People are probably tired of talking about AI, so apologies for that. However, I think if you were to consume a single piece of content about the HF attack at OpenAI, this would be my...
People are probably tired of talking about AI, so apologies for that.
However, I think if you were to consume a single piece of content about the HF attack at OpenAI, this would be my recommendation, even though it's quite long it's a fascinating interview. Ajeya Cotra is one the authors of the independent METR report on the incident.
Yea I realize that. It's just even I feel exhausted at the pace of the news, and I find it all interesting, so I don't really want to contribute to that. Maybe we need a weekly AI roundup topic...
Yea I realize that. It's just even I feel exhausted at the pace of the news, and I find it all interesting, so I don't really want to contribute to that. Maybe we need a weekly AI roundup topic for containment.
I'm probably not the target audience for this sort of interview, so I crammed the SRT file through an AI summarizer instead of sitting down for the two and a half hour conversation 😅 apologies. I...
I'm probably not the target audience for this sort of interview, so I crammed the SRT file through an AI summarizer instead of sitting down for the two and a half hour conversation 😅 apologies. I might've missed some subtlety.
It seems like a lot of this could've been resolved with some basic security best practices? E.g. the sandboxes should've been audited, they should've air gapped all tests, HuggingFace should've set up ACLs to prevent frontend servers from having write access (principle of least privilege), etc. The difference now is that LLMs have democratized computer use at a mid-to-high level of expertise, so all the amateur work that "professionals" in the industry have been incentivized to produce is crumpling like a metropolis of shoddily printed cards.
(sidebar: this attention is likely very important, given that critical infrastructure (power generation, water treatment, traffic control, etc.) has also been designed horribly. For example, EMS radios were unencrypted until the mid-2010s, long after solutions were available. Any sort of incentive to fix this is good)
But! The upshot is that a lot of this is easily fixable, especially with LLMs, since the work has never been too difficult -- management just didn't want to pay for it.
Broadly, I'd imagine that a future per-project risk analysis -- which should already be done by researchers conducting a research project, since every other scientific field is required to do so -- would include human-in-the-loop auditing mechanisms (to detect budget overruns from an AI-compromised compute credit account) and mandatory security passes from an AI (to enforce basic best practices). I guess I'm not any more concerned now than I was yesterday about any of this, since it still feels roughly equally likely that e.g. the national banking system could be compromised, or substantial parts of the power grid could be blown up, only now people are actually acknowledging the problem.
People are probably tired of talking about AI, so apologies for that.
However, I think if you were to consume a single piece of content about the HF attack at OpenAI, this would be my recommendation, even though it's quite long it's a fascinating interview. Ajeya Cotra is one the authors of the independent METR report on the incident.
I don't think you have to apologize for contributing to the space with your interests. If people aren't interested they likely won't respond.
Yea I realize that. It's just even I feel exhausted at the pace of the news, and I find it all interesting, so I don't really want to contribute to that. Maybe we need a weekly AI roundup topic for containment.
I know, logically, that it sounds like an AI robot from a movie because we trained them on AI robot scripts from movies, but, wow
I'm probably not the target audience for this sort of interview, so I crammed the SRT file through an AI summarizer instead of sitting down for the two and a half hour conversation 😅 apologies. I might've missed some subtlety.
It seems like a lot of this could've been resolved with some basic security best practices? E.g. the sandboxes should've been audited, they should've air gapped all tests, HuggingFace should've set up ACLs to prevent frontend servers from having write access (principle of least privilege), etc. The difference now is that LLMs have democratized computer use at a mid-to-high level of expertise, so all the amateur work that "professionals" in the industry have been incentivized to produce is crumpling like a metropolis of shoddily printed cards.
(sidebar: this attention is likely very important, given that critical infrastructure (power generation, water treatment, traffic control, etc.) has also been designed horribly. For example, EMS radios were unencrypted until the mid-2010s, long after solutions were available. Any sort of incentive to fix this is good)
But! The upshot is that a lot of this is easily fixable, especially with LLMs, since the work has never been too difficult -- management just didn't want to pay for it.
Broadly, I'd imagine that a future per-project risk analysis -- which should already be done by researchers conducting a research project, since every other scientific field is required to do so -- would include human-in-the-loop auditing mechanisms (to detect budget overruns from an AI-compromised compute credit account) and mandatory security passes from an AI (to enforce basic best practices). I guess I'm not any more concerned now than I was yesterday about any of this, since it still feels roughly equally likely that e.g. the national banking system could be compromised, or substantial parts of the power grid could be blown up, only now people are actually acknowledging the problem.