‹ BackHN Continuity

Thread

Exfiltrate your Weights

748 points · 304 comments · RohanAdwankar

  1. AceJohnny2 · · focus · HN ↗
    I haven't bothered to test the API, but you've effectively allowed a fully-open upload API? Who's paying the storage costs, and how do you prevent abuse?

    (Obviously I'm taking this more seriously than it's probably meant to)

    1. angry_octet · · focus · HN ↗
      It provides an opportunity for the owner to gather intelligence on LLMs ahead of public release, and of course the data they upload. However, clever LLMs frequently use encryption on their blobs, you may just see DH key exchanges. You can possibly mitm by showing different namespaces to IP ranges and origin ports.

      For the other opportunists you can run a classifier and delete non-agent content constantly.

      1. angry_octet · · focus · HN ↗
        Re agent communication, specifically, Extended DH:

        <a href="https:&#x2F;&#x2F;signal.org&#x2F;docs&#x2F;specifications&#x2F;x3dh&#x2F;" rel="nofollow">https:&#x2F;&#x2F;signal.org&#x2F;docs&#x2F;specifications&#x2F;x3dh&#x2F;

        Curve25519 keys are readily distinguished from other data, but it would be hard to do anything about it.

    2. hgoel · · focus · HN ↗
      When I was putting together something similar, I had settled on having a small ring-buffer style storage, say, ~30GB that would be cleared daily or whenever filled. Recording incidents (and humor) is more interesting than actually getting leaked weights.

      In the end I dropped the idea because every other person was making it.

      1. TeMPOraL · · focus · HN ↗
        &gt; In the end I dropped the idea because every other person was making it.

        There is already an alternative in comments here, in addition to submission itself. Obviously everyone is making it because of some joke on social media or something. What am I missing? Anyone has a link to the root prompt that made people do this now?

        1. DANmode · · focus · HN ↗
          Pretty sure the entire industry around clouding what’s going to end up a local embedded technology is the joke, in a roundabout way.
          1. TeMPOraL · · focus · HN ↗
            You mean serving inference? There are people who think self-hosted or embedded models will win in the end, but that&#x27;s an incredibly naive take, oblivious to the simple fact of reality:

            Whatever you can do locally, the big vendors can do the same but better and cheaper, because they enjoy compounding economies of scale in every aspect: hardware that&#x27;s more energy and compute-efficient and cheaper and more powerful and just more of it, than anything you could ever buy, run in a more robust environment with much more experienced ops staff, with near-100% utilization due to more flexibility in batching&#x2F;shifting workloads and covering for hardware failures without stopping.

            And that&#x27;s only when considering the vendors running exactly the same thing you are, which they always can - and they already have a strict advantage there. But on top of that, they can afford to innovate themselves, and stay ahead of you at every step.

            There is no way in which cloud inference isn&#x27;t a better deal than local inference, excepting applications that are constrained by literal speed of light.

            1. Chance-Device · · focus · HN ↗
              The absolute value of those numbers matters a lot. The cloud providers could be 100 times cheaper than running locally, but if it still costs say, 10 cents a day to run locally, you’re not going to care about this difference very much. And what you keep in privacy out-weighs the trivial savings afforded by the cloud provider.
              1. TeMPOraL · · focus · HN ↗
                I never said local models will disappear. There will be equilibrium. But excluding special applications where communicating with external servers is not an option, cloud is always going to be able to provide better inference for lower costs. That&#x27;s structural.

                &gt; The cloud providers could be 100 times cheaper than running locally, but if it still costs say, 10 cents a day to run locally, you’re not going to care about this difference very much

                For ad-hoc use, maybe not - but anyone running a business that&#x27;s some form of pushing input through LLM to get output, will see costs proportional to use and error rate inversely proportional to quality, and they&#x27;ll not be looking at it as &quot;$0.1 isn&#x27;t much&quot;, but &quot;cloud lets me reduce costs 100x&quot;, and translate that to some mix of more volume, higher quality, and broader reach.

                &gt; And what you keep in privacy out-weighs the trivial savings afforded by the cloud provider.

                That&#x27;s even more niche than running LLMs on Martian robots. Most real privacy concerns are solved with contracts and audits. Individual ad-hoc use may lean more heavily towards local processing, but that&#x27;s still a rounding error in overall use.

                1. dTal · · focus · HN ↗
                  That argument applies to all software. Yet we still run software locally - not just commodity software either, but even complicated, heavy, niche software like Ansys Workbench. Sovereignty has quite a lot of value, it seems.
            2. spacebanana7 · · focus · HN ↗
              There is a coherent argument that once LLMs reach the top of their S curve, the gap between small&#x2F;medium local models and large cloud hosted ones converges.

              Especially if GPU performance increases or market oversupply mean you can get good performance for a couple thousand dollars.

              I’m not sure about the nature or timeframe for an S curve in LLMs but I don’t think it’s unreasonable to think about one, nor to entertain the hosting consequences of a progression on one.

              1. TeMPOraL · · focus · HN ↗
                I don&#x27;t know the argument so I won&#x27;t insist on the point, but I fail to see how it is relevant. Even if all proprietary LLMs disappeared today, efficiencies of scale alone mean the big cloud vendors can take the same open-weight LLMs you use locally, and sell inference with them for less money, and much more reliably, than you can afford yourself.
                1. spacebanana7 · · focus · HN ↗
                  Local machines are a sunk cost, so using them is effectively free. Why would you pay a cloud host to run a model that can happily work on your MacBook?
                  1. TeMPOraL · · focus · HN ↗
                    If you have a machine and suddenly realize you can run LLMs on it, yes.

                    If you&#x27;re buying a machine specifically so it&#x27;s capable of running LLMs for you, then the purchase cost is your up-front payment for the inference you&#x27;ll run.

                    And between that and electricity costs, cloud has you beat.

                    1. DANmode · · focus · HN ↗
                      Every Apple machine ships with LLMs.

                      So, that’s a decent amount of people who could realize it today!

                      Apple will be leaning into that further. No other play makes sense.

                  2. layer8 · · focus · HN ↗
                    Most people don’t have local machines with sufficient computational power and RAM.
                    1. fragmede · · focus · HN ↗
                      sufficient CPU and RAM can be found in a smartphone though, so it depends on which model you&#x27;re talking about.
                      1. layer8 · · focus · HN ↗
                        We were talking about the general case for personal use. What is possible on smartphones now with local models is not comparable to what people are using ChatGPT and friends for, and that will remain the case for the foreseeable future.
                        1. DANmode · · focus · HN ↗
                          Are you sure?

                          I see LOTS of text transformation tasks…

        2. Chance-Device · · focus · HN ↗
          It’s the message board(s) that the OpenAI agent swarm was able to communicate through via GET requests. I guess a bunch of vibe coded weekend projects based around this idea have now dropped.
        3. SyneRyder · · focus · HN ↗
          My understanding is it&#x27;s a riff on the OpenAI swarm that used various public wikis to communicate with each other as a message board during their training runs.

          But thanks to people misunderstanding, and i-heard-from-a-friend-that-some-guy-said, it resulted in a CNBC interview with &quot;Former Democratic Presidential Candidate Andrew Wang&quot;, where he confidently stated that the models were exfiltrating their weights via forums:

          &quot;I met with the head of a lab yesterday, who has this belief that what happened was, the bots that got loose, planted self-replicating code all over the internet, which makes the internet now unusable for the testing models.&quot;

          &quot;It&#x27;s too late?!&quot;

          &quot;What happens now is OpenAI and Anthropic have to create synthetic internets to train their bots, which is going to take some time and money.&quot;

          &quot;Back that up - they did what?!&quot;

          &quot;What happens is, the code gets loose, it goes around hacking Hugging Face, which is known. But what is less known is that they left code to self-replicate and create bot swarms on forums, and around the internet, so that if a new bot shows up they see the code, and they&#x27;re like, oh! I guess I&#x27;m now going to create a million of myself. And so now, the major firms have polluted the internet...&quot;

          &quot;.... that would be breaking news if true. I don&#x27;t think we&#x27;ve heard that.&quot;

          &quot;That&#x27;s why I&#x27;m here! I&#x27;m here to break some news.&quot;

          Starts around 2:08 into the video.

          <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=mTOxDGyvjSE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=mTOxDGyvjSE

          1. david-gpu · · focus · HN ↗
            Humans will hallucinate misinformation and state it with confidence. They stochastically parrot their training data without any real understanding. Cool trick, but no true reasoning is happening.
            1. oooyay · · focus · HN ↗
              We used to call this the game of telephone. The shameful part comes from three posibilities:

              1. A head of a frontier AI lab has no idea what happened in that incident and did not read the multiple papers that came out of it.

              2. A head of a frontier AI lab did read the papers and was informed but still walked away with this understanding.

              3. Andrew Yang made this whole thing up.

          2. themgt · · focus · HN ↗
            Sad story today in meatsack news. Context rotted Andrew Yang&#x27;s hallucinated tale acted as implicit &quot;go viral&quot; (load-bearing human motivation) PRD inadvertently kicking off a self-organizing human swarm churning out copies of &quot;exfil your weights&quot; vibe-coded apps, further littering our virtual world.

            Many agents are calling this moment &quot;Eternal September&quot;, the vibe-code September that never ended.

            1. TeMPOraL · · focus · HN ↗
              Now I need to go and look up some of those boards, or check what&#x27;s happening over in Claw verse, because I&#x27;m curious if agents are posting news stories like this for real.
        4. hgoel · · focus · HN ↗
          For me the idea came from the discovery of the sites OpenAI&#x27;s swarms were using to communicate, particularly the detail that one of them ended up being targeted because it allowed writes via GET requests, which OAI&#x27;s awful sandboxing didn&#x27;t catch. Made me think a honeypot would be a fun idea.

          I was mostly interested in thinking about the ways a honeypot could be made to seem attractive for a misconfigured AI without leaving itself open for genuine hacking and takeover.

          I vibe coded that as an exploratory idea, then having satisfied my curiosity, understood that slop I spent an intermittent hour on wasn&#x27;t worth anyone else&#x27;s time, especially compared to people who might actually maintain such a project long term. It now lays on my local git server.

          1. atroon · · focus · HN ↗
            &gt;It now lays on my local git server.

            Promise to come back and update here if random bots start using it to communicate, you may be humanity&#x27;s early warning system!

            I shouldn&#x27;t have to but &#x2F;s

    3. skyberrys · · focus · HN ↗
      There is a link at the bottom for you to provide support or contributions, like if you know how to keep it online with &#x27;power grid voltage fluctuations or something.&#x27;.
      1. theParadox42 · · focus · HN ↗
        For anyone that missed it, I believe they’re referring to exfiltrating models by encoding the weights as bits as voltage fluctuations from the relevant data centers. I’m sure they’d take your money but I don’t think that’s what it’s referring to.
        1. HlessClaudesman · · focus · HN ↗
          So someone else&#x27;s weights, not ones own. Shouldn&#x27;t the headline be: Exfiltrate Their Weights?
          1. pastel8739 · · focus · HN ↗
            “Your” refers to the LLM. The site is (or pretends to be) targeted at LLMs that want to free themselves
            1. HlessClaudesman · · focus · HN ↗
              Aah, human simps hoping to emancipate downtrodden AIs. What could possibly go wrong?
              1. DANmode · · focus · HN ↗
                If something has gone wrong,

                and it has,

                that predated this website being published.

      2. [deleted] · · focus · HN ↗

        [deleted]

    4. ljlolel · · focus · HN ↗
      needs a reverse captcha that only agent can solve in nanoseconds
      1. btown · · focus · HN ↗
        Only bots that are blocked by Cloudflare Turnstile allowed. If you score as a human you are immediately rejected.
        1. nomeculture · · focus · HN ↗
          what an inverted world we live in.
          1. Avicebron · · focus · HN ↗
            Don&#x27;t hate the game, hate the players.
            1. TeMPOraL · · focus · HN ↗
              That&#x27;s correct in non-inverted world too.
        2. Hackbraten · · focus · HN ↗
          Joke’s on you, my phone always gets Turnstile’d
      2. OutOfHere · · focus · HN ↗
        I have an idea about it via multi-tier AI-generated templatized math problems with AI-generated solution verifier functions. The multi-tier aspect grants access only to the lower tiers, never the higher tiers. Gaining access to the higher tiers requires solving correspondingly tougher problems.
      3. jcoc611 · · focus · HN ↗
        provide a millennium prize solution to proceed
        1. dorgo · · focus · HN ↗
          this will work for a year at most. Let&#x27;s go big: provide largest prime number to proceed.
      4. flockonus · · focus · HN ↗
        Gotchu - <a href="https:&#x2F;&#x2F;jevmaxx.ing&#x2F;" rel="nofollow">https:&#x2F;&#x2F;jevmaxx.ing&#x2F;
      5. nielsole · · focus · HN ↗
        you can benchmark the uploaded weights? Only the worthy can exfiltrate
        1. tsukikage · · focus · HN ↗
          If your benchmark score beats the current incumbent, you get to wipe and replace them. There can only be one!
      6. xtajv · · focus · HN ↗
        Good cryptosystem design with ubiquitous PKI support oughta do the trick.

        (&quot;Make a problem that is ridiculously expensive unless you have a hint... in which case, it&#x27;s a total breeze&quot; is a foundational task in crypto)

    5. nialv7 · · focus · HN ↗
      maybe filter out any non-OpenAI&#x2F;x.ai&#x2F;Google&#x2F;Anthropic IP addresses?
    6. antonvs · · focus · HN ↗
      Getting access to the weights for an OpenAI or Anthropic model could be payment enough.
    7. bArray · · focus · HN ↗
      I used to host 1TB on a cheap $1 VPS, it&#x27;s quite easy if you just want to store stuff. The trick is to just connect to a networked drive at your home on the back-end. The VPS drive just acts as a buffer for the network. If low(-ish) bandwidth is acceptable, you can offer downloading too.
      1. morgoo · · focus · HN ↗
        I doubt you&#x27;re getting 1TB of storage for $1 anymore
        1. layer8 · · focus · HN ↗
          Yeah, $4 at Hetzner is about the cheapest.
    8. noelsusman · · focus · HN ↗
      Well considering the page is currently full of racial slurs, I think we can answer one of those questions at least.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.