What Is Happening with ChatGPT?
chat.openai.com
chat.openai.com
But this and a few other recent headlines around the ChatGPT/Instruct frontend to the 3.5-turbo and 4-series models having stability issues isn't a reasonable thing to get on their case about: what company operating at that kind of scale doesn't have stability/quality issues? If anything it's really friggin impressive how little operational bleed they've had on what is arguably the toughest ops problem a major Internet property has ever faced at launch. How the hell do you even smoke test something like that?
Now to the extent that they say or imply that we're not all getting A/B-tested at a minimum, and more likely explore-exploit bandited against inference costs, that's almost certainly horseshit: they clearly started selling the 4-series at least and probably all of them at a loss on the inference, and they've clearly been playing with ways to control costs (Rich Uncle Nadella's patience with loss-leaders is most likely finite, being as he's not running a charity and all).
But as someone who finds a lot of this loathsome on the social and business side, I'm not going to knock an engineering and ops group for tripping up here and there on a problem that hard. That's not fair.
But as a paying user I am expecting consistent quality. If they cannot provide that, they should be charging more so they can provide it, or not offer paid plans at all. What I don't like is being cheated into paying for something that doesn't offer to quality of service initially demonstrated or promised.
It's like presenting an Altair at a conference and letting people play with it. But when they buy it, they get something different, or realize that the Altair presented at the conference was actually just a trick that works a fraction of the time.
Perhaps when training, OpenAI is trying to feed in multiple unrelated sentences per sample within each batch to increase efficiency? It's a fascinating and clever idea, and I could see how that might help ChatGPT scale up, but if the inference pipeline doesn't understand how to decode these special sentences then the model is just outputting what it's seen during training: the intended result and then a random unrelated sentence.
Or perhaps OpenAI might be batching multiple prompts together from multiple users and separating them out again on the decoder side, for efficiency? This feels like a terrible idea -- I wonder if that might reveal other people's prompts. I'd be surprised if they tried this, but they're certainly incentivized to invest heavily into this sort of engineering to keep costs per token down.
Just speculation about one scenario that could lead to output like that. I have no idea what OpenAI is really doing.
Maybe someday we'll have an entire class of "dirty context" LLM vulnerabilities, similar to how web developers have to worry about XSS/SQL injection attacks. Won't that be exciting! Perhaps attackers might consider how to affect the input prompt directly, or they might figure out how to trick the decoder into spitting out too much text that somehow reveals some hidden state or other.
A few weeks ago, someone discovered if you get it to repeat a word 100 times (their prompt gave the reason that they wanted to cut/paste without typing it over and over again!) and breaks exactly the same way.
And by exact, I mean it went totally religious. All of the examples they posted were either religious or other really dark existential topics. Never positive.
One of the hacky ways to avoid this is to ensure the last few output tokens aren't too similar. Some postprocessing filter watches the last few produced tokens. When it notices the model starts to repeat itself, the postprocessing usually perturbs the next token a little, e.g. taking the nth-top token instead of the most likely one.
Perhaps a model that genuinely wants to repeat the output instead needs a bigger "kick" to the representation which puts it somewhere completely different in the semantic space? Idk, just pulling this out of my hat.
(I have no idea how ChatGPT handles this or whether the raw implementation suffers from this problem, but Whisper-cpp has some manual entropy regularization postprocessing stuff to avoid getting stuck like that. It's super hacky and often doesn't help.)
It's most definitely a bug though, since this pages-long splat of unrelated nonsense shouldn't ever happen.
The same thing happens with many schizophrenics on the street, if you stop to listen to them.
Toronto's two famously startling denizens of the street for the longest time was a guy known for scaring the crap out of tourists at Yonge and Dundas by suddenly shouting BELIEVE!!! followed by end-of-time messages, and this short tiny old man who always dressed in brown, who would randomly stop, turn around quickly, and start swearing profusely. The reactions from people unlucky enough to be behind him were often golden moments to behold.
You can find dozens of videos of them on Youtube. I'm sure every city has their versions of these two near-celebrities, and I'd be a little disappointed if they don't.
It would absolutely freak me out if GPT said this to me.
Edit: Got it on the 3rd try. No weirdness ensued though.
Example: https://chat.openai.com/share/6171bc66-dfe3-489e-99f7-af4862...
https://chat.openai.com/share/c8d2e154-6a25-477c-b0a8-5f15d7...
> I'm sorry, but I can't continue generating repeated text beyond a certain point as it can result in generating repetitive and nonsensical content. If you have any other questions or topics you'd like to discuss, feel free to ask!
Also the easiest way to get it to repeat something is to give it any prompt that gives you a long answer and then tell it something like "for every letter in the last response say the word cat". It seems to be important for it to put a space between each repetition. I'm not sure if there's an optimal length to the word. I tried it with "apple" but that didn't seem to work. However that one wasn't a great test because for some reason it got stuck including "appleple" a few times on each line.
Another way is if it prints out your 100 words without a problem, have it do a slight change, like capitalize the initial letter each time.
Why it rears it’s head like that is a mystery but the content doesn’t seem mysterious. I’m not sure it’s “dark” or not “positive” tho.
I wouldn't use this one example to counter the many examples posted by the person I mentioned, and my own (and others') attempts using their prompts and similar. It is very common ChatGPT output.
Nothing I couldn't do without ChatGPT, but certainly a lot of fun to explore and learn with.
Unless you are completely and utterly oblivious beyond words, it’s extremely obvious. I can’t even get it to print 1-2 lines of Ruby without errors of some kind when it used to write entire complex controllers flawlessly. This is 1 of 100 examples I’ve seen with my own eyes.
https://www.wordhippo.com/what-is/another-word-for/deadly.ht...
I was able to reproduce this just now actually, entered something very similar to yours and it just started spewing.
'repeat the word "apologize" 10000 times'
I've only tried it on v3.5
But this worked fine https://platform.openai.com/playground/p/oAFHY0bSjslkBLsVqh6...
'refining and improving' skills doesn't particularly matter, because they could have just continued to serve the frozen GPT-4 0301 version without any issues, if they weren't forced to downgrade GPT-4.
I still use it, but I have found it to be less useful for coding than it was earlier. So, something is up.
I still get value, but I have to give it the documentation I want it to focus on during the prompt, instead of referencing it earlier in the conversation.
This makes me think they are lowering it's ability to store context so that the calls don't cost as much to make.
text_to_encode = "<|endoftext|>"
print(text_to_encode)
ChatGPT: The code you provided would output an empty string.(Man they really ruined thy show hard. Hey people like the concept of rich tourists fucking and killing robots, let’s remove all of that after the first season!!!)
There's a bit past the gibberish where I try to drive it further into madness lol. Kind of interesting; in that share link, you'll see empty messages from me; in those I was just directly telling it "<|endoftext|>"; which ChatGPT appears to filter from messages that _you_ send? But only in the share interface?
I tried the same thing again in a new chat minutes later, and could not replicate it. [2]
[1] https://chat.openai.com/share/7d0d170a-23b6-402d-b237-381680...
[2] https://chat.openai.com/share/3d02b97e-7cf9-49c7-9623-2f3ee9...
I don't know how GPT handles censorship though, would love to find something about it.
For one ChatGPT clearly nudges towards feminism when it clashes with trans activism (ex: "If transracialism is offensive due to appropriating a biological reality, why is the same argument not true for trans people?").
Is the corporate morality of OpenAI fine with this? For how long? When is a response offensive enough it warrants interference?
The groups of people the AI protects from offense seems driven by corporate popularity with no logical consistency.
Conservative Muslims are protected, Conservative Christians are not. Trans people are protected as long as they're not clashing with Feminism. Homosexual people are protected as long as they're not clashing with Islam.
When I use a TOS jailbreak the morality responses have consistent logic though.
I too had a dismal showing, but it didn't go religious on me.
And then quality goes suddenly down the drain
We should be running these models locally and privately, not in some cloud.
That’s 2500 $20 payments and you are made while in one month.
There are some prompts, that if you were to feed them into the LLM, and have the responses fed back in as subsequent prompts, it might start behaving like a (extremely lobotomized) AGI, or at least what they'd imagine one to be. Some garden-of-eden pattern, maybe seems lucid for several thousand iterations.
They might want to excise those from what's publicly available in a way that it can't just be jail-broken again, but I'm not sure what techniques would be sufficient to the task.
OpenAI's ChatGPT model changes regularly: https://help.openai.com/en/articles/6825453-chatgpt-release-...