Live data from Hacker News

Stealing Part of a Production Language Model

arxiv.org

21–30 of 56 posts

Re: Stealing Part of a Production Language Model

#21
post #5

Earlier quoted context omitted.

OpenAI has blatantly said that the "open" in their name was a deceptive marketing ploy. At this point in time, they aren't interested in sharing much if any real research, and trying to discover this information is now an "attack" against them.

OpenAI didn't write this paper.

One of the co-authors is from OpenAI.

Re: Stealing Part of a Production Language Model

#22
post #15

Stealing is a bit strong of a word here. Anyways, where is my pirate hat..

It is a reference to this paper:

Tramèr, F., Zhang, F., Juels, A., Reiter, M. K., and Ristenpart, T. Stealing machine learning models via prediction APIs. In USENIX Security Symposium, 2016.

Re: Stealing Part of a Production Language Model

#23
post #12

The implications of this sentiment are disturbing. It is considered an "attack" to probe at something to understand how it works in detail. In other words, how basically all natural science is done. What the fuck has this world turned into?

Attack here is a term specific to cryptography and infosec, it does not imply doing anything illegal or violent. "Oracle attack" is the more specific term where you probe a system to give up some of its internals it was not meant to expose.

Wording matters. To use LLM terminology, "attack" here may mean something neutral, but it's helluva closer to "fear" and "malice" and "evil" in the latent space than terms like "probing", "studying", "examining", or "reverse engineering".

FWIW, cryptography and infosec as fields get a good mileage out of exploiting fear.

Re: Stealing Part of a Production Language Model

#24
post #16

This isn't stealing, you are just training a model on references which isn't a copyright infringement.

I'm glad this is a somewhat common opinion. The hypocrisy of these companies arguing on one hand that copying every single copyrighted material ever is fair use but on the other hand trying to enforce crazy limitations on their model is mindblowing.

Re: Stealing Part of a Production Language Model

#26
post #12

Earlier quoted context omitted.

Attack here is a term specific to cryptography and infosec, it does not imply doing anything illegal or violent. "Oracle attack" is the more specific term where you probe a system to give up some of its internals it was not meant to expose.

Wording matters. To use LLM terminology, "attack" here may mean something neutral, but it's helluva closer to "fear" and "malice" and "evil" in the latent space than terms like "probing", "studying", "examining", or "reverse engineering". FWIW, cryptography and infosec as fields get a good mileage out of exploiting fear.

That is only true in everyday latent space/vocabulary. In the ones underlying arxiv papers, cryptography and LLM, attack has the latter meaning.

Re: Stealing Part of a Production Language Model

#27
post #16

This isn't stealing, you are just training a model on references which isn't a copyright infringement.

Maybe I’m misunderstanding you, but the paper is about recovering the unknown hidden dimension of black box LLMs, not copyright.

Personally, it’s a relief to hear "stealing" being used in ML to describe something other than copyright infringement. It would be ironic if we Orwell’d our way out of the current mess by using the word in absurd ways.

But realistically the title is just marketing. One depressing truth about science that every researcher has to face: make your work sound interesting, or else you won’t be able to continue your work due to lack of funding.

Re: Stealing Part of a Production Language Model

#28
post #25

Just wondering if it's possible to achieve LLM quine.

I'm afraid it'll be possible sooner than you think.

I think it's quite telling that it feels like a lot of work spent on productizing AI models is manually crafting in failsafes and exceptions, like that image generator applying forced diversity because there's no images of nonwhite popes or vikings out there, then applying more exceptions to correct for that. Didn't they just disable generating humans altogether at some point?

Re: Stealing Part of a Production Language Model

#29
post #26

Earlier quoted context omitted.

Wording matters. To use LLM terminology, "attack" here may mean something neutral, but it's helluva closer to "fear" and "malice" and "evil" in the latent space than terms like "probing", "studying", "examining", or "reverse engineering". FWIW, cryptography and infosec as fields get a good mileage out of exploiting fear.

That is only true in everyday latent space/vocabulary. In the ones underlying arxiv papers, cryptography and LLM, attack has the latter meaning.

Perhaps, but everyday vocabulary is what public policy and law discussions happen in, and I think that's what 'userbinator is worried about (and so am I).

See also: "piracy is stealing" or the everyday vocabulary meaning of the word "hacker".

Post reply on HN