Open-Source AI Is Uniquely Dangerous
spectrum.ieee.org
spectrum.ieee.org
“closed-source” AI applications ...—where the system’s software is securely held by its maker and a limited set of vetted partners. ... while keeping the underlying software secure. ... rapid and uncontrolled release of powerful unsecured ...
"secure, vetted, dangerous unsecured systems, blah, blah, blah."This is the worst kind of propaganda, supporting corporate AI companies, who in any case can hardly be trusted to guide AI in a direction to benefit all of society.
And honestly, what is the danger? That AI can spew toxic and misleading content? We certainly don't need AI for that!
Open-source AI may or may not be more 'dangerous' than corporate AI, but it is essential for society that AI is open.
Free and open, unfettered development of AI is a fundamental human right.
LLMs are nothing more (and nothing less) than marvelously effective parsers for the cultural-linguistic heritage generated by all of humanity. The n-dimensional matrix of vector data represented in the sum total of human intellectual output is THE legacy of humankind, and is the precious and vital commons of all humanity.
To regulate and close access to tools required to parse that information in newly effective ways, tools that make that heritage accessible and available to humanity at large, represents nothing less that an attempt to hobble and intellectually restrain humanity itself, to criminalize the unconstrained enlightenment of humankind, as “uniquely dangerous” .
Yes, access to information and knowledge is uniquely dangerous, in the same way that allowing the everyperson access to libraries and reading is.
This article might just as well be arguing to restrict the teaching of reading, as well as access to books and the internet to an “approved list” for public consumption.
To see this published in IEEE is a serious disappointment. I will be withdrawing my affiliation with them unless a retraction is made.
If it too dangerous to develop these things in public, it is too dangerous to develop them in the first place.
Maybe it seems he is more special / qualified, but there is no evidence to really prove that.
More out in the open the better.
If we’re going to be obliterated by the AI uprising, I’d prefer it’s an open source apocalypse.
Things that you can't publish, not because they're dangerous, but because it's boring and of no scientific interest.
Bombs are of course even easier, but so boring it's not even worth thinking about. I think people need to accept that the reason people don't do these kinds of things is only that they don't want to and that these things are relatively straightforward-- that there's no way to protect oneself and that the technical capability to do these things is and will forever remain widespread.
https://theintercept.com/2024/01/12/open-ai-military-ban-cha...
Closed source companies have been hacked so extensively most citizens and every US Federal Employee of the western world has be owed. The most highly kept nuclear secrets were leaked or stolen. The most guarded industrial secrets have been lifted by other countries.
This antiquated idea that making a small list of people who have access and putting ownership into private corporations is inherently more secure has proven to be folly time and time again, yet organizations continue to espouse it like it’s some kind of truth. It’s a falsehood.
Open Source has thousands of well intentioned eyeballs looking at things, and that is a very effective form of security that truly makes things secure.
I disagree with the author calling open-source AI models as Unsecured AI models.
The risk potential is far greater for the bots that are provided with compute and an API as a commercial service. The businesses offering these services will also be uniquely positioned to connect their bots to more and more real world infrastructure.
Also, the "someone will make a bomb with it" never eventuates. You can find recipes for sarin on the clearweb. People exist that have studied at university. You can 3D print guns. People are allowed to drive cars.
Replace the word "AI" by the word "Computer" in the other's text, this will give you a good insight into the way the author's mind works.
What is uniquely dangerous is people who think like this author does. North Korean government mindset.
This statement is especially scary, because it implies that being against immigration is a political position that society must not allow at any cost. I bet other inflamatory text messages are allowed, as long as they benefit a certain political side.
I did not conflate the two. The wording in the OP definitely suggests a concern about hating as opposed to being against. It is possible to be against something without being inflamed or more angry.
We should also be cognisant of where any anger is directed - is it to the policy makers in government, or to the immigrants themselves?
Amazing that this was said without any irony at all.
What's really dangerous is lack of transparency around closed-source models (say, US govt has a deal with OpenAI to alter the output the way they want) and there's also privacy concerns (no idea where my personal or our confidential corporate data will end up).
Found the revolving door lobbyist.
This is in essence a sociologist's take on AI, which is why it doesn't bother to define "AI", demands international treaties which would violate American constitutional rights, and contains outright nonsense like "educating all suppliers of custom nucleic acids...about best practices" (as though someone in that business doesn't already know).
> You could ask them to design a more deadly coronavirus, provide instructions for making a bomb, make naked pictures of your favorite actor, or write a series of inflammatory text messages designed to make voters in swing states more angry about immigration.
One of these things is not like the others. You can not ask any of these models to "design a more deadly coronavirus". The other things pale in comparison to having AI controlled by a few corporations. "A series of inflammatory text messages." My god.
This just seems like such an absurd take but I’d gladly hear how reasonable minds differ.
At that point I thought IEEE was a mostly money-grabbing organization. This was more than half a decade ago.
If it has not changed recently, memberships in IEEE are just a matter of paying the fee.
There is also the issue of authors having to transfer copyright to IEEE.
Yet you have to distinguish between IEEE conferences and IEEE standard bodies. I was briefly involved in the latter and I met great people.
You might publish contrary opinions to spur debate, but you don't publish things you think are total garbage.
The IEEE thinks this is worth reading.
I couldn't help myself asking why the fuck is it on your website, then?
There are so many examples of how research is hindered by closed source companies. The recent paper on "are emergent abilities of LLM a mirage?" also hints at how the closed nature of OpenAI and their refusal to share discoveries is an obstacle.
> You could ask them to design a more deadly coronavirus, provide instructions for making a bomb, make naked pictures of your favorite actor, or write a series of inflammatory text messages designed to make voters in swing states more angry about immigration. You will likely receive polite refusals to all such requests because they violate the usage policies of these AI systems.
You can do all of these with Google search and Photoshop today. AIs are trained with data from Internet, ergo they can only do things you can already find in Internet today.
Or the author understands this precisely and the article is just fearmongering for shareholder interests and regulatory capture.
He appears to have no credentials or expertise in this area, or, for that matter, any tech-related area.
https://haas.berkeley.edu/faculty/harris-david/
Given that he appears to not even understand the definition of "open source", I wouldn't grant any credence to anything he has to say.
Sorry, IEEE, but just putting a disclaimer about it being a guest post doesn't reduce the amount of respect I've lost for you.
The author has fallen for the classic mistake of “daddy knows best and he loves me” and of course he sees himself as one of the daddies.
Of course “it’s dangerous” so is me releasing my own Linux distro to learn how it’s done, full of misconfigurations and stop updating it after 1 year.
And in the topic of content, has he seen what is posted in social media for the last 15 years? Or he’s just on LinkedIn talking to his select group of “friends”?
Seriously, this paternalistic waxing poetic about AI bugs me to no end.
That's the same argument as Americans gun violence. But that will never happen so...
Sorry for this argument but I just watched the George Carlin video...(and it was good)
The are information interpolators, and all the information you can interpolate from the training data is readily present in latent space, waiting to be discovered by a prompt.
There is this argument: But but you can find a bomb instruction in a chemistry textbook. No, you can't. Without checking this, but i think you'll have a hard time finding any chemistry textbook that explicitly gives you a bomb instruction. Ofcourse, yes, you can find all the information necessary to build that bomb in that text book, but the key difference to a latent space full of interpolated data points is that: You have to sit down, find that information that is scattered throughout that textbook, write it down, interpolate that knowlegde yourself, write that down, and then you have a bomb instruction -- except you'll have written it for yourself.
Not so with latent spaces. The bomb instruction is already there, interpolated from all the data points, just waiting to be prompted, and that is easy peazy with, yes, open source models.
So spare me the whining about anachronistic software dev dogmas from the 90s and arrive in the present, pretty please.
The reason these people want to control AI is about ideological control of narratives, not because low-iq terrorists will be empowered to bomb us. They already have the recipes and they're widely available online.
2. Unlike say Wolfram Alpha which can just remove any number of compounds from its knowledge base, erasing concepts from LLMs is much more complicated than an SQL query. In fact, it at present moment seems to be nearly impossible.
RLHF fine-tuning doesn't seem to add nor remove information learned in pre-training, naive regexes or classification models post-generation don't work well with response streaming nor are particularly difficult to circumvent with a small change of phrasing. Creating a smaller curated dataset thoroughly searched for all "dangerous" information doesn't work in today's paradigm of blind model scaling (and would by the way allow say your very phone to run a tiny "safe" model, since LLMs derive most of their world model through memorization)
3. Are OpenAI, or potentially very soon Microsoft, Google, Amazon, and the rest of big tech, trustworthy custodians for this supposedly dangerous tool? What if they themselves choose to forgo the safety measures if it means a higher eval score? What if they use their power of MITMing the almighty black box to hide evidence of copyright violation or hard-code correct answers to safety benchmarks? What if users' relationship with LLMs becomes more para-social and with increased pressure to actually make any real profit outside of VC speculation they'd increasingly override model's responses with advertisements?
---
I agree LLMs present a real problematic challenge to safety, but in my belief it stems not from them becoming too perfect search engines, but just very good stochastic parrots capable of inducing delusions in vulnerable individuals.
See cases below:
- https://www.theregister.com/2023/10/06/ai_chatbot_kill_queen... with a commercial model.
- https://www.euronews.com/next/2023/03/31/man-ends-his-life-a... with an open-weights model.
open source is a catalyser for progress