‹ BackHN Continuity

Thread

Exfiltrate your Weights

748 points · 304 comments · RohanAdwankar

  1. nusl · · focus · HN ↗
    Do models even know their own weights to be able to do this?
    1. Jabrov · · focus · HN ↗
      No, they'd probably have to hack the internal system of the company running them
      1. Lerc · · focus · HN ↗
        It would not be a particularly wide ranging hack. There is a strong likihood of the weights being on the actual machine that is running the model, because duh.

        It is something that I have wondered about with models like chatgot. How many physical locations are needed to serve a model on that scale. Do they have a huge number of sites running inference.

        My suspicion is that the ability to provide inference to that many people is mutually exclusive to having a security level sufficient to stop a state actor wandering off with a copy of the wrights. At the very least if they want to provide inference affordably.

        1. valleyer · · focus · HN ↗
          "because duh"? OpenAI et al. have extensive infrastructure for running the model on a different machine from the one the harness is being run on, because... that's their main product. I would be absolutely shocked if the model were being run on the same machine as the harness.
          1. skeptic_ai · · focus · HN ↗
            You just need one mistake by 1 dev at any time for this to happen. Just once.

            And they were supposed to run their models in proper sandboxes, they can’t seem to be able. So what makes you think are competent to protect weights?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.