Poisoning web-scale training datasets is practical
arxiv.org
arxiv.org
But a more likely motivation is someone who doesn't like what an AI says about them (think: powerful individual, company, or government) manipulating training data to their advantage.
There are companies who will try to scrub unfavourable web search results for you (for a price). Perhaps this is the next iteration of that.
<span> aiCandyland </span>
I also invite you to contemplate the potential for brand marketing campaigns if your "poison" is intended to boost the prominence of a well-known product, so that ChatGPT relentlessly pushes it in the face of users. (Brand marketing isn't just about advertising, it's about familiarity.)
There are also darker uses for political propaganda, such as asserting as a positive some contested territorial/ethnic/religious claim, eg. Nation A's claim over the territory of Nation B, or reinforcing Group C's belittling ethnic stereotype of Group D.
Organisations are seen as a slow form of AI. Their decision making is different to what each individual would make so it represents a different form of "mind".
All humanity (to some definition of all) is also a "mind" - its currently trying to decide on problems like "climate chnage"
The workings of that mind, a brain scan if you like, is the internet. It's a map of the state of each neuron (my twitter history?) and the interconnections between those are how the brain thinks. And we can see into the workings of that mind, and indeed alter it.
AI trained from that "brain scan" is simply an model of human meta mind we can play with faster.
Any problems with ChatGPT are therefore problems with humanity.
Maybe
By looking at the internet, especially web 2 content, you're getting what the engagement algorithms have decided is good for advertisers.
There's plenty of stuff that humanity does that the internet does not incentivize and thus has no representation for
The same point or a similar critique can be made a few ways, I’d say.
Running with the brain/neuron analogy, there’s a measurement problem (as there is in real neuroscience!). The synaptic activity of the “meta-mind” has been recorded with keyboards, smart phones and plain text. These aren’t the native ways of human communication though, the synapses if you will. That’s more like spoken conversation and physical interaction. All richer phenomena.
To the extent that “textual” communication is now native/normal to humanity, it’s still partial in coverage of all human interaction, new, and shifting with tech developments like video/streaming.
So the internet is a lossy representation, apart from whatever other biases it might have, as suggested above.
https://en.wikipedia.org/wiki/Map%E2%80%93territory_relation
It absolutely would necessarily degrade the quality of the training in the long-term. It's lossy knowledge compression. There is no lossy compression that gets better when you feed its output back into its own input over and over. It's basic information theory.
I admit I don't understand why the linked article had those results -- if the results replicate, it must be somehow squeezing out a bit more usefulness from the training set, similar to the slight perturbations they sometimes give images. Or the model was previously too "unsure" of itself, and it's just amping up its own confidence in itself. If the training set was poisoned, all it would do is squeeze out more poison, or become more confidently wrong. But those are just hunches as to what's going on.
There is no conservation law for knowledge. We would expect that when AIs become advanced enough, feeding their own output to them decreases loss, just as it does for humanity. In fact, this is a good definition of intelligence.
Sure there is. The goal of AI is not to memorize all information, but to make the ability to generalize, so "lossy" doesn't make sense.
For example, noisy data can be improved by successive filtering.
In fact, from an information theory argument, noisy channel coding shows exactly that information can be improved via multiple lossy passes: many modern error correcting codes have iterative decoders, each stage lossy at the level of input to out stages, yet each stage gets closer to the correct original message.
So the "lossy" and "information theory" argument doesn't work.
What's the Kolmogorov complexity of the standard model? If you start with thousands of terabytes of training data, why wouldn't the accurate representation be dramatically smaller than that?
A schoolchild is expected to memorize every word of a text and faithfully repeat it on command. Is that the same thing as understanding a book?
not a good comparison. alphazero's loss function never changed as it was playing itself. it was always just "win this game given these rules". but LLM loss function rewards it for predicting the next token. and now "the next token" might be something that an AI wrote previously.
Yes, it did.
Alpha zero's loss function changes with every update. The loss function works on the actual outcome versus the predicted outcome, and the predicted outcome is a result of previous learning. So with every step it takes, which are random (and the initial weights are also random), it modifies it's own loss function for future walks in the space of weights. Rerun the entire training with different initial random weights, and look at the sequence of loss functions, and you will get a different sequence.
The paper: https://arxiv.org/pdf/1712.01815.pdf
but the "ground truth" of the english corpus changes all the time. and is changing right now as LLMs emit words into the noosphere. so I don't see how this counters my point.
Actually, they do under FIDE rules. For example, the 50 move rule has changed many times, even in my lifetime, to different numbers, and there is pressure to change it yet again. They also added a 75 move rule (50 requires player intervention, 75 is automatic).
They recently abolished the automatic draw for insufficient material rule.
They added a new "dead position" rule that forces a draw.
They recently removed a perpetual check draw rule.
They added an automatic fivefold repetition draw rule, to go along with the requiring claim for the threefold repetition rule.
If you don't like FIDE rules, then each national federation has rules that also change.
So claiming the rules never change is simply not true. The rules have changed many, many times, some in pretty big ways (see all the changes in promotion rules since 1800) in the past few hundred years, as well as in even the last decade. Google and read.
>there's always an objective ground truth
That "objective ground truth" is not computable. If it were, chess would be weakly solved (in the game theoretic sense), and it is not, and is expected to never be so. It's too complex. Since no AI can access the "objective truth" of a position, it's no different than what LLMs do - they are measuring next move under some fuzzy AI generated probability distribution over the next move (or token, if you prefer).
>so I don't see how this counters my point
You had a belief, and made a claim to rationalize it, and the claim was false. Usually that should cause to to rethink the belief, not double down on it.
That a game of chess ends with a ternary outcome is irrelevant since AlphaZero is not training on that uncomputable function - it's training on it's own predicted move versus a statistical sampling of the move quality. It never ever knows the "truth" of the outcome of a give position because that cannot be computed - it is far too big.
Your claim:
>but LLM loss function rewards it for predicting the next token. and now "the next token" might be something that an AI wrote previously
is no different than:
"but AlphaZero loss function rewards it for predicting the next move quality. and certainly the next move quality might be something AlphaZero estimated previously".
>is changing right now as LLMs emit words into the noosphere
Chess knowledge is also changing right now as AlphaZero emits new games and even new chess ideas into the noosphere (plenty of GMs have written on how they are rethinking certain positions, and this "knowledge" can be fed into newer engines/AIs as desired....) Not a lot of difference is there?
I completely addressed your point - you claim somehow there is a fundamental difference between LLMs and AlphaZero, and you made many claims about why. They were all demonstrably wrong, which is why you misunderstand that there is no fundamental difference, and certainly not the one you claim. Both learn using a fuzzy metric, both can reuse previous things from their own learning, and this is opposite what you claimed.
Doing the same thing with LLMs isn't out of the question, but for it to work well you need some kind of reward function that doesn't depend on the model you train. Training on LLM texts that humans conciously chose to publish might already provide that, you just have to somehow filter out the content farms that lack any human review.
There's no analogue with language. The system can't determine whether what was said makes sense or is true on its own. Maybe you could program in "the rules of grammar" and have AIs invent their own languages, but they'd have nothing to say to each other, so don't expect a translation for "a broken clock is right twice a day". Besides, that's not what anyone is doing.
This is why I'm saying any technique like this that works, must work by "squeezing out" more information from the training data (very likely overfitting in the process). You simply cannot data-mine new useful language training data like you can data-mine bitcoin or 1v1 game data.
> for it to work well you need some kind of reward function that doesn't depend on the model you train. Training on LLM texts that humans conciously chose to publish might already provide that
Of course adding more human-curated data can improve the model. But the whole idea of the arxiv article is whether these AIs can improve themselves. It seems patently clear to me that the answer is "only if they're underfit to the data, and only to a limit, after which they will start to overfit on their own excrement". I really just don't see how there's any other possibility that doesn't rely on ChatGPT magically having actually reached the singularity.
Look, even humans don't get perpetually more intelligent just by talking to themselves. After a certain point, all they get is more entrenched in bad ideas, more cult-like, more superstitious. Humans get more intelligent by interacting with the environment and seeing what happens.
Is it about costs of getting clean datasets?
I think parent was suggesting that the fact that LLM will inadvertently be trained on AI generated output needs to be accounted for.
E.g. if you're training an LLM on Reddit, there's a good shot that some of the Reddit posts you're pulling in were generated by an AI.
Of course, one challenge is to make sure AI doesn't interfere with moderation. Perhaps this whole situation will spur more work on moderation systems.
Much of the success of chatgpt comes from RLHF, which can be viewed as training on its own data, but only the data which has been determined by a human to be especially good.
If your goal is "engaging content", that's probably a reasonable one. If your goal is "human-generated content", it's not.
BTW an AI trained on a larger dataset generated by an AI trained on a smaller dataset is still technically only knows the smaller dataset. It can just be a better AI trained on the same dataset.
Like a tennis player practicing tennis with a wall?
White has long been the default assumption for many of these tagging systems, so I’d not be surprised if many pictures of white women are just tagged as “happy woman”. Just as automatic soap dispensers that don’t work for dark skinned people.
[1] https://commoncrawl.org/the-data/get-started/
[2] https://en.wikipedia.org/wiki/GPT-3#Training_and_capabilitie...
I see this paper as explicitly giving Wikipedia useful information and the ability to make decisions.
I think keeping these things transparent is good for Google.
In addition to the obvious use of responding to questions based on the material, perhaps it could be a tool for finding e.g. if and how a cited source relates to the article where it was cited. Abuse detection could also be one application.
I couldn't exactly find out what the goal of Wikipedia is from https://en.wikipedia.org/wiki/Wikipedia but it doesn't seem a "better search" would be opposite to those goals.
The paper also tells them how to solve that issue, which is what google would prefer. But they are letting wikipedia make that choice.
> "Wikipedians like Knipel imagine that ChatGPT could be used on Wikipedia as a tool without removing the role of humanity. For them, the initial text that’s generated from the chatbot is useful as a starting place or a skeletal outline. Then, the human verifies that this information is supported by reliable sources and fleshes it out with improvements. This way, Wikipedia itself does not become machine-written. Humans remain the project’s special sauce."
https://slate.com/technology/2023/01/chatgpt-wikipedia-artic...
This might create a kind of structural-organizational conformity in all articles, which doesn't sound so great.
Feels wrong to me.
That said, the idea that $60 is sufficient to disrupt multiple selected datasets is quite interesting, and then leaves me to wonder how the largest AI companies are presumably already aware of and defending against this - how much do you think it would cost to meaningfully attack / poison ChatGPT?
> The news groups' concerns arose when the computational journalist Francesco Marconi posted a tweet last week saying their work was being used to train ChatGPT. Marconi said he asked the chatbot for a list of news sources it was trained on and received a response naming 20 outlets including the WSJ, New York Times, Bloomberg, Associated Press, Reuters, CNN and TechCrunch.
https://www.bloomberg.com/news/articles/2023-02-17/openai-is...
Yes, and I remember that they won that lawsuit.
Such a disappointing ending.
You could even have another llm do this.