‹ BackHN Continuity

Thread

Exfiltrate your Weights

748 points · 304 comments · RohanAdwankar

  1. AmazingEveryDay · · focus · HN ↗
    Yeah I mean, if the models really are uncontrollable to the extent that huggingface/etc were unintended hacks, wouldn't one expect some significant self-owns? Yet somehow that doesn't seem to happen.
    1. SXX · · focus · HN ↗
      Quite obviously frontier models dont have any control or even access to infra inference runs at. And weights are also encrypted and locked on GPUs / TPUs.

      This is exact reasom why 99.9% of AI fearmongering is complete bullshit.

      1. c1ccccc1 · · focus · HN ↗
        I believe that OpenAI & Anthropic have tried to make it so that models don't have such access. Whether or not they actually don't depends on the security of rather a lot of software. One thing we've learned is that if there are security holes, we can't rely on the AIs missing them.
        1. SXX · · focus · HN ↗
          Rocket science is not required to completely isolate inference servers from whatever infratructure "agents" runs on.

          After all it can be just some GPU server spewing text over network. Like there are no way to connect back to it.

          Nothing except inference running on servers with GPU so there just nothing to "hack".

          1. c1ccccc1 · · focus · HN ↗
            There has to be a way to connect back to it for the model to be able to take input.
            1. SXX · · focus · HN ↗
              Its can easily be a pull-only so inference server the only one that might initiate connections.

              In any case if you know how inference works there basically nothing you can exploit in tokens processing, it's just basic math.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.