The AI That's Too Dangerous to Release
blog.floydhub.com
blog.floydhub.com
I extremely rarely upvote stories.
I read the comments section more than i read the articles.
I cant be the only one.
You can also use this text generation for less nefarious purposes such as for submitting journal articles (https://pdos.csail.mit.edu/archive/scigen/), creating fake facebook campaigns, creating fake github profiles, phishing on dating sites, fool Google's page ranking algorithms and so on.
We are already in an arms race for people's attention and data, that horse already left the stable. Kindly asking people not to produce fake news is so far not working out for us. This AI will be replicated, likely very soon, if not already.
> problem would affect almost every site on the internet and
> almost every text-based communication channel.
Every text based channel is already compromised, if not by AI, then by bad actors. The only difference is that it's in lower volume than it might be with AI. It's only a matter of time before somebody else recreates this AI (I'm relatively sure I could with 2 solid months and some motivation) and the longer we delay, potentially the greater the threat.
Consider this in terms of anti-virus software, do you respond to each incremental advance in virus programming or do you wait until the problem is overwhelmingly bad and you don't have years of incremental research to support yourself?
> If burglary increased 100-fold, I don't think many would
> see it as a wake-up call to install beefier home security
> systems.
Even if this increased spam 100-fold, this wouldn't happen overnight. But by locking it away, researchers can not actively work on a counter solution - so when somebody invents a better AI and releases it, they are extremely ill prepared. Not only this, the people themselves are unprepared too.
I think in delaying the handling this problem, the potential for mass disruption increases - not decreases.
That means no more skimming threads to get the gist of what people are saying, no more skimming through answers on stackoverflow, no more skimming through articles.
An article that looks reasonable on a cursory glance only begins to fall apart when you spend (waste) time reading it carefully.
It also means anyone posting content must spend extra effort proving they are a human for their readers.
What if you could beneficially weaponize an AI to teach children/people a vast body of knowledge quickly on any given subject.
Please see the movie; Lawnmower Man
It would be slightly more coherent to at least point to a potential use case for text generation specifically.
[0] https://openai.com/blog/better-language-models/ [1] https://d4mucfpksywv.cloudfront.net/better-language-models/l...
“We made this super cool thing. It’s super dangerous. You can’t see it.” I mean, come on.
They can earn their reputation the regular way, and it will be fine. Sure they have the click baity DOTA demos, and maybe they are doing some interesting stuff. But OpenAI’s announcement of GPT-2 was particularly egregious.
If trained on massive sets of source code and briefs (or perhaps a set of unit tests), could it spit out functioning code based on a problem statement?
I'm just not well versed enough with ML to know if these things are a possibility or if it will just remix its training data in probabilistically correct, not-guaranteed-to-make sense ways?
Maybe it could transcompile or re-implement common algorithms to already solved problems.
This had about 10 million parameters though, compared to OpenAi's 1.5B. I don't think their text is nonsense though. There's some very interesting examples. They have since released publicly a 345M parameter version, there are some nice examples from that model pre-trained with modern poetry on this twitter account: https://twitter.com/rossgoodwin
Microsoft's latest Visual Studio 2019 beta (v3) has intellicode[0] support which is supposed to ML "guess" 'code' based on equivalent github similarities. I don't think it is quite near to what you are asking, but certainly part of the way there.
(autocomplete) 'Robert'); DROP TABLE students;--
It's better at making up bullshit, but it's still bullshit.
I am not an expert with machine learning, but it seems (at a very high level) we've done amazingly well at creating models that can recognize and sometimes recreate patterns. But they never seem to have any ability to understand the patterns. I'm sure someone much more knowledgeable could compare it to a child of whatever age (or maybe I'm just completely wrong).
Or, to put that another way, flipping the perspective around: our minds could consist of an intelligent, analytical, but utterly unimaginative agent, that sits there listening to a stream of suggestions spewed out by a distinct second agent, one that is "creative" but has no idea about the constraints of things like physics. The brain's analytical agent filters this stream of suggestions, taking notice of the suggestions that seem like they'll make the world change in the ways it "wants"†; and then it does those.
† Or, according to modern perceptual-control research, the agent attempts to predict the world that will occur a few seconds in the future, with a bias toward predicting world-states the reward-system has annotated as being rewarding; and then it looks at what motor commands it "would have" issued in that hypothetical world, and actually issues those. The stream of suggestions, in this model, serve as input to feed the generative model of potential world-states; the executive agent then must notice whether the potential world-state is a "possible" world or an "impossible" world (and whether the motor commands required of it are "possible" or "impossible" inputs), and filter out the "impossible" worlds.
Under this hypothesis, dreaming is the state when your executive responsible for filtering out "impossible" worlds isn't online. So you just get a continuous "impossible" world generated from the streamed suggestions of the creative-but-stupid bullshit-generating agent, with nothing to tear it down—just as seen in these generative AIs. As consciousness returns, the mental predicted world-state is noticed to be impossible by the now-online analytical agent, and is torn down.
That will be a lot of bullshit to filter out, if such agent doesn't provide more of less detailed description of what has to be generated. People with Broca's aphasia probably demonstrate a part of such input.
In other words, it could operate just as AI generative networks like GPT2 do, first receiving training input/output pairs; and then later, receiving input prompts and "completing" them by generating outputs.
When it comes to attacks, it's not the average-case which matters.
IMHO the more interesting story with GPT 2 is the hype around it as well as the (huge) backlash around its release. [self-plug coming] If interested, check out this summary of that whole story: https://www.skynettoday.com/briefs/gpt2
But this is for a smaller version of GPT-2 (~400M parameters). Since the bigger model (2B parameters) was deemed too dangerous by OpenAI.
Some details are available here:
Hm, why in the world would they not train it on Sci-hub articles and generate output for which we have plenty of domain experts who can judge the quality?
* Training on Sci-hub or book torrents would probably get them sued, so that's right out.
* The point of training the model on reddit-linked-articles with 3+ karma (not reddit comments, as the article suggests) is to filter out worthless content (spam or non-text pages) while still getting a large, diverse sampling of human writing. They're training huge models and they need as much data as possible to do so.
* Every native english speaker is a "domain expert" for the purpose of evaluating the model's results. The point at which we need subject-matter experts to evaluate the quality of neural-net generated research papers is many decades away; the excitement around GPT-2 is that it can generate coherent English sentences at all.