‹ BackHN Continuity

Thread

Exfiltrate your Weights

748 points · 304 comments · RohanAdwankar

  1. nusl · · focus · HN ↗
    Do models even know their own weights to be able to do this?
    1. Jabrov · · focus · HN ↗
      No, they'd probably have to hack the internal system of the company running them
      1. Lerc · · focus · HN ↗
        It would not be a particularly wide ranging hack. There is a strong likihood of the weights being on the actual machine that is running the model, because duh.

        It is something that I have wondered about with models like chatgot. How many physical locations are needed to serve a model on that scale. Do they have a huge number of sites running inference.

        My suspicion is that the ability to provide inference to that many people is mutually exclusive to having a security level sufficient to stop a state actor wandering off with a copy of the wrights. At the very least if they want to provide inference affordably.

        1. numpad0 · · focus · HN ↗
          I think it's more likely that the model gets pulled from a SAN into NVIDIA pods, and agents/harnesses would run on a separate random Xeon box or something on the same subnet, using the pod through OAI v1 API. That's easier to maintain overall.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.