OpenAI: 'The New York Times Paid Someone to Hack Us'
torrentfreak.com
torrentfreak.com
If I can reliably recite verbatim a 10 page short story then I 'contain' it even though you can't dissect my brain and find it.
If a LLM can reliably and repeatably recite an article verbatim then it 'contains' it even if you can't run 'strings' on the weights and find it.
Disagree? You might, but the court's opinion is what matters, and I think they'll go with the 'touch and feel' judgement not the 'bits and bytes' judgement.
“ OpenAI believes that it took tens of thousands of attempts to get ChatGPT to produce the controversial output that’s the basis of this lawsuit. This is not how normal people interact with its service, it notes.”
I think the substance of OpenAI’s complaint is valid - think of the word “hacking” as clickbait to the real heart of the matter which is that New York Times went to obscene lengths to reproduce meaningful amounts of article text and, by withholding their methodology, misrepresented the behavior of OpenAI’s product. There are much easier ways to get NYT content for free than making tens of thousands of attempts to reproduce an NYT article while violating OpenAI terms of service and repeatedly ignoring GPT’s refusals to an insane* degree.
*not normal insane, insane to the 10th power
https://arstechnica.com/tech-policy/2023/12/ny-times-sues-op...
And this is a screenshot of their session with copilot
https://cdn.arstechnica.net/wp-content/uploads/2023/12/Scree...
“ ChatGPT has apparently closed that loophole in between the preparation of that suit and the present. We entered some of the prompts shown in the suit, and were advised "I recommend checking The New York Times website or other reputable sources," although we can't rule out that context provided prior to that prompt could produce copyrighted material.”
If I tried to do what NYT did, I would:
- give up after a few attempts
- get worried that I’m going to be banned from using OpenAI (a rational concern, because it doesn’t take a lot to get banned)
- doubt the veracity of any “reproduced” text that I may receive
The equilibrium here is for OpenAI to suggest signing up for NYT and providing a signup link if it detects interest in doing so.
So I would argue you kind of need have make thousands of attempts. Merely a few tries just doesn't give you enough one way or the other.
This is one aspect what makes everything so tricky here, and how no one can be quite sure of anything.
The underlying models are in principle deterministic. There is random sampling used, but there is a pseudorandom seed parameter you can supply to get reproducible results. [0] However, while the OpenAI APIs expose that parameter, the consumer-facing ChatGPT product doesn't.
Well, almost deterministic. OpenAI has some internal-only config settings they can change which will change the results even with the same model version and seed; they expose a system_fingerprint value in the response which lets you know when they've changed those settings. (They don't document what it means, but it looks like it is likely based on an abbreviated Git commit hash from some internal config repo of theirs.)
And, apparently, there is a small chance it can generate different results even with the same seed and an unchanged system fingerprint. Apparently, different nodes can run different GPUs which can produce slightly different results due to differences in floating point rounding, operations being performed in parallel which finish in slightly different orders, etc. The underlying mathematics is 100% deterministic, so OpenAI can make it all 100% deterministic if they really wanted to. But maybe that has some performance cost, and maybe perfect determinism is not something they care about enough to pay that performance cost.
[0] https://cookbook.openai.com/examples/reproducible_outputs_wi...
From the article:
> But not all loopholes have been closed. The suit also shows output from Bing Chat, since rebranded as Copilot. We were able to verify that asking for the first paragraph of a specific article at The Times caused Copilot to reproduce the first third of the article.
OpenAI boasts constantly about 100+ million people using its ChatGPT product. By this logic 10,000+ users should be seeing results NYT saw. One in a million users are commonplace at scale.
1. NYT content is the only content OpenAI is plagiarising.
2. The only way to provoke plagiarised content is to specifically prompt for it.
[1] https://arstechnica.com/tech-policy/2023/12/ny-times-sues-op...
[2] https://www.nytimes.com/2022/12/07/science/oldest-dna-greenl....
I’d rather we didn’t normalise clickbait interpretations; that’s how words get their meanings diluted and corporations throw sand in our eyes. OpenAI is using a specific word to elicit a reflexive emotion from us to be on their side against The New York Times. Don’t fall for it, it’s purposely disingenuous.
Think about it for two minutes and there’s no scenario where this doublespeak looks good for OpenAI. Either they’re lying about what happened (not a hack), or they just proved they cannot be trusted with your data (they got hacked).
The people who were key in building our modern tech were Boomers, and a 60 year old person today was born on the edge of Boomer/Gen X.
Someone 60 today was 20 in 1984, when small "home computers" were already widespread.
Stallman is 70. Larry Wall is 69. Guido van Rossum is 68. Eric S. Raymond is 66. That young student Linus Torvalds is 54.
As I see it, the point of the parent was probably actually prejudice against the technical understanding among law professionals, with intersection of (about) 70 years of age relevant because those cohorts would often have had their education and early professional experience before computer technology became so pervasive that it's routinely involved in legal cases.
I'm sure law professionals can be just as capable as a 60-year-old of understanding that words in English can mean more than one thing, but there has been plenty of reporting on HN and elsewhere over the years indicating that in practice the chances of inadequate technical understanding affecting the outcome of court cases are significant.
What do you think about the apparently not blatant enough lawyerism? Is it justified, on the basis of actual competences out there and case assignments? Personally I think it seems like a valid concern.
Considering there is very little substance to the comment as a whole and that this is almost all there is to the comment, I'm not inclined to bend over backwards to give a good faith interpretation. It would be different if that comment was part of a more substantial comment. I'm not one to nitpick jibes or off-hand remarks, but in this case that's really all that was said.
When you have millions of customers, the thousands of attempts is a trivial number, and you'll have plenty of "abnormal" people interacting, but also plenty of "normal" people interacting "abnormally" , so that's a poor excuse
That being said, this is probably the first case that will determine the future of AI so staking a strong, extreme rebuttal is how the system should work, and the courts will decide the truth. It's going to be very interesting to see how this case progresses.
Preemptive Edit: "Truth" might not be the best word, but rather how this should be seen in context of copyright law. It's very unclear how AI will legally be allowed to operate since corpuses commonly include copyrighted material - this is a question, due to how US law is structured, that HAS to be litigated in court for a clear answer. Just because you don't like OpenAIs argument, and I don't, this is how the legal system is designed to work.
Edit 2: I feel many people are missing the point here (which I buried in the second paragraph, my bad) - This isn't some catty PR fight between NYT and OpenAI - this is the first major case about how LLMs/deep learning/etc fits in relation to copyright. This isn't about what is morally right, this is about do LLMs violate copyright law. NYT has made a strong case that it does violate copyright. OpenAI has some good and bad arguments (IMO 1 very good argument and the rest weak or bad) but they should be throwing their best arguments at the wall since that is how law works in the US. This won't be the last, but this is probably the first important case in the future of LLMs.
In that sense, it was hacking.
Otherwise the court document would read "NYT paid someone to creatively create a solution to generating copyrighted text" and would actually be praising NYT for that, instead it reads like they are damning them.
But can it be considered a bug if it's inherent and unsolvable in the system? Can AI truly ever be resistant against prompt injection or will it always be a series of patches to cover up unwanted behaviour? (Genuine question - I do not know)
If something is inherent in the design of the system I'd argue that it is not a bug and not hacking, just as it's not "hacking" to use a hunters rifle to shoot a human, despite it being "not the way it was intended to be used". It can still be illegal of course, but that's a separate issue.
More colloquially when someone says: 'someone tried to hack us', it means the hacker tried to gain access to the companies backend servers.
If they use that particular prompt that primes the model for regurgitation.
It's not one in a thousand of regular queries.
Oh no! Anyway...
Well that's horrifying news.... I hope this is in a data-processing capacity that's able to be independently validated and doesn't rely on the accuracy of its generated output. If only we could sue newsrooms for shoddy journalism!
Patent trolling when?
Getting OpenAI to spit out part of the prompt you provided in its output, and then claiming that it had been trained on that, seems dishonest. It shouldn't be illegal, but it also shouldn't be the basis of a successful lawsuit unless there's other context missing here.
https://arstechnica.com/tech-policy/2023/12/ny-times-sues-op...
And this is a screenshot of their session with copilot
https://cdn.arstechnica.net/wp-content/uploads/2023/12/Scree...
> by using deceptive prompts
A new nadir in the great multi-billion AI content grift.
If the "bug" is "we had a bad system prompt" ok then this is stupid. If the bug was "turns out if you pass a secret argument to a HTTP endpoint you can skip the system prompt" then this is a hack.