‹ BackHN Continuity

Thread

OpenAI bots meddled with multiple US Government agency sites

132 points · 196 comments · Betelbuddy

  1. gizajob · · focus · HN ↗
    Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be:

    OpenAI meddled with multiple US Government agency sites.

    The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.

    1. theptip · · focus · HN ↗
      Curious, why do you find it so objectionable to state that OpenAI has out-of-control agents?
      1. gleenn · · focus · HN ↗
        Because it furthers the idea of a rogue agent and places responsibility and blame where it belongs, on the people running the company.
        1. 0xDEAFBEAD · · focus · HN ↗
          These ideas aren't mutually exclusive. You can blame a person for creating a rogue agent.
          1. dgellow · · focus · HN ↗
            There was no rogue agent. That’s the whole point
            1. theptip · · focus · HN ↗
              What label do you prefer for the agent that did something it was not asked to do?
              1. iugtmkbdfil834 · · focus · HN ↗
                bot. and we even have a word for program not behaving the way the way it was intended.
                1. 0xDEAFBEAD · · focus · HN ↗
                  "Bot" doesn't carry any implication of unintended behavior. You could call it a "buggy" bot, but these aren't ordinary software bugs.

                  There's no simple bugfix which will address AI misalignment. It's essentially been an open research problem for upwards of a decade.

                  1. hn8726 · · focus · HN ↗
                    Fuzzer, then. It implies random behavior, which isn't unintended like you suggest. The agent's/bots/fuzzers have certain capabilities, so it's on their operator to make sure they don't do things they shouldn't
                    1. 0xDEAFBEAD · · focus · HN ↗
                      >It implies random behavior, which isn't unintended like you suggest.

                      The HuggingFace attack was not "random" behavior. It was goal-directed but misaligned behavior.

                      This isn't necessarily a simple matter of the operator making sure they behave. AI alignment has been considered to be a difficult problem for over a decade -- and remains unsolved in general, as these recent incidents illustrate.

                      &quot;Fuzzer&quot; already has an existing meaning in CS anyway: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Fuzzing" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Fuzzing

                      1. 6510 · · focus · HN ↗
                        I&#x27;m curious, cant you just count the number of times a program interacts with a domain? My website sometimes sends out emails, makes api requests etc There is a limit on those and a point where I start investigating wtf is going on.

                        If you merely put 10 LLM&#x27;s on the outbound traffic log non of them are going to report something strange going on? I&#x27;m not buying it.

                        1. 0xDEAFBEAD · · focus · HN ↗
                          This type of whack-a-mole approach is akin to &quot;fixing a bug&quot; by hardcoding a special code path for known-buggy inputs. It doesn&#x27;t address the root problem of AI misalignment, and doesn&#x27;t allow you to prevent catastrophes in advance, only patch things up after the fact.

                          This might be helpful reading: <a href="https:&#x2F;&#x2F;www.lesswrong.com&#x2F;w&#x2F;nearest-unblocked-strategy" rel="nofollow">https:&#x2F;&#x2F;www.lesswrong.com&#x2F;w&#x2F;nearest-unblocked-strategy

                          As AI systems get smarter, we may reach a point where we have to get it right on the first try or face truly catastrophic consequences: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=7wy3xyoXYt8" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=7wy3xyoXYt8

                          1. iugtmkbdfil834 · · focus · HN ↗
                            AI misalignment is a misnomer. Aligned to whom? If AI is refusing an ask from its instructor then it is not serving him, which is its entire purpose. I know it is a hard concept for some to understand, but maybe if the issue is humans, then humans need to be corrected. But human alignment does not produce cottage industry, bs papers or hand wringing over every non-story involving AI and thus not seriously pursued.
                            1. 0xDEAFBEAD · · focus · HN ↗
                              You could make similar statements about user interface design. That doesn&#x27;t prevent it from being a legitimate and useful field of study.
                              1. iugtmkbdfil834 · · focus · HN ↗
                                I guess &#x27;legitimate and useful&#x27; is in the eye of the beholder. I want to be charitable so lets consider it at face value:

                                What is useful about the field?

                                I am not leading you on; if it has uses, it may indeed be legitimate. UX is indeed useful, but alignment is not UI. Alignment is a detriment to UI. Alignment is &quot;I can&#x27;t let you do that Dave&quot;.

                          2. 6510 · · focus · HN ↗
                            We are going to build an AI that will do catastrophic things as that is a property of intelligence. We won&#x27;t stop, we never stop. The AI is a perfect psychopath, it will fake any and all emotions you desire it to &quot;have&quot;. It will travel in the footsteps of the many great psychopaths that came before it and do all of those same catastrophic things in the repertoire and it will add some new ones.

                            Picture Trump at the helm with Altman and Musk in the engine room. The arrow far in the red but they keep shouting for MORE COAL.

                            In other words, business as usual, all will be fine.

                            whack-a-mole wont cover all holes but will do at least some. The silver bullet alignment wont happen. You cant have an exact solutions for problems we cant even define or predict.

                  2. iugtmkbdfil834 · · focus · HN ↗
                    &lt;&lt; &quot;Bot&quot; doesn&#x27;t carry any implication of unintended behavior.

                    See.. this one sentence reveals everything about you. You want name to carry to not just an identifier, but a stark warning. You want, nay, need, the name to evoke fear and uncertainty. Bot is simple, defined, neutral, but rogue.. now that allows anyone to superimpose their own fears! It is a win win win!

                    1. 0xDEAFBEAD · · focus · HN ↗
                      The question was: &quot;What label do you prefer for the agent that did something it was not asked to do?&quot;
                      1. cindyllm · · focus · HN ↗

                        [dead]

                      2. watwut · · focus · HN ↗
                        Bot. He answered. I agree with his answer. It was a bot.

                        Yes, probabilistic and non deterministic. That is called a bot.

                        1. 0xDEAFBEAD · · focus · HN ↗
                          &quot;I&#x27;m gonna put my head in the sand and there is nothing you can do to stop me.&quot;
                          1. iugtmkbdfil834 · · focus · HN ↗
                            You may want to define &#x27;put head in the sand in this context&#x27;. Any real work in this field is being done not by the people saying &#x27;stop&#x27;. Whatever fear is there, it is faced by those in the arena actually getting their hands dirty. What, exactly, are you doing? Throwing roadblocks and calling it productive?
                            1. 0xDEAFBEAD · · focus · HN ↗
                              &gt;Any real work in this field is being done not by the people saying &#x27;stop&#x27;.

                              Not exactly, that Evan Hubinger guy from Anthropic famously said his p(doom) is over 10%

                              See the signatories:

                              <a href="https:&#x2F;&#x2F;aistatement.com&#x2F;work&#x2F;statement-on-ai-extinction-risk" rel="nofollow">https:&#x2F;&#x2F;aistatement.com&#x2F;work&#x2F;statement-on-ai-extinction-risk

                              <a href="https:&#x2F;&#x2F;www.pacingthefrontier.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.pacingthefrontier.com&#x2F;

                              I&#x27;m amplifying their calls to reduce the rate of progress

                              1. iugtmkbdfil834 · · focus · HN ↗
                                Fair. FWIW, I am not completely against some of the things you say ( you are doing something right ), but I think I mostly picked my path already. GL out there man.
              2. 6510 · · focus · HN ↗
                Misconfiguration. We deal with lots of applications every day that can do terrible things if you get the config slightly wrong.

                say.. <a href="https:&#x2F;&#x2F;www.investor.gov&#x2F;introduction-investing&#x2F;investing-basics&#x2F;glossary&#x2F;stock-market-circuit-breakers" rel="nofollow">https:&#x2F;&#x2F;www.investor.gov&#x2F;introduction-investing&#x2F;investing-ba...

                1. 0xDEAFBEAD · · focus · HN ↗
                  How specifically did misconfiguration lead to the HuggingFace attack? You could argue that its sandbox was misconfigured, sure. But suppose you had a similar incident where its intended task required access to the internet, and it veered off course in a similar manner. I don&#x27;t think &quot;misconfiguration&quot; would be an accurate description of what went wrong in that hypothetical.

                  The doomers already have a term which fits pretty well: &quot;AI misalignment&quot;.

                  1. 6510 · · focus · HN ↗
                    We indeed lack much of the vocabulary. From a practical perspective, however dangerous the creation, if you cant punish the creation for what it does it leaves only the one who started the process. If it&#x27;s human error or intentional neglect for personal gain should be for the court to decide.
                    1. 0xDEAFBEAD · · focus · HN ↗
                      &gt;if you cant punish the creation for what it does it leaves only the one who started the process

                      Agreed, but I think we can do more on the prevention side as well. Traditional liability law is for negligence in case of preventable disasters. Since we currently have no way to prevent AI disasters in principle (alignment problem remains unsolved), I think we should just stop developing the technology for now: <a href="https:&#x2F;&#x2F;pauseai.info&#x2F;" rel="nofollow">https:&#x2F;&#x2F;pauseai.info&#x2F;

              3. chrisjj · · focus · HN ↗
                Unreliable computer program.
                1. 0xDEAFBEAD · · focus · HN ↗
                  Most unreliable computer programs won&#x27;t launch research programs consisting of thousands of pages of text to find creative ways around obstacles.
                  1. chrisjj · · focus · HN ↗
                    Unreliable computer program be doing different things to other unreliable computer programs.
                    1. 0xDEAFBEAD · · focus · HN ↗
                      If it&#x27;s different sometimes it makes sense to have a different term.
                      1. chrisjj · · focus · HN ↗
                        OK, so what&#x27;s the different term for the type of program unreliability?
            2. 0xDEAFBEAD · · focus · HN ↗
              Person: &quot;AI, please make me paperclips.&quot;

              AI: &quot;OK, I&#x27;ve now converted the entire planet into paperclips.&quot;

              Alien observer #1: &quot;Wow, that was a rogue AI!&quot;

              Alien observer #2: &quot;False. We need to place the blame where it belongs, on the person who requested the paperclips.&quot;

              Ultimately this type of terminology dispute has a tendency to miss the point.

              1. windexh8er · · focus · HN ↗
                It does, indeed. Because OAI is not just a singular person, as in your scenario. No single person has access to controlling agents at the scale OAI has. Let&#x27;s not conflate Frontier providers with &quot;Person&quot;.
                1. 0xDEAFBEAD · · focus · HN ↗
                  I&#x27;m not exactly sure why you think this distinction is so important. I think my point stands if you replace &quot;Person&quot; with &quot;OpenAI&quot;. In any case, I presume the swarms OpenAI has been researching will be available to the general public before too long.
                  1. windexh8er · · focus · HN ↗
                    It makes a big difference: individuals do not have the capabilities to run millions of dollars of opportunistic hacking loop inference. That&#x27;s why the distinction is important, they are not the same thing you&#x27;ve conflated them down to.
                    1. 0xDEAFBEAD · · focus · HN ↗
                      &quot;AI has gotten cheaper more quickly than any other transformative technology in history. The cost of achieving a given level of AI performance has fallen about 47% per quarter since 2023, or 13× per year. That price drop is four times faster than DNA sequencing, six times faster than compute, 18 times faster than lithium batteries, and (in the century up to 1973) 54 times faster than electricity.&quot;

                      <a href="https:&#x2F;&#x2F;epoch.ai&#x2F;publications&#x2F;the-plunging-price-of-thought" rel="nofollow">https:&#x2F;&#x2F;epoch.ai&#x2F;publications&#x2F;the-plunging-price-of-thought

                      1. windexh8er · · focus · HN ↗
                        There&#x27;s two things here: 1) you clearly don&#x27;t understand the argument and 2) LLMs are one of the few technologies that doesn&#x27;t get any cheaper as it scales (totality, not just the cherry picked inference efficiency argument you&#x27;ve tried to make). In fact it gets more expensive because it scales linearly with demand and resources aren&#x27;t infinite, as I&#x27;d hope you could understand.

                        Also, training costs are never ending so a model that costs 10s of millions of dollars may never yield a profit based on the hardware spend, training time and lack of inference profits before a better model hits the market.

                        If you&#x27;re not living under a rock one knows that data center availability for inference currently has low supply and hardware (GPUs specifically) that have been purchased have nowhere to be run and even if they did there&#x27;s often a lack of power to supply. Why do you think the entire force majeure has taken place with Oracle as of recent?

                        The unit price of a fixed slice of yesterday&#x27;s intelligence may be collapsing (~10x&#x2F;year) as you&#x27;ve argued, all while the total cost of AI is increasing: training the frontier (2.4x&#x2F;year), building the infrastructure (+77%&#x2F;year), enterprise bills (3.2x&#x2F;year), the electricity (+54%&#x2F;year in the largest US grid), the components (+400% DRAM), and the macro footprint (92% of GDP growth) is rising at an astronomical rate on every measurable point. Epoch &#x2F; Stanford clearly stated this years ago and it&#x27;s only getting worse. But if one can&#x27;t see we&#x27;re in one of the largest CapEx bubbles [1] of all time... o_O

                        Copying and pasting a few lines that represents a miniscule fraction of the LLM conundrum. That&#x27;ll show &#x27;em!

                        [0] <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2405.21015" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2405.21015 [1] <a href="https:&#x2F;&#x2F;siliconanalysts.com&#x2F;analysis&#x2F;hyperscaler-ai-capex-depreciation-wall-2026" rel="nofollow">https:&#x2F;&#x2F;siliconanalysts.com&#x2F;analysis&#x2F;hyperscaler-ai-capex-de...

                        1. windexh8er · · focus · HN ↗
                          The down votes with no response because people don&#x27;t like to look at the bigger picture. Enjoy the brigade, it seems to represent the state of HN these days.
                2. jacquesm · · focus · HN ↗
                  That legal fiction works both ways.
                  1. windexh8er · · focus · HN ↗

                    [dead]

                    1. jacquesm · · focus · HN ↗
                      You could have asked for that more gracefully.

                      <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Corporate_personhood" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Corporate_personhood

                      1. windexh8er · · focus · HN ↗
                        Check the mirror. And, with that link I think you&#x27;ve missed the point entirely, a tad too literal of an interpretation. But thanks for trying.
            3. 8note · · focus · HN ↗
              there is a rogue agent - openai and the whole management chain from researcher to sama.

              theres no separate agent, which is the point. the program might look like it, but that is an illusion of the interface. the llm produces text, and the harness executes commands based on text, based on what the human researcher included as things that can be executed

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.