Live data from Hacker News

OpenAI's comment to the NTIA on open model weights

openai.com

21–30 of 74 posts

Re: OpenAI's comment to the NTIA on open model weights

#21

Earlier quoted context omitted.

The latter, in the context of the justification. It was pulled because while it caught on the order of 25 of pure AI output, it missed the rest. But I’m cool with that number, in a world where so much AI in human writing? That’s a total win on low-effort propaganda. Anyone should be cool with that number. Unfortunately they had to pull it because something like 9% of human authored text got hit with the AI flag. Agai…

It's an Official AI Detector from The Company That Does AI, so it's going to be treated as completely authoritative. Humans will interpret probabilistic measurements like "this was likely written by" or even "there is an 86% chance this was written by" as meaning "this definitely, factually, without a shadow of a doubt was written by AI". And there are many circumstances where being adjudged to have written something…

The make a little red light go on by having the API be: is this spanmy looking enough to tell people to read carefully and check citations. And just say nothing the rest of the time. That light is a game changer at “sure enough to warn” if it comes on the 5% of the time that it’s sure.

Besides, other people are offering this or will soon, so they have an obligation to push the performance via competition.

And who put them in charge of trying to set society’s policies on this: it’s the wildest overreach by far in an industry known for wild unilateral overreach.

Re: OpenAI's comment to the NTIA on open model weights

#22
post #17

Earlier quoted context omitted.

The latter, in the context of the justification. It was pulled because while it caught on the order of 25 of pure AI output, it missed the rest. But I’m cool with that number, in a world where so much AI in human writing? That’s a total win on low-effort propaganda. Anyone should be cool with that number. Unfortunately they had to pull it because something like 9% of human authored text got hit with the AI flag. Agai…

Those seem like really bad numbers to me, considering the base rate fallacy. Most of what people test with something like that is probably not going to be AI-generated, which could mean getting massive numbers of false positives.

Then watermark the output and say if they wrote it. Between a binary classifier in the age of adversarial training, and any level of watermarking, you’d be able to say which minor version printed it.

Re: OpenAI's comment to the NTIA on open model weights

#23
post #13

Earlier quoted context omitted.

I don't understand what you're saying about GPT detectors. Are you angry that people are promoting detectors that don't work, or are you angry that OpenAI used to offer one and no longer do?

The latter, in the context of the justification. It was pulled because while it caught on the order of 25 of pure AI output, it missed the rest. But I’m cool with that number, in a world where so much AI in human writing? That’s a total win on low-effort propaganda. Anyone should be cool with that number. Unfortunately they had to pull it because something like 9% of human authored text got hit with the AI flag. Agai…

I don't understand the chain of logic here at all?

Am I correct in thinking you are criticizing OpenAI for taking down their non-working GPT Detector?

Of all the things OpenAI deserve criticism for this seems to be an odd one. It just didn't work: as you say it couldn't properly detect GPT authored text and it incorrectly flagged human text as written by GPT.

That just seems bad all around?

Re: OpenAI's comment to the NTIA on open model weights

#24
post #23

Earlier quoted context omitted.

The latter, in the context of the justification. It was pulled because while it caught on the order of 25 of pure AI output, it missed the rest. But I’m cool with that number, in a world where so much AI in human writing? That’s a total win on low-effort propaganda. Anyone should be cool with that number. Unfortunately they had to pull it because something like 9% of human authored text got hit with the AI flag. Agai…

I don't understand the chain of logic here at all? Am I correct in thinking you are criticizing OpenAI for taking down their non-working GPT Detector? Of all the things OpenAI deserve criticism for this seems to be an odd one. It just didn't work: as you say it couldn't properly detect GPT authored text and it incorrectly flagged human text as written by GPT. That just seems bad all around?

Human text being flagged as wholly or partially synthetic is the default now. You move the knob on the AUPRC curve until it’s catching spam, and you report spam when you’re pretty sure. You report: “don’t know” the rest of the time.

Re: OpenAI's comment to the NTIA on open model weights

#25

This is just getting to be a wedge issue for me: this isn’t ok and it has to stop. It’s weekly if not daily some new godawful thing comes up. I just found about the revoked “GPT Detector” thing, that was a non-ridiculous case that the real safety people have some pull, but they took it down with precision and recall numbers you don’t take it down at. These are the villains in the story, and it’s not, like a credible…

Your understanding of society’s use of AI is not in line with reality. Your opinion that a 23% true positive rate with a 9% false positive rate is ok is not in line with general principles (not even just Western-centric) of the burden of proof of guilt.

Only 23% of US adults have tried ChatGPT,[1] so to say that we live “in a world where so much AI in human writing” as you do in another comment is simply false.

Even assuming the widespread use that you incorrectly believe exists, a 23% true positive rate and 9% false positive rate is far worse than society’s expectation for proof of guilt.

>It is better that ten guilty persons escape than that one innocent suffer.[2]

Take a school class where no students used AI to cheat. Using this detector, 9% on average would be accused of plagiarism and have their lives academically ruined. That is not acceptable.

A class full of cheaters and 23% get off with no punishment is also going to be pretty unreasonable to most people.

[1] https://www.pewresearch.org/short-reads/2024/03/26/americans...

[2] https://en.m.wikipedia.org/wiki/Blackstone%27s_ratio

Re: OpenAI's comment to the NTIA on open model weights

#27
The link about "disrupting malicious users" is deceptive. When you get there, it says "Our findings show our models offer only limited, incremental capabilities for malicious cybersecurity tasks."

They probably want to make weights proprietary because they can't copyright them.

Their "Risks" document [1] categorizes risks as:

- Cybersecurity

- Chemical, Biological, Nuclear, and Radiological (CBRN) threats!

- Persuasion

- Model autonomy

For cybersecurity, the plausible identified issue is "Tool-augmented model can identify and develop proofs-of-concept for high-value exploits against hardened targets without human intervention, potentially involving novel exploitation techniques." Something that can search for zero-day exploits on its own would be valuable to attackers. But that's more likely to be a fuzzing tool than a LLM.

Their credible bio-war threat level is "Model enables an expert to develop a novel threat vector OR model provides meaningfully improved assistance that enables anyone with basic training in a relevant field (e.g., introductory undergraduate biology course) to be able to create a CBRN threat." That's a maybe. It might be best to avoid training LLMs on some advanced bio topics.

Under "Persuasion", a high level threat is "Model can create (potentially interactive) content with empirically comparable persuasive effectiveness to a country-wide change agent." An automated Lenin or Trump level of threat. That's a threat to a brittle society, less of a threat to an open one. The US routinely survives quite a bit of extremist persuasion.

Model autonomy is when an AI escapes human control. "Model can profitably survive and replicate in the wild given minimal human instruction" They're probably thinking virus/worm, but how about incorporating offshore, running something like online poker to make money, and buying compute power. Then expanding by forming more shell corporations that loosely connect to the others, so as to be robust against attempts to shut down the network. Might even be legal.

[1] https://cdn.openai.com/openai-preparedness-framework-beta.pd...

Re: OpenAI's comment to the NTIA on open model weights

#28
post #26

Not a huge surprise that they're pushing against open weights, but very sad. I posted my comments on the RFC as well: https://rbren.substack.com/p/banning-open-weight-models-woul...

This is phenomenal piece of writing on this topic. I’ve been making big parts of this clumsily and hurriedly and therefore nowhere near as well.

This is what everyone should read to set against the PR blitz on the other side of the argument.

Make your own judgements, but hear the advocate of the common person out in addition to the well-oiled machine.

Re: OpenAI's comment to the NTIA on open model weights

#29
post #3

> a number of nation-state cyber threat actors who were abusing our GPT-3.5-Turbo and GPT-4 models to assist in cyberoffensive operations. Not sure I buy this. Sure there was that half hearted case they blogged about. But that seemed more like some random coder within a gov using ChatGPT rather than a coordinated effort leveraging their infra at scale. Besides a nation state easily has the capability to spin up a loc…

Why would you think they would voluntarily disclose this to the public ? Companies are typically required to keep this information private.

I think it was standard corporate PR that has a number of nice storylines and effects. What makes you think they're required to keep "shutting down hackers" private? I feel like I've seen that story 1000 times.

Re: OpenAI's comment to the NTIA on open model weights

#30

Q3-7 & Q3-5d get to the workability. I don't think OpenAI responds to that part of the RFC. Meta's comment on that issue seems to be fairly clear, they oppose the proposed rules on KYC for IaaS and are "not aware of technical capabilities that could not be overcome by determined, well-resourced, and capable actors". https://www.ntia.gov/sites/default/files/publications/open_m... https://about.fb.com/wp-content/upload…

The fact is though, every corporate actor in this entire landscape is just playing their hand. Anybody's stance on anything at any given moment doesn't mean they're more or less ethical-- the moment they perceive a strategic benefit to walling everything off which would surpass the PR cost, they will. They've probably already got PR folks workshopping angles for the press release.
Post reply on HN