‹ BackHN Continuity

Thread

Hackers influence ChatGPT and Gemini to direct users to scam centers

143 points · 53 comments · ArielSimon

  1. pluc · · focus · HN ↗
    That's happening across the board when it comes to models that feed off online information. Create a website with a false claim, have AI slurp it up and spit it back out when a user asks a question.

    Happy elections.

    1. ariel-vigilance · · focus · HN ↗
      That's very troubling. The scariest part is how easy it is, one Instagram post and you may change the customer phone number of Airbnb, or who is leading the election poles.
      1. lotsofpulp · · focus · HN ↗

        [dead]

    2. mrweasel · · focus · HN ↗
      Oh no, my uncritical ingestion of data, based on the assumption that all data is of equal quality, and that more is better, has failed. How could this happen!

      You've always needed to be critical of your sources, your teacher tried to explain that when you ripped of that Wikipedia article or clicked the first link in a Google search. How the fuck did the AI companies think they could avoid reading and rating the content they've been hovering up?

      1. Sharlin · · focus · HN ↗
        I don't think they did. Or those who did have been "encouraged" to leave a long ago.
      2. jackb4040 · · focus · HN ↗
        Because their leaderships have defunded / fired all ethics researchers looking into their ongoing crimes and failures in favor of a bs "AI safety" narrative based around a creepypasta about an AI monster time traveling backwards to torture their staff for not maximizing shareholder value.
      3. cush · · focus · HN ↗
        They don’t assume all data is of equal quality
        1. mrweasel · · focus · HN ↗
          Well, they clearly aren't considering that some data is just wrong or deceptive.
          1. kjs3 · · focus · HN ↗
            Clearly. They are considering what data increases their net worth. That's the priority.
          2. cush · · focus · HN ↗
            That too, is an assumption. I think what you mean to say is they're not perfect at determining what data is wrong or deceptive
        2. Tanjreeve · · focus · HN ↗
          Who to believe here. The actual outcome in the headline people can observe or what the marketing people say does and doesn't happen?
          1. cush · · focus · HN ↗
            The actual outcome. The fact this post is even being commented on - that hackers have discovered a way to influence the models - is but one small proof. The vast majority of data coming out of LLMs these days is truthful enough that you're going out of your way to argue that this special case is noteworthy. The idea that the ingestion of data is "uncritical, and based on the assumption that all data is of equal quality" is ridiculous
            1. Tanjreeve · · focus · HN ↗
              So they went out of their way to turn off the magic good useful data that isn't being manipulated switch here but the rest of the time it's fine? Seems like a lot of effort to go to.
      4. adrianN · · focus · HN ↗
        Recent political discourse has all but proved that a majority of the populace in many countries is quite removed from facts in general. I don’t think that there is much hope for critical thinking.
      5. ambicapter · · focus · HN ↗
        Because AI companies select out the kinds of people who would ask silly questions like "wait, is this data good" that hamper the eternally "profitable" quest for "scaling".
      6. dgellow · · focus · HN ↗
        They believe their role is to build a god machine, as prophetized by Eliezer Yudkowsky and other Rationalists/Efective-Altruism folks. Nothing else really matters to them, they already made up their mind
    3. someonebaggy · · focus · HN ↗
      But how do you get AI to slurp up the site? It's quite hard for a random to get a site indexed these days.
      1. pluc · · focus · HN ↗
        You can't count on that, but quantity increases visibility don't it, and it takes a single prompt to spit it all out. Couple that with social media bots and you've got a decent modern and super cheap propaganda machine. Now imagine you toss millions of dollars at that idea.
      2. burningChrome · · focus · HN ↗
        Depends on the site. If its a small/medium business, every LLM is now looking for "reputation signals" and "authority signals". This means everything from your basic SEO on the site with incoming links, how updated your google business profile is, how many reviews you have, how recent they are. They're also looking at any kind of references from other blogs, substacks, youtube videos, social media shares as well as a number of other things they look for.

        I would imagine in smaller industries, flooding the internet with fake information, then linking it all together would be somewhat easier - but it still takes quite a bit of work to get even just the major LLM's to give the consistent responses you want to see.

    4. jsrozner · · focus · HN ↗
      I was re-reading a book, and I had a thought. I googled to see whether someone else had the thought. Google AI said the internet did in fact have the same thought as I did. But when I looked more closely at the reddit source that Google AI cited, it turned out only a single user had had the thought before, and that user was .... me, when I last read the book.

      Lol.

      1. kjs3 · · focus · HN ↗
        Congrats...you're AI famous.
    5. RobRivera · · focus · HN ↗
      Hypnotoad promises peace.

      Hypnotoad promises peace

      Hypnotoad promises peace.

      ... or brainslug

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.