Live data from Hacker News

Potential session/cache leakage between workspace instances or consumer accounts

github.com

141–150 of 151 posts

Re: Potential session/cache leakage between workspace instances or consumer accounts

#141

Earlier quoted context omitted.

Exactly. If you've never had an LLM (all models) suddenly start spouting nonsense in a completely different language...you haven't been using LLMs that much. They will go absolutely insane some % of the time.

I've used LLMs quite a lot (Claude, GPT) and have never seen this behavior. You've got something else going on.

Chinese models will do that.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#142
post #22

Earlier quoted context omitted.

It'd be terribly compute inefficient to not share prefix caches (KV cache) across customers.

What is the probability that two customers will have exactly the same tokens in cache? Wouldnt it require using the exact same CLAUDE.md, skills, MCPs and context? After that it is even worse since the nondeterminism of LLMs and humans

Not only that, but thy need to have the same tokens at the same time? I just can't see how likely this is.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#144
post #80

I’ve been seeing this in Gemini in the past few days. Often during a prompt with a reasonably large input set, I’ll get answers that appear to belong to someone else. It may be trigger hallucination, but it seems like it may be cache collisions or something else. I’ve not seen anything to suggest private information is leaking, but it’s disconcerting to be researching something and then get what appears to be a math…

My whole company is doing mid year reviews and Gemini is the only allowed tool and its been flumoxing people with seemingly random unrelated responses. Often in different languages. That is when it bothers to respond instead of just sending back an 1099 error code

You just reminded me of how Copilot (also the only allowed tool at some of the orgs I do client work for) will sometimes switch to Toki Pona for no reason.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#145
post #128

Earlier quoted context omitted.

HN thinks the safety crowd is dumb, and has never seriously engaged with the AI safety space. HN doesn't believe superintelligence will be a thing; while the AI safety crowd believes they are building it. So the decisionmaking of the safety crowd is incomprehensible to HN.

What is the AI safety crowd exactly? Dont we have a thread here how the model allegedly leaks responses what is "normal" safety? (Not "agi will become skynet" safety - what is mostly a rehash of terminator 2 story)

According to their comment history, the person you're replying to believes that AGI, ASI, "superintelligence" and all of that sci-fi terminator what-have-you is not only possible, but literally inevitable. They're not worried about normal safety, they're worried about Skynet and the T-1000. American AI labs – Anthropic in particular – are apparently playing the role of Sara and/or John Connor in this story.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#146

I’ve been seeing this in Gemini in the past few days. Often during a prompt with a reasonably large input set, I’ll get answers that appear to belong to someone else. It may be trigger hallucination, but it seems like it may be cache collisions or something else. I’ve not seen anything to suggest private information is leaking, but it’s disconcerting to be researching something and then get what appears to be a math…

I’ve also had problems with Gemini when accessed through their UI in the past few weeks. That’s concerning that you are also seeing it several days later in a different context. I wonder if there could be a large security situation playing out behind the scenes right now. I’ve been working on using AI to assist me in writing meta parsing grammars. Fortunately I have not launched most of them yet. I know for a fact th…

> I wonder if there could be a large security situation playing out behind the scenes right now.

There absolutely is in the sense that Mythos via Project Glasswing has uncovered over 10,000 critical vulns and counting. I don't know that this incident is directly related, but there's a lot going on at the moment in this area.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#148

Using a throwaway account for obvious reasons, but I’m very involved in this space using LLMs from multiple providers. I’m aware of at least two instances in which the intermediate infrastructure “swapped” responses, once impacting Claude models and once impacting GPT models, from two different providers. One gave us a proper postmortem in which their API gateway was incorrectly handling HTTP 100 status codes, puttin…

I hope you reconsider your use of a throwaway account for this sort of comment—This sort of feedback and experience is very valuable and if the culture of the company you're in or the companies your working with discourage this sort of feedback, it's only going to create chilling effect that prevents more people from coming forward

Re: Potential session/cache leakage between workspace instances or consumer accounts

#149

Using a throwaway account for obvious reasons, but I’m very involved in this space using LLMs from multiple providers. I’m aware of at least two instances in which the intermediate infrastructure “swapped” responses, once impacting Claude models and once impacting GPT models, from two different providers. One gave us a proper postmortem in which their API gateway was incorrectly handling HTTP 100 status codes, puttin…

I hope you reconsider your use of a throwaway account for this sort of comment—This sort of feedback and experience is very valuable and if the culture of the company you're in or the companies your working with discourage this sort of feedback, it's only going to create chilling effect that prevents more people from coming forward

Would prefer to stick to a throwaway, sorry. It’s not that such feedback is discouraged by my company, it’s been very much escalated. However the response to these incidents had legal repercussions and my replies here aren’t subject to attorney-client privilege.

While whistleblower protections (at least used to) safeguard against government persecution, I work for a private company and don’t want my livelihood risked. I did what I could to escalate through official channels.

Re: Potential session/cache leakage between workspace instances or consumer accounts

#150
post #105

Using a throwaway account for obvious reasons, but I’m very involved in this space using LLMs from multiple providers. I’m aware of at least two instances in which the intermediate infrastructure “swapped” responses, once impacting Claude models and once impacting GPT models, from two different providers. One gave us a proper postmortem in which their API gateway was incorrectly handling HTTP 100 status codes, puttin…

Actually, it’s not obvious why you’re using a throwaway account… Every emergent behavior from these actors - whose claim to positive moral values is barely plausible - should be reported, discussed, dissected and critiqued early and often .

I like being gainfully employed, and the best position for me to push for genuine AI safety is within an influential company in the space.
Post reply on HN