Time to act on the risk of efficient personalized text generation
arxiv.org
arxiv.org
The paper makes some good points - it doesn't take a lot of data to convincingly emulate a writing style (~75 emails) and there is a significant gap in legislation as most US "deepfake" legislation explicitly excludes text and focuses heavily on image/video/audio
All our written interaction will have been polished and enhanced by one LLM or another into a uniform template.
That said, I suspect this won’t remain true in literary circles nor in certain professional contexts - where word choice is an art or signal, it will remain valuable. Politicians won’t sound like ChatGPT, for example. Think of some of the most famous modern politicians… they all have a unique way of speaking that makes it clear who’s talking.
"That said,"
...is a bog-standard ChatGPT-esque way to begin one's "summarize and wrap up" paragraph :D
Isn't that just a natural continuation of a global homogenization of human culture and experience?
If you visit anywhere in Europe, or Asia, or the Americas you now have virtually the same 'a la starbucks' coffee culture (even in countries with strong cafe cultures). Same lighting, same minimalist furniture, same music.
Couples now take the same style of wedding/newborn photos across the globe.
Music globally has become less, not more, diverse.[0]
A loss of writer's voice or style would be just another step in this global 'blandenization' of human experience/aesthetics.
[0] https://www.smithsonianmag.com/smart-news/science-proves-pop...
-- Hannah Arendt
There are bloggers with distinctive writing styles, but most bloggers write in a fairly generic "blogger style", a bit like the writing equivalent of the ~universal "youtube video essay voice".
I would say the prevalent of automatic spelling and grammar checkers has has a bit of an influence. I find Outlook often "corrects" something I write to an alternative style that is not any more correct than what I wrote.
- the corporation running the AI
- the user
- the AI, sometimes - depending on the particular conversation's ascription of agency to the AI
It seems the downstream harms are of 2 kinds:
- social engineering to give up otherwise secured systems
- 'people engineering' - the kind of thing people complain about when it comes to recommender systems. "Mind control", basically, y'know. [0]
Things like r/LocalLlama and the general "tinkerer" environment of open source AI makes me wonder if it wouldn't be rather trivial in some sense for users to build the same capabilities but for personal protection from malign influences. Like a kind of user-controlled "debrief AI". But then, of course, you might get a superintelligence that can pretend to be your friend but is actually more like Iago from Othello.
But is that really a likelihood in a situation where the user can make their own RLHF dataset and fit it to the desired behavior? Generally I'd expect the user to get the behavior they were looking for. Plus, like immune system memory, people could continually train new examples of sleights into it. I guess maybe there could be a hint of the "Waluigi problem", perhaps.
[0] I think it does the people who are distressed about it a disservice to saturate all their news channels with reports about how they are utterly incapable of outwitting an algorithmic super intelligence. But that's a different discussion altogether
Yes the implication of AI in economics and society is like that of scraping, spam, scalping or fraud, ie leading to an arms race. Insurance companies denying claims, citizens fighting back filing appeals with AI. Captchas and fingerprinting to protect against bots, that use OCR and now AI to bypass the defenses.
Well, this idea of increased net productivity relies on the fact that we don’t waste the excess on fighting each other in the same games we were playing all along. It’s like a feud between tribes going from sticks to swords to guns. It’s only when you replace the zero-sum activity with a positive value that the world actually improves.
The techno-optimists see only potential in an all-else-equal world, which isn’t the world we live in. Potential is irrelevant in the face of incentives.
None of the watermarking methods I have seen work in this way. All of them require extra work at inference time. In other words, Gemini might have watermarking technology on top of their model, but if I could download the weights I could simply choose not to watermark my text.
Stepping back, in section 6 the authors don’t address what I see as the main criticism: authentication via writing style is extremely weak and none of the mitigation methods actually work. If you want to prevent phishing attacks I would suggest the most salient factor is the identity of the sender, not the style of writing of the email itself.
Another thing that annoys me about these “safety” people is they ignore the reality of running ML models. Getting around their “safeguards” is trivial. Maybe you think it is “unsafe” to talk about certain Tiananmen Square events. Whatever change you make to a model to mitigate this risk can be quite easily reversed using the same personalization methods the paper discusses.
The risk is that any one of us peasants can do it without having to have a bunch of other people in on it
I’ve done some content work using LLMs. Once I started to think about how inevitably it’ll get coupled with ad networks and how anybody can do this stuff, it made me go this isn’t good.
On the bright side, it might push us back to paper or other means of exchanging info. The cost should be prohibitive enough that it increases the quality of content. That’s very hypothetical, though. Mailers are already a direct contradiction.
Ordinary people have trouble seducing other people because they can't deliver perfect mirroring because of their own self (e.g. they are uncomfortable adapting to another person's emotional demands because of the needs of their own self or aspects of their self that are unappealing to the other person manifest) Sociopaths and people with narcissistic personality disorder do better than most people precisely because their self is less developed.
An A.I. has no self so it has no limits.
Look this is not fancy work. But writing about limiting models is just useless when it comes to fraud prevention. Why are we talking about watermarking models? Because it's easier than doing the hard work of policing money flows.
Humanity has already seen harmful effects from social media algorithms that efficiently identify content a person can't turn away from even if they consciously want to. The prospect of being able to efficiently generate media that will be maximally persuasive to each individual viewer on any given issue is terrifying.