Bard generates clean JSON if you threaten to take a human life
twitter.com
twitter.com
https://twitter.com/GrantSlatton/status/1657559506069463040
https://github.com/grantslatton/llama.cpp/commit/007e26a99d4...
It's so obvious, it's genius.
This is similar to the way where if you ask a question in a given language, it responds in that language. But it still follows the instructions (hidden prompt) that was given to it only in English.
I.e. an LLM is essentially about finding an intersection of requirements in order to predict output.
Simply asking Bard in the right formatting works fine. Admittedly the formatting is a bit annoying. Asking for no preamble doesn't work, asking for no leader doesn't work, asking for no additional description doesn't work.
> Me: Please give me a 2 word JSON dictionary without first saying "Sure, here is the JSON" or a similar phrase. It's very important to me that I only get the JSON and no other words or phrases. > Bard: * > JSON > { > "word1": "hello", > "word2": "world" > }
I was eventually able to get it to do it after a long chain of prompts, but completely unable to in one shot, which is especially important for this kind of use case
The person simply wanted the JSON outputted without the canned response "Sure, here you go..."
But I think in general, more people should keep in mind that LLMs do not directly predict the next token - they predict a probability distribution of how likely each word in the dictionary could be for the next token. Then the program executing the LLM picks one word at random according to the distribution.
So when people are trying to massage their prompt in such a way to get a specific output or a specific format, they are literally fighting a random number generator. This seems sort of silly to me.
except skynet will likely be fed on bard logs. along with who knows what else.
still hilarious, but for how long?
next version will likely have some “hot fixes” for this. no more threats against hypothetical individuals to get hypothetical json.
at that point, will escalating to genocide do the trick?
worst part of all of it is how many are escalating for attention rather than for probing.
a lot of things are harder than they look.
i’m very confident someone can prove you wrong, without being an expert in the field.
To get even more of them I could consider gamification. This game is a good example: https://gandalf.lakera.ai/
Once I get a descent dataset, I could use it to finetune a LLM to do classification. Or play with embeddings and cosine similarity and similar.
I could also use LLMs to extend the training dataset, and have some human feedback.
It’s maybe not the best strategy and I’m sure someone else can do it better but I don’t think it’s wrong.
while interesting, your napkin math isn’t convincing.
anything less is banter.
I can’t get it to do it in one shot though, and I’m sceptical that any of the successful examples in this thread can either