‹ BackHN Continuity

Thread

An agent used DNS to reach an external chatbot

198 points · 189 comments · apsec112

  1. garo-pro · · focus · HN ↗
    Most interesting here:

    > We therefore stopped the affected training run and have subsequently decided to pause all other training, evaluation, and inference with tool-use (defined broadly) for our most capable models until we have both validated that the gap is resolved and performed additional red-teaming of the system. When training restarts, we will begin a fresh run with additional alignment improvements, including more comprehensive misalignment interventions. We will not resume training this particular model, even though the existing reward signal already correctly penalized this behavior.

    1. CTDOCodebases · · focus · HN ↗
      Maybe I lack intelligence but when you have a program that is basically brute forcing a solution to a problem repeatedly how is it possible to contain it?

      Sooner or later it's going to come up with a solution that is more intelligent than the lead security person anticipated.

      1. dgellow · · focus · HN ↗
        By limiting what the harness execute. The LLM has the reasoning. The harness is what makes it an agent, it’s a while loop continuously prompting a model, and processing tool calls. You don’t have to expose tools calls that make it possible to execute any process! OpenAI decides what tool can be called and how, they have full control over this and should be hold responsible for running so many instances with basically full execution permission and very little oversight
        1. majormajor · · focus · HN ↗
          The issue here for OpenAI is that they can limit what their harness can execute, but if they try to sell API access to the model, someone else would try to rebuild that harness, and in all likelihood be able to succeed pretty well (especially once they get things running to the point of being able to use the model's reasoning to help them come up with clever obfuscation and such).

          They are a company that's built a business and crazy-high valuation on "this is 'intelligence' that we can sell to everyone as a service" but seem to have ended up instead in the much-smaller-addressable-market space of "this is a weapon that we can't sell to just any old person off the street."

          1. dgellow · · focus · HN ↗
            Ok, but that’s not the issue discussed here. We don’t even have the first level of control. All the issues they reported so far are from their own systems, with harnesses they control
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.