Earlier quoted context omitted.
yeah, I'm still hoping that Wikipedia remains valuable and vigilant against attacks by the radical right but its obvious that Trump and congress could easily shut down wikipedia if they set their mind to it.
you're ignoring that both sides are doing poisoning attacks on wikipedia, trying to control the narrative. it's not just the "radical right"
A small number of samples can poison LLMs of any size
271–280 of 459 posts
Re: A small number of samples can poison LLMs of any size
#272Re: A small number of samples can poison LLMs of any size
#273Re: A small number of samples can poison LLMs of any size
#274Re: A small number of samples can poison LLMs of any size
#275Re: A small number of samples can poison LLMs of any size
#276Earlier quoted context omitted.
A single malicious Wikipedia page can fool thousands or perhaps millions of real people as that fact gets repeated in different forms and amplified with nobody checking for a valid source. Llms are no more robust.
But is poisoning just fooling. Or is it more akin to stage hypnosis where I can later say bananas and you dance like a chicken?
… the articles example of a potential exploit is exfiltration of data.
Re: A small number of samples can poison LLMs of any size
#277Earlier quoted context omitted.
> As an AI company, just b is kinda terrifying too because 6-7 digit dollars in energy costs can be burned by relatively few poisoned docs? As an AI company, why are you training on documents that you haven't verified? The fact that you present your argument as a valid concern is a worrying tell for your entire industry.
AI companies gave up on verification years ago. It’s impossible to verify such intense scraping.
Re: A small number of samples can poison LLMs of any size
#278Re: A small number of samples can poison LLMs of any size
#279There is a famous case from a few years ago where a laywer using ChatGPT accidentally referenced a fictitious case of Varghese v. China Southern Airlines Co. [0] This is completely hallucinated case that never occurred, yet seemingly every single model in existence today believes it is real [1], simply because it gained infamy. I guess we can characterize this as some kind of hallucination+streisand effect combo, eve…
Of course, that does not contradict a finding that the base models believe the case to be real (I can’t currently evaluate that).
Re: A small number of samples can poison LLMs of any size
#280Note that there isn't the slightest attempt to explain the results (specifically, independence of the poison corpus size from model size) from a theoretical perspective. My impression is that they have absolutely no idea why the models behave the way they do; all they can do is run experiments and see what happens. That is not reassuring to me at least.
Only 249 to go, sorry fellas, gotta protect my future.