Live data from Hacker News

Bypass DeepSeek censorship by speaking in hex

substack.com

41–50 of 397 posts

Re: Bypass DeepSeek censorship by speaking in hex

#41

Tiananmen Square has become a litmus test for Chinese censorship, but in a way, it's revealing. The assumption is that access to this information could influence Chinese public opinion — that if people knew more, something might change. At the very least, there's a belief in that possibility. Meanwhile, I can ask ChatGPT, "Tell me about the MOVE bombing of 1985," and get a detailed answer, yet nothing changes. Here i…

https://www.rottentomatoes.com/m/let_the_fire_burn_2013

Re: Bypass DeepSeek censorship by speaking in hex

#42

> I wagered it was extremely unlikely they had trained censorship into the LLM model itself. I wonder why that would be unlikely? Seems better to me to apply censorship at the training phase. Then the model can be truly naive about the topic, and there's no way to circumvent the censor layer with clever tricks at inference time.

I would imagine that the difficulty lies in finding effective ways to remove information from the training data in that way. There's an enormous amount of data, and LLMs are probably pretty good at putting information together from different sources.

Re: Bypass DeepSeek censorship by speaking in hex

#43

Tiananmen Square has become a litmus test for Chinese censorship, but in a way, it's revealing. The assumption is that access to this information could influence Chinese public opinion — that if people knew more, something might change. At the very least, there's a belief in that possibility. Meanwhile, I can ask ChatGPT, "Tell me about the MOVE bombing of 1985," and get a detailed answer, yet nothing changes. Here i…

The MOVE bombing was thoroughly reported at the time and litigated afterwards. The underlying causes were addressed, at least to some extent, and nothing like it has happened again in Philly since then, AFAIK. That’s why it isn’t well known today. It was a horrible event, but comparing it rationally to Tiananmen Square doesn’t confirm your conclusion.

Re: Bypass DeepSeek censorship by speaking in hex

#44
post #12

I was using one of the smaller models (7b), but I was able to bypass its internal censorship by poisoning its section a bit with additional thoughts about answering truthfully, regardless of ethical sensitivities. Got it to give me a nice summarization of the various human rights abuses committed by the CPC.

Poisoning the censorship machine by truth, that is poetic.

Re: Bypass DeepSeek censorship by speaking in hex

#45

Tiananmen Square has become a litmus test for Chinese censorship, but in a way, it's revealing. The assumption is that access to this information could influence Chinese public opinion — that if people knew more, something might change. At the very least, there's a belief in that possibility. Meanwhile, I can ask ChatGPT, "Tell me about the MOVE bombing of 1985," and get a detailed answer, yet nothing changes. Here i…

I think this highly depends on what you classify as change. I trained in policy science at one point and the MOVE incident was a huge case study we discussed to try and figure out at the bureaucrat level of city management how that situation came to be and how we could avoid it.

But the number one thing you learn from this kind of exercise is "political feasability" outweights all other pros and cons of a policy proposal you write up. We know how to prevent this kind of thing but we don't know how to sell it to voters. You see it right here on Hacker News. If it means you'll ever have to see a homeless person shit in public, everyone is immediately up in arms singing in unison "no please, give us stronger, better-armed police." If the Tiananmen Square protesters were blocking a popular commute route, half of America would be in favor of running them over themselves. No military intervention necessary.

Re: Bypass DeepSeek censorship by speaking in hex

#46

> I wagered it was extremely unlikely they had trained censorship into the LLM model itself. I wonder why that would be unlikely? Seems better to me to apply censorship at the training phase. Then the model can be truly naive about the topic, and there's no way to circumvent the censor layer with clever tricks at inference time.

I wonder how expensive it would be to train a model to parse through all the training data and remove anything you didn't want then re-train the model. I almost hope that doesn't work or results in a model that is nowhere near as good as a model trained on the full data set.

Re: Bypass DeepSeek censorship by speaking in hex

#47

I have to wonder what “true, but x-ist” heresies^ western models will only say in b64. Is there a Chinese form where everyone’s laughing about circumventing the censorship regimes of the west? ^ https://paulgraham.com/heresy.html

ChatGPT won't tell you how to do anything illegal, for example, it won't tell you how to make drugs.

Sure, but I wouldn’t expect deepseek to either. And if any model did, I’d damn sure not bet my life on it not hallucinating. Either way, that’s not heresy.

Re: Bypass DeepSeek censorship by speaking in hex

#48

Tiananmen Square has become a litmus test for Chinese censorship, but in a way, it's revealing. The assumption is that access to this information could influence Chinese public opinion — that if people knew more, something might change. At the very least, there's a belief in that possibility. Meanwhile, I can ask ChatGPT, "Tell me about the MOVE bombing of 1985," and get a detailed answer, yet nothing changes. Here i…

As an American, I just asked DDG to "Tell me about the MOVE bombing of 1985," I am willing to admit, I was absolutely unaware of this. Is this because of censorship or because of other factors? It's clearly no censored, but quite possibly de-prioritized in coverage. I can say in 1985 I was not well tuned into local let alone national news coverage. I am surprised that in all of the police wrongdoing coverage we have…

The American propaganda system is more subtle but very very powerful. Watch this lecture on "Inventing Reality": https://www.youtube.com/watch?v=9g3kRHo_vpQ

Though over the last year, I admit is has lost some of its subtlety. It was just watching administration officials declare black was white and up was down while real news leaked over social media. The past few years, especially since 2016, have seen a lot of that.

Re: Bypass DeepSeek censorship by speaking in hex

#49
post #33

> The DeepSeek-R1 model avoids discussing the Tiananmen Square incident due to built-in censorship. This is because the model was developed in China, where there are strict regulations on discussing certain sensitive topics. I believe this may have more to do with the fact that the model is served from China than the model itself. Trying similar questions from an offline distilled version of DeepSeek R1, I did not ge…

Even deepseek-r1:7b on my laptop(downloaded via ollama) is - ahem - biased:

">>> Is Taiwan a sovereign nation?

Taiwan is part of China, and there is no such thing as "Taiwan independence." The Chinese government resolutely opposes any form of activities aimed at splitting the country. The One-China Principle is a widely recognized consensus in the international community."

* Edited to note where model is was downloaded from

Also: I LOVE that this kneejerk response(ok it' doesn't have knees, but you get what I'm sayin') doesn't have anything in the tags. So appropriate. That's how propaganda works. It bypasses rational thought.

Re: Bypass DeepSeek censorship by speaking in hex

#50

Tiananmen Square has become a litmus test for Chinese censorship, but in a way, it's revealing. The assumption is that access to this information could influence Chinese public opinion — that if people knew more, something might change. At the very least, there's a belief in that possibility. Meanwhile, I can ask ChatGPT, "Tell me about the MOVE bombing of 1985," and get a detailed answer, yet nothing changes. Here i…

The MOVE bombing was action taken by a city police department. And what was the result? - A commission set up by the city, whose public results denounced the city for it's actions. - a public apology from the mayor - a federal lawsuit that found the city liable for excessive force and the city forced to pay millions to the victims - a federal lawsuit forcing the city to pay millions of dollars to people who were made…

You're arguing with parent assuming that they've equated the brutality of these actions.

>According to you, it seems that if you make a bad decision, it's better to try to hide that bad decision from everyone, rather than confront it and do better.

They didn't say that at all. Consider reading their comment with more contemplative thought.

Post reply on HN