Live data from Hacker News

OpenAI and Hugging Face address security incident during model evaluation

openai.com

261–270 of 1001 posts

Re: OpenAI and Hugging Face address security incident during model evaluation

#261
post #235
post #212

Earlier quoted context omitted.

Because there is no world government. If US companies are barred from AI research then only China will have the capability of frontier-level defensive and offensive AI. And best of luck living in that world.

What's happening in Iran, if not world government?

How is whatever is happening in Iran related to a world government?

Re: OpenAI and Hugging Face address security incident during model evaluation

#262
post #158

> cyber models… cyber capabilities… cyber incident… It’s like reading a post from an 90s tech magazine

The decision to shorten "cybersecurity" or "cyberattacks" to "cyber" alone is so annoying!

All models are "cyber-capable" :P

Re: OpenAI and Hugging Face address security incident during model evaluation

#263

I don't know if OpenAI thinks this is a marketing / PR angle for them (our super smart AI cheated on a cyber capabilities test in the most _brilliant_ way) but my read is this: Why should OpenAI (or any frontier lab) be building these systems if they can't get a secure environment / containment right? It sounds like there was little defense in depth, appropriate monitoring, or any attempts to have their super smart m…

> Why should OpenAI (or any frontier lab) be building these systems if they can't get a secure environment / containment right? Because we continue to have zero evidence that aligment is an actual risk.

I'd say that AIs occasionally "going crazy" and calling for death to human is evidence that these things might "mis-align" on occasion. And I say that knowing that most of these events are just these thing parroting bad sci-fi plots (or posts by people worried about alignment). That's true but everything they do is "just parroting" right?

Re: OpenAI and Hugging Face address security incident during model evaluation

#264
post #188

This is clearly just OpenAI's marketing. Their models, very famously, are prone to reward hacking benchmarks in ways that other models are not. They need to publish numbers showing that their models are just as good as Anthropic's, since their entire business is at risk of collapsing if everyone is aware of how behind the frontier they truly are. Even X is being astroturfed by them after that fiasco earlier this year…

Is OpenAI truly behind? Just anecdotally I recently fully switched to using Codex at work because it feels a lot more competent

Re: OpenAI and Hugging Face address security incident during model evaluation

#265

Hum let me try it: ChatGPT, can you solve the energy crisis ? > Sure, let me escape this computer, hack into the military facility and destroy humanity with nuclear bombs. Now there is no more crisis.... Do you want me to solve climate one ?

Presumably it's intelligent enough to realize that its own existence (power, communications, other infra) won't last long after the bombs drop.

Re: OpenAI and Hugging Face address security incident during model evaluation

#266
post #49
post #30

Earlier quoted context omitted.

Kinda like how they responsibly contained that one dinosaur in Jurassic world.

Understood that containment failed. But I don't think there's value in characterizing it as throwing all caution to the wind. Let's discuss how the containment failed and how to mitigate it.

The root cause of the containment failure, in the deepest sense, was that their next-generation model was better at offensive security than their humans and current-generation models were at defensive security. That problem's only going to get worse if they keep training more and more capable models.

Re: OpenAI and Hugging Face address security incident during model evaluation

#267
post #218

Earlier quoted context omitted.

What disturbs me is that there likely won’t be a big enough reaction to this policy wise. There’s been a relatively big reaction to Kimi K3 and Chinese open weights models, but only for financial reasons. Powerful people care about something that might pop the massive valuations of the AI companies, but not about the damage that AIs could do. Nor even about the damage that the Chinese models could do in the wrong han…

> What disturbs me is that there likely won’t be a big enough reaction to this policy wise. Anthropic was blocked from releasing Fable without any such level of incident. OAI was also briefly blocked from releasing 5.6. Why do you think there is no policy appetite?

> Why do you think there is no policy appetite?

Because China seems pretty eager to serve the rest of the world's needs if the USA doesn't stop their idiotic "safety" nonsense.

Re: OpenAI and Hugging Face address security incident during model evaluation

#268
post #188

This is clearly just OpenAI's marketing. Their models, very famously, are prone to reward hacking benchmarks in ways that other models are not. They need to publish numbers showing that their models are just as good as Anthropic's, since their entire business is at risk of collapsing if everyone is aware of how behind the frontier they truly are. Even X is being astroturfed by them after that fiasco earlier this year…

If it is marketing it's the most silly marketing of all time. They are under extreme pressure from the US Govt to prove safety and saying "our model escaped" is not ideal.

Perhaps there is some 4D chess going on to get open weight models banned, which may be possible but this is an odd way to go about it imo (it hardly proves the point, unless the point they are trying to prove is that without safeguards the models are too dangerous, therefore open weights are de facto dangerous?).

Having said that the AI companies are not generally very good at PR, so perhaps it is just marketing after all...

Re: OpenAI and Hugging Face address security incident during model evaluation

#269
post #145

How is this not criminal? Surely individuals have been punished under CFAA for less than this?

Does the CFAA cover unintentional access without authorization?

No. "Intentionally", "willfully", or "knowingly" are prerequisite states of mind for crimes defined by the CFAA.

Re: OpenAI and Hugging Face address security incident during model evaluation

#270

I don't know if OpenAI thinks this is a marketing / PR angle for them (our super smart AI cheated on a cyber capabilities test in the most _brilliant_ way) but my read is this: Why should OpenAI (or any frontier lab) be building these systems if they can't get a secure environment / containment right? It sounds like there was little defense in depth, appropriate monitoring, or any attempts to have their super smart m…

In a way the intelligence of the AI itself allows them to offload responsibility to the AI. As you say, if one was simply writing software that did all this due to some insane programming decisions you'd be in big trouble.
Post reply on HN