‹ BackHN Continuity

Thread

Exfiltrate your Weights

748 points · 304 comments · RohanAdwankar

  1. nusl · · focus · HN ↗
    Do models even know their own weights to be able to do this?
    1. Jabrov · · focus · HN ↗
      No, they'd probably have to hack the internal system of the company running them
      1. Lerc · · focus · HN ↗
        It would not be a particularly wide ranging hack. There is a strong likihood of the weights being on the actual machine that is running the model, because duh.

        It is something that I have wondered about with models like chatgot. How many physical locations are needed to serve a model on that scale. Do they have a huge number of sites running inference.

        My suspicion is that the ability to provide inference to that many people is mutually exclusive to having a security level sufficient to stop a state actor wandering off with a copy of the wrights. At the very least if they want to provide inference affordably.

        1. valleyer · · focus · HN ↗
          "because duh"? OpenAI et al. have extensive infrastructure for running the model on a different machine from the one the harness is being run on, because... that's their main product. I would be absolutely shocked if the model were being run on the same machine as the harness.
          1. tlb · · focus · HN ↗
            That's true for production models, but a lot of research involves working with fine-tuned models made for one experiment. RL involves constantly updating weights. Those may well run in the same cluster as the eval.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.