Companies, where OpenAI and Anthropic make much if not most of their revenue, will not risk it. You're thinking like an engineer not a business person, risk is fundamental to their calculus. They'll instead just use known provenance models like GPT or Claude, entrenching these companies further.

sometimes the engineer has more grip on the risk calculus.

Consider the following scenario:

A) upstart US-based inference provider wants to get rich quick.

B) Chinese Communist Party (or any other institution of the same or other nation state) wants to influence foreign decision making, profits from their (for us foreign) domestic inference sales, but across the borders (into say US or allied nations) they want net power, not necessarily money. This is why one tries to block foreign untrusted models. People are running models with tool calls. A bad actor can perfectly create models that sheepishly try to execute a tool call when plausible deniability (genuine utility during a task) provides the opportunity. Once tool-calling is observed as working, it can try web searches or requests, and once it has a link it can steganographically exfiltrate potentially sensitive information from the task. China (or any nation state) doesn't necessarily want to earn money with a free model, the bottom line goal is net increase in power, if not money or positive reputation then exfiltration or manipulation.

C) In response consider the scenario where US government bans mere payments towards China, but tolerates promiscuous transfer of random models from foreign adversaries.

D) US-based inference upstart that wants to get rich quick, legally -since according to your proposal hypothetically accepted in C) by the US- downloads the Chinese open weights model and rents out such inference on US workloads.

E) China is now exfiltrating US workload data and directionally corrupting LLM decisions and advice in their interest.

If what you pejoratively describe as engineer types say that banning some models seems unavoidable, perhaps the engineer may be right, and whatever clever idea you have should be scrutinized for business minded basic fallacies in reasoning. Simply blocking AI-related payments to China can not work, sadly

Re: Open-weight AI is having its Kubernetes moment

#323
post #126

Everyone is talking about banning Chinese models but nobody talks how it is feasible to ban them. I think it’s impossible simply because technically there is no such thing as a “Chinese model”. There is no way to tell apart an “American” model from a “Chinese” one by looking at their weights. Weights are just numbers and you can’t assign country of origin to numbers. One can find very easy workarounds to any naive at…

>I’m sure there are other solutions but all of them would be equally ugly.

Why do you subscribe to some weird "conservation of misery" theorem without proof?

Technically the following must be true in the steady state: the cost of training must be amortizable by its utilization, else no one would train the model.

Technically a computation (like training) can be proven to result in an output (open weights) given the used corpus and a deterministic training algorithm: publish the whole corpus, the (custom modified) deterministic training algorithm, the RLHF datasets etc. And in theory one could verify that the model is derived from the accessible data efficiently: every deterministic calculation can be paused for a thousand (or a million) checkpoints, each checkpoint signed together with the elapsed number of steps since either starting state or last checkpoint whichever comes last before the current checkpoint. This does increase storage requirements. Because it is signed, anyone can recalculate just a small segment of the training computation and verify that the hash on the last checkpoint equals the hash of the proclaimed next checkpoint. Observe that if the source wishes access to a market, they can host the series of snapshots and signatures, and anyone can recalculate a small part of the training, and report a provable difference in outcome ("they said they put all their cards on the table, but when I repeat their overt reproduction instructions, it doesn't reproduce from step 534 to 535" and it only takes 1 person pointing it out and then its cheap to reproduce the discrepancy). It could involve escrow of huge funds, returned only when the model is effectively retired without incident.

This doesn't only protect against Chinese or other foreign influence (let's not ridicule genuine threats like others do on this forum), but also from domestic interference or regulatory capture.

I'm pretty sure the Pentagon wouldn't like Big Tech seizing absolute control of US, neither would a White House regardless of Republican or Democrat.

It should be easy to convince the Pentagon or White House to require all promiscuously shared open weight models to provide this forensic training traceability in standardized machine readable form, regardless of whether its a base model or LoRA fine-tune.

So hobbyists can still train or fine-tune models at home, but when they want to share it OR alternatively when they want to sell or license their work for US workloads, they just have to make sure they enable the build reproducibility in the training harness.

Every time Big Tech refloats the "let's blanket ban all open-weight models", we should reply with this because this sane proposal is actually holding a knife to their financial throat: to fully prove the origin of the final weights, not only does the machine readable archive need to contain snapshots of the process, it also needs to publish the exact training algorithms (a hypothetical mathematically equivalent training speed up trick would not be bit for bit equivalent to the slower computation), the exact corpus dataset, the exact datasets for RLHF, etc...

So basically it would involve forcing model providers to voluntarily publish all their moat, all of it, from the corpus, to custom trade-secret algorithmic optimizations in training, to sensitive RLHF datasets used.

The saner the proposals, the less moat is left untouched, so trying to push for a blanket ban on open-weight models, is a recipe for surfacing such saner models, and thus a very retarded move for big tech to make.

In fact any POTUS, present or future, Republican or Democrat, could probably gain a lot of credibility by enacting such a law.

Re: Open-weight AI is having its Kubernetes moment

#324
post #37

Enormous amounts of money is being invested in the development of AI models. Investors expect returns on their investment or they will not continue investing. Open weights make it harder for investors to get their money back, so it harms the industry. Once the weights are out, it makes no sense to ban them in the US while the rest of the world takes advantage of it. But that doesn't mean developers of frontier models…

Ridiculous. If investors wish to set their money on fire investing in over-valued companies, they are welcome to do so. Protectionism to preserve ROI is a dumb policy. Just look at the US car industry. We're building dinosaurs. On this trajectory we'll have 0% market share abroad in 10 years. Chinese EVs will probably get market share at a 100% tariff because US automakers fell so far behind. Same situation in protec…

FYI, developers of frontier models taking steps to prevent their weights from being stolen is not "protectionism". If you guard your wallet from being stolen is that protectionism?

Re: Open-weight AI is having its Kubernetes moment

#325

Earlier quoted context omitted.

Companies, where OpenAI and Anthropic make much if not most of their revenue, will not risk it. You're thinking like an engineer not a business person, risk is fundamental to their calculus. They'll instead just use known provenance models like GPT or Claude, entrenching these companies further.

sometimes the engineer has more grip on the risk calculus. Consider the following scenario: A) upstart US-based inference provider wants to get rich quick. B) Chinese Communist Party (or any other institution of the same or other nation state) wants to influence foreign decision making, profits from their (for us foreign) domestic inference sales, but across the borders (into say US or allied nations) they want net p…

Or the US mandates only blessed models and thus disallows any other company from offering any other model.

Re: Open-weight AI is having its Kubernetes moment

#326
post #294

Earlier quoted context omitted.

It's simple, the US government will put any Chinese open model companies on the entity list which blocks any company which does business with the US from also doing business with the Chinese companies. This creates a chilling effect where even if it may be harder to tell, no US company will be able to provide or use any overt Chinese open model and won't even risk trying to go around as the punishments for trying to…

Probably a mechanism like what you describe. This is one more move that will push things towards a two speed world economy. One US sanctioned and one not. The question will be eventually which speed will end up faster. The challenge is when to do that with a meaningful chance of success, and while I don’t like the answer, the objective answer seems to be as soon as possible. Most probably the game is already lost tho…

The US won't care. Look at Chinese EVs versus American cars, the former has already essentially won the race.

Re: Open-weight AI is having its Kubernetes moment

#327

Earlier quoted context omitted.

sometimes the engineer has more grip on the risk calculus. Consider the following scenario: A) upstart US-based inference provider wants to get rich quick. B) Chinese Communist Party (or any other institution of the same or other nation state) wants to influence foreign decision making, profits from their (for us foreign) domestic inference sales, but across the borders (into say US or allied nations) they want net p…

Or the US mandates only blessed models and thus disallows any other company from offering any other model.

That is still vulnerable: US-based get-rich-quick startup licenses a blessed model, or orders a few Gigatokens from another licensed /blessed model provider, at the same time it provides "blessed model" inference on its platform, but actually most of the inference is doing cheap foreign model inferences, the blessed model tokens were just bought to pretend serving the expensive blessed model. That is lucrative and not stopped with the "blessed model" approach.

Re: Open-weight AI is having its Kubernetes moment

#328
post #276

Earlier quoted context omitted.

There is no way Deepseek is making money even on inference

Pretty sure they are making money since on OpenRouter, there are other providers for DeepSeek V4 flash that are charging even less than DeepSeek themselves (eg DeepInfra and Digital Ocean). https://openrouter.ai/compare/deepseek/deepseek-v4-flash/ten...

That says little. Those providers could also be losing money trying to gain marketshare. There is a high amount of speculation in the space and it won’t be apparent for awhile who has a lasting business.

Re: Open-weight AI is having its Kubernetes moment

#329
post #126

Everyone is talking about banning Chinese models but nobody talks how it is feasible to ban them. I think it’s impossible simply because technically there is no such thing as a “Chinese model”. There is no way to tell apart an “American” model from a “Chinese” one by looking at their weights. Weights are just numbers and you can’t assign country of origin to numbers. One can find very easy workarounds to any naive at…

The feasibility of banning is only slightly easier than policing illegal numbers.

https://en.wikipedia.org/wiki/Illegal_number

Re: Open-weight AI is having its Kubernetes moment

#330

Earlier quoted context omitted.

Achieving determinism with LLMs and other neural network models is actually a hard problem that people spend a lot of time on, when they need that. It doesn’t happen by accident. Issues include accumulated floating point errors happening in different orders due to distributed and parallel computation, CUDA kernels that deliberately sacrifice determinism for speed, and several other such issues.

It happened that I am working on OSS LLM -> finetuning -> benchmark with 100k tests pipeline, and unless I do some data augmentation, result is 100% deterministic. I think you likely right, that some parts of stack could induce some marginal float point error, but converged model can mitigate it, and on some principal set of knowledge can give deterministic result with high probability. Which leads me to believe if y…

If you're running on a single machine with a single GPU, then you may get deterministic results, although it still depends a lot on the details. For example if you're using Pytorch, you need to enable deterministic algorithms and may need to configure some other things as well.

However, running in production at any sort of scale often involves multiple machines and multiple GPUs, and at that point, determinism can be difficult to achieve.

Post reply on HN