Interstellar communication. IX. Message decontamination is impossible
arxiv.org
arxiv.org
The entire paper assumes we get a certain type of communication and in the course of decoding it, destroy humanity. It would make an interesting screen play, but the paper presents no proof whatsoever that "message decontamination is impossible."
At best, the paper presents 1 case and outlines 1 possible ending which is the end of humanity. Kinda interesting but not nearly as universal as the title claims.
"Assume" is a bit of an odd way of putting it. The paper is a discussion of the risks of receiving a certain type of message.
> but the paper presents no proof whatsoever that "message decontamination is impossible."
That's a bit harsh. The paper provides several arguments which I find quite solid. Which of them did you find unconvincing? The existence of message that can't be parsed by hand? The risk of manipulative AI running on an air-gapped computer? The difficulty of containing a message given that we can't turn off the source? The difficulty of containing knowledge/information over longer time scales?
I didn't think there was much particularly new in that article. It's mostly a re-hashing of other people's arguments. The most interesting point the article made is this conclusion:
"As we realize that some message types are potentially dangerous, we can adapt our own peaceful transmissions accordingly. We should certainly not transmit any code. Instead, a plain text encyclopedia (Heidmann 1993), images, music etc. in a simple format are adequate. No advanced computer should be required to decrypt our message."
I think what the paper actually shows is \exists message M, s.t. \forall decontaminating functions F, F does not decontaminate M.
In fact, we know the title (as I interpreted it) is false - the paper gives an example of a message that can be read as plain text which can be truly decontaminated.
Basically, when we get a message, we'll be able to immediately tell whether we can decontaminate it or not. If not, the paper argues we're doomed because eventually it'll leak. I just don't find that to be very interesting, and definitely not as strong a claim as the title (as I interpreted it).
I don't think this is true (at least not "immediately").
The paper is arguing that we will need computers to help decode any non-trivial message, and any computer program capable of decoding a non-trivial message will be Turing complete, and hence capable of running virus code that could have damaging or destructive effects. (The paper's example was a message containing equations in LaTeX, which is Turing complete, hence an ETI could embed a virus in LaTeX code, and humans might not be able to spot it.)
The strategy the paper is advocating, as far as I can see, is that, unless the message is simple enough that humans can decode it without computer help, and thereby check directly whether it contains any dangerous information, the message should be destroyed. I suppose this could count as "we can't tell whether we can decontaminate it", but I'm not sure that's what you meant.
Edit: If we were incredibly paranoid and had some self-sacrificing astronauts it could be a one-way trip to Mercury.
Just speculating, without knowing how we could get to such a predicament.
2. How would you identify that what you've created is an AI?
3. Under what circumstances would you decide to trust the AI that you've created?
4. Under what circumstances would you be confident to feed a potentially malicious potential AI to your trusted AI?
But more to the point, who knows what it can convince the astronaut to do? Can it convince the astronaut to transmit a hostile message back to Earth, suborning the receiving computer, and thereby letting the AI out of the box?
In the AI alignment field, this is called the "value drift" problem.
I may have been unclear: the astronaut is never intended to leave the box, he burns with the box. The astronaut is paralyzed save for his tapping finger, and on a doomed one way trip.
It's certainly possible, but negotiations with hidden agendas have been part and parcel of humanity for all time, and are a major basis for all foreign (and most internal) affairs.
The paper presents no predicament that China couldn't put the US in tomorrow with a suitably (apparently) one-sided deal, and yet countries don't as a rule isolate themselves to avoid hearing potentially deadly trade offers.
That's because you're assuming that whatever ETI or AI we are bargaining with has roughly our intelligence. That is what has made it possible for humans to negotiate with each other instead of isolating themselves to avoid hearing potentially deadly offers.
But any ETI or AI capable of sending us a complex message will probably be much more intelligent than we are. In that case, we would basically be in the same position as, say, a dog trying to negotiate with humans; we simply would not even be able to comprehend what the other side was doing or thinking.
If I were negotiating with an alien intelligence, I would assume that it could think circles around me, so I wouldn't be about to accept any bargain that I couldn't - fully - think through the ramifications of. I'm not going to accept complicated bargains, only extremely simple ones. This would most probably result in making no bargains at all. So be it.
I reject the notion that a being capable of reason, holding all the cards, is unable to create an unwinnable state for its opponent, when inaction is a possibility. The most intelligent computer in the universe can't beat you at chess if you don't play.
Any sufficiently advanced alien invasion could be indistinguishable from local politics.
I think the paper fails because it assumes a magical hypersmart AI would arrive as a message at a radio telescope.
But if you’re going to magically assume a magical hypersmart AI, you may as well assume it can get here magically without being noticed.
I'm just jumping off from the particular assumption that the paper makes.
If this is true for you, it's also true for the AI. Which would be a contradiction, similar to the old classic irresistible force meeting immovable object. So the notion you're rejecting is the only consistent possibility.
Firstly, we begin with a power imbalance, we're not on a level playing field.
Secondly, there's nothing inconsistent about both parties being able to create an unwinnable state for the other. As I stated earlier in my comment, the most likely outcome is no dealing whatsoever. The only rational alternative is an agreement whose effects we can both perfectly foresee.
https://m.youtube.com/watch?v=_yo9WHrTvks
https://en.m.wikipedia.org/wiki/The_Funniest_Joke_in_the_Wor...
I deal with 'unusual' payloads all the time and I've never seen anything that has this potential, I don't see how anything could be built to be so, without obviously being so.
EG: the progression would go from something being some form of plain text, to it being encoded in some way which is very very likely.
On the extreme ends say something is sent as machine code. Firstly, this is very odd and suspicious for a lot of reasons but even still you can run untrusted machine code in a very safe way. Assume its resistant to existing types of disassembly for whatever reason. Let's say you want to take an absurd level of paranoia (which, really, is justified if an alien civilization sends us machine code), rut it on an entirely physically disconnected (battery powered) machine inside a Faraday cage. If the code still won't work (ERR: must be connected to the internet to proceed) you can basically assume its malicious.
And, after all that, there are far easier ways to kill us all. Send the plans to a massive superweapon but only send it to the USA (or just to Russia, or just to China) but send the other side a message telling them what you did. The snubbed nation may feel the need to make a preemptive attack before the other nation can develop the technology.
Send plans for an ultimate bioweapon to the right/wrong people.
The author is suggesting that the message contains the code for a true ai and makes the point that it might be able for it to bargain in exchange for giving humans information they want or need. It goes on to reason that eventually knowledge of this ai will become public and due to human nature it will eventually be let free.
Disconnection from infrastructure is not enough to make the message safe.
Given that time is not a factor for the ai this does not seem far fetched. At least in the context of this paper.
It goes beyond the medium.
Humanity could receive a schematic for an extinction device and wouldn't know it until it's turned on. How long would we last before we caved? We could project any potential use for some mysterious alien tech; debate and rationalize at every moment of weakness. Could it cure a plague or teach us even more? Someone could build it in secret.
Looking at the mousetrap
Interesting device
It sees the spring and smells the bait
Understands everything -except the connection
What if decompression produced an alien message hundreds of gigabytes in length? Is that file completely safe to transmit to un-airgapped computers?
Would you bet all of human civilization that it's safe? No way any part of it would produce any negative effect on a human reading it?
>Send the plans to a massive superweapon but only send it to the USA
Laser beams sent over interstellar distances will be hundreds of thousands of kilometres wide at the destination.
The threat model for a hostile probe inside our solar system would be rather different, of course.
[Time passes]
"By Jove, I think we've cracked it, Sir. It's essentially Huffman encoded and contains a mechanism for repeating redundant strings. Let me see if I can decode the entire message."
[Time passes]
"Shit, my computer crashed."
But here the basic premise is that merely thinking the right thoughts can physically change reality. Which is 'sort-of' true for real brains, but there's an important layer of indirection that makes it not work the way I spelled out above.
http://tvtropes.org/pmwiki/pmwiki.php/Main/ItsTheOnlyWayToBe...
<spoilers>It's about two things. First, an alien race that give's humanity a "weapon" which is their language. Anyone who learns the language starts to perceive time in a non-linear (probably deterministic) fashion, ie. flashbacks and flashfowards. They did this so that humanity would save them sometime in the future from something unknown to modern day humans. And second, it's about how a translator lives through the life and death of her child while understanding said language. She makes the choice of conceiving her child even though she knew the child was going to die in the future because it was worth it to her because of how much she loved her daughter.</spoliers>
If you want a fiction novel that IS very similar to this, I recommend reading The Three-Body Problem.
Secure isolation review of code is dismissed because AIs can trick people into freeing them.
Finding states: "[M]essage cannot be decontaminated with certainty, and technical risks remain which can pose an existential threat. Complex messages would need to be destroyed in the risk averse case."
Couldn't we simply agree not to execute un-audited code from unknown third parties? Seems like the same threat vector as unknown executable code delivered over email to me.
There are a couple of problems with this.
First, limiting the spread and ensuring that nobody executes the message is non-trivial (especially given that currently the protocols dictate "These recordings should be made available to the international institutions listed above and to members of the scientific community for further objective analysis and interpretation". Also, unless all instances of the message were destroyed AND transmission ceased permanently, humanity is left with a literal Pandora's Box. It's hard to imagine that this box wouldn't be opened eventually by someone with more curiosity that caution.
Second, there are messages that cannot be safely audited without running. A self-bootstrapping decompressor/compiler that modifies it's own code as it parses itself into existence could be impossible to evaluate. Committing ourselves to never executing un-audited code means accepting there are certain types of messages we would never understand.
So while your solution is a possibility, it is not an easy one and it is not one without costs. Maybe I'm not risk averse enough but I (like authors) think the potential gains of executing ET code outweigh the risks associated
I used to read old Analog magazines in high school, and I distinctly recall a short story about people picking up a transmission with a radio telescope, which told them how to build a computer - basically a form of alien invasion based on the fact that radio transmissions are the only practical way of interstellar travel.
The simplest of tricks have been proven to work again and again.
Though it's likely pretty hard to get a signal 10000 light years, especially if you don't know the direction to send it.
How exactly would we achieve that? How can we prevent every single human being on the planet from executing some malicious code coming from open space?
The ability of humans to abide by such a restriction is highly doubtful. Destroying the message would be much safer.
Assume that, beyond a shadow of a doubt, we have an impenetrable system for interfacing with the AI. I say system, because the people that are part of the protocol are all moral equivalents of Jesus. They can't be corrupted, they can't be blackmailed. The AI is kept in a box that cannot be accessed by anyone else. In short: we've solved the containment problem (of the AI).
Of course we _do_ want to use the AI. We've installed it in the box for a reason. If we didn't intend to use it we might as well not have built it. So actually using the tech that it gives us, after checking for corrupting technology, is also a given in this scenario.
We can ask the AI questions and interact with it, extract knowledge and have it solve our problems for us.
If we were to use the AI, it would still destroy us, even without corrupting any of the people working with it or feeding us corrupted technology. Simply _using_ the AI will be enough.
Using the AI effectively cheapens the creation of another AI. Each new processor we have the AI design will be faster and than it's predecessors. Every mathematical problem that it solves is checked, confirmed an shared in our universities. Eventually the technological over-saturation of our society will ensure that the contemporary equivalent of a mobile phone can run a strong AI. The ubiquitousness of the new insights will ensure that all the theory needed to bootstrap another AI is there for the taking. In short, truly _using_ the AI, (asking the questions, sharing the knowledge) will ensure another AI existing outside of the containment system, malicious or otherwise. Taken to the extreme, if strong recursive AI is a possible, it is a given.
I don't think strong self improving AI can actually exist. But who knows?
These are extremely strong statements, which you cannot prove.
Would like to point out the morally pure uncorruptible interfaces to the AI would be incapable of validating whether any tech that came out of the AI was non-malicious. If you can't identify whether an arbitrary piece of software halts. You also can't identify whether it does something nasty after billions of instructions.
Also, AI in a box would be necessarily dumb. It wouldn't have senses and external knowledge. I think the most effective intelligence will be intimately tied to body (whether physical or virtual). But that's an opinion.
The question isn't complexity per se but speed. Suppose there were an AI that had the same general capacity for handling cognitive complexity as humans, but that ran at computer speeds--i.e., the time it takes the AI to have a single conscious thought or perception, which is roughly 100 milliseconds for humans, is, say, 1 nanosecond. That means the AI can think ten million thoughts in the time it takes us to think one. So it could potentially think through problems ten million times as fast as we do. It could make the same intellectual progress in one day that a human could make in ten million days, which is roughly thirty thousand years.
Our 50 year horizon for technology might still be thousands or millions (or billions) of years behind the technology of an ETI.
But seriously, confined evaluation was figured out in the mid-90s by the E folks, building on years of research into capability security, and the worst thing that can happen is Turing-completeness.
I'd be more worried that the message contains a memetic hazard. Our computers wouldn't be infected; our minds would be infected.
I read it in "Tech for Youngs" USSR magazine (Техника Молодёжи) a long time ago, around 1980. It is short and profound, for example, I later came around human echolocation phenomena and instantly remembered that piece. Our current human echolocators are about as good as the main hero of the piece above.
Given that, I think we are safe. ;)
Also, this reminds me of the premise of the movie Ex Machina (no spoilers!) which is sweet! http://www.imdb.com/title/tt0470752/
If you were going to use some form of lossless compression, what compressor would you choose that could be simply and quickly explained in a preamble series of data?
https://en.wikipedia.org/wiki/The_Three-Body_Problem_(novel)
Another source I believe comments that with one infinitesimal change to fundamental universal constants, fission and fusion would be impossible except at stellar scale. Odd, that we live in a universe where the boundary between existence and annihilation is so thin, yet we continue to exist.
Personally, I think the proof here is a divide-by-zero instance. Conceptually, a design of information that can be communicated, such that it cannot be comprehended or enacted but its consequence ensues. Isn't that a kind of meme?
If the universal constants were different, there could well be a different form of life making the comment instead.
For example, see Greg Egan's scifi book The Clockwork Rocket, which features a universe that runs on fundamentally different principles but that has broadly recognizable forms of life.
Even receiving and recording the message might be very dangerous. There have been cases in the past where contaminated MP3 or video files took over the media players (because of decoding bugs in them).
Imagine a very weak signal which requires complicated signal processing and correlation between multiple receivers to reconstruct.
The paper does talk about message compression being a vulnerability since we would have a hard time manually running their decompression algorithm.
However, I find it hard to believe that any kind of message will be dangerous due to signal processing without the sender having knowledge about our IT system structure and implementation details or some sort of feedback cycle. Given the time delays of interstellar messaging, I feel the only risk here can come from some sort of AI running locally which I assume would only be possible if we evaluate the message in a turing complete tool (such as their provided decompression algorithm.
But at the same time, with long enough messages you could sample a lot of possible IT system structures.
The unknown danger here is that there might be some underlying generic exploitable structure in our systems or processes that we are not aware of yet.
You would need more than an exploit, you need an exploit that allows you to parse the message in a turing complete fashion to bootstrap an AI.
Otherwise, I don't see how identifying the exploit transitions to being a significant risk to humanity.
For example, they can safely assume that the moment we catch a glimpse of a message we will point all our receivers towards the source, thus they got us to amplify their signal and look for it all over the spectrum.
Then, they can guide what sort of analyses we run.
For example, they might embed a lot of prime number structures into their signal, thus we will apply a lot of our prime number expertise and methods on their numbers. What if you can bootstrap a turing complete machine by doing various statistics on prime numbers?
They could alternate, one week the signal is prime-number heavy, the next week it has vary weird spectral distributions, so we will pull out all kind of Fourier transforms.
We don't yet know all the possible places where a turing machine might hide.
In a way, you can consider the whole network of research facilities and researchers applying statistical methods on a signal some sort of a predictable controllable machine. Maybe not turing, but maybe you can go by with a weaker kind. Think how you can do good computations with non-deterministic machines. Couple that with psychology (social engineering) and game theory.
It seems to me highly dangerous to let our signal analysis be guided by the signal itself, and in general to do anything with a signal form an intelligent source.
Even if it's just clear text ASCII English, who knows what kind of social havoc you can wreck with just a few carefully constructed sentences from a very advanced intelligence.
It encodes itself explicitly as Turing machine instructions that are necessary to decode the later chunks of data. We would have to implement the program and run these instructions to get any meaningful interpretation of the data. It could be encoded in a way such that the entirety of the message needs to be processed through it before any of it is usable.
In this scenario, in order to get any meaningful data out of the message, you'd have to execute arbitrary software.
But I agree that simply storing the data in a computer wouldn't be enough to be a danger (I think?).
But all they have is "it seems to me that".
You can publish that, sure, think tanks do that kind of thing all the time. But that's not a scientific paper, not as I understand the concept.
Also, there is no proof that true AI can be achieved with Turing completeness alone, so this is a gaping hole in the logic right there.
Our current computers are certainly not able to simulate a human brain. No computer in the world has currently the computing power to run decent, biochemistry based models for each neuron in a human brain. This basically calls for specialized hardware, which may or may not extend the limits of computable problems beyond Turing completeness.
If we manage to get to that point, we will have to face more important ethical challenges anyway, like how do we deal with tools that allow us to assess what a person is thinking and planning with near certainty? At that point, the key argument of the paper might actually fall apart because there is a chance that we end up understanding the inner workings of the alien AI.
But at that point we have heaped up so much speculation that decent science fiction authors are about to get jealous.
In... what way do you think human brains are hypercomputers? Keep in mind that quantum computers are "merely" Turing universal, they can't solve decidability. (If you think that human brains can solve the halting program, then I would like to ask you to produce Busy Beaver 100)
To the contrary, I believe human brains are what they look like: a glob of regular, boring old proteins, interacting with each other using normal atoms. No exotic physics, closed timelike curves, integrated information theory phi factor, Penrose quantum spookiness, Sam Hughes infolectricity, nothing. Humans aren't special, we're just atoms, capable of being simulated by a sufficiently gigantic Turing machine.
If I had to guess right now, I'd say that it is more likely that the human brain has clever ways to exploit signal timings and randomness (e.g. Brownian motion). There is no room for large scale and/or long duration quantum processes in biochemistry.
Then why do you think it's a hypercomputer? These are all classical physical effects. What math problems do you think the human brain can solve that a Turing machine with sufficient time can't?
[citation needed]. How can you confidently make an assertion like that? How do you design an experiment that distinguishes randomness in the human brain from sufficiently-advanced pseudorandomness?
On the contrary, at the surface level, we seem to be terrible at doing anything that resembles true randomness [1].
[1] http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.211...
Besides, random processes within cells are a fact of nature. Research has discovered various ways how organisms protect themselves against that. I will not point you to references on this because this goes down a rabbit hole of different aspects.
To put it less obliquely, how do you distinguish "true randomness" from perfectly-deterministic physical phenomena that are just determined by a "rabbit hole of different aspects"? Is a die roll truly random, or is it just a theoretically-predictable product of factors like air circulation patterns and friction?
To the first part of your question: I thought long about how to put it succinctly and I cannot. The best thing that I can come up with is to point you to the safeguards that are in place for gene expression within cells. A bit of Google-fu brought me to an entire volume dedicated to explaining how that particular process can be so reliable[2]. (I already know that this stuff was complex, but this takes the cake!) Now, these complex mechanisms take tons of resources to maintain. Natural selection generally gives processes with lower resource usage an edge. This has in some cases lead to amazingly efficient solutions, e.g. for some single-cell organisms. But gene expression stayed this complex. It stands to reason that every bit of this mechanism is required to keep cells reasonably alive.
[1] https://en.wikipedia.org/wiki/Laplace's_demon
[2] https://books.google.de/books?id=Czv25w1HNcEC&lpg=PA252&ots=...