80 karma · joined September 7, 2017
As for the card example it is on you to keep secrets secret. It is clearly a fault with how credit cards work and for things like that you should get insurance. Keep your card safe, or better yet, use cash. We can call it theft, doesn't matter to my point.
There is no "taking" or "grabbing" anything, I visited your website and was served a copy of the data because you made it do so. You wanted it to happen, for the public to see it, that was your goal. You expected it to happen. Do you disagree that me acquiring a copy was consensual? If so it is very different from the hypotheticals you're posing don't you think?
Once a copy is in my possession you would need to initiate violence to stop me from training a model on it which puts you on the wrong side of the moral line.
Do I really have to explain this? You know I don't. Do better.
Okay, extract the images from a Stable Diffusion checkpoint then. I'll wait.
It's not like lossy compression CAN'T be fair use or transformative. I'm sure you can imagine how that is possible given the many ways an image can be processed.
> All the corporations that are offering AI as a paid service?
Am I them?
Also who said anything about selling?
To train a model on the data.
edit: the webpage does call it "Stable Code Completion"
We know it can copy parts of the context and the system prompt while a special part of the context isn't immune to being copied.
You can test it yourself by adding random strings to the system prompt, you can consistently have the model copy them over. Is that not enough to have a reasonable belief that the model can copy system prompt instructions in the web interface?
I really want that Azure information and whether prefilling works there as it does with Claude or not. Can you provide that at least before you walk away?
We were not talking about that model and I'm 99.999% sure you do not use that model. You might as well mention text-davinci-003 and all the legacy models, you're muddying the waters.
> b) Even the chat tuned version does completions, if you go via Azure and use ChatML you can confirm it for yourself. They trained the later checkpoints to do a better job at restarting from scratch if the output doesn't match it's typical output format to avoid red teaming techniques.
Don't fucking say "even", I know you know I know it can technically do completions as it is just GPT, the issue is what they do with the prompt in the backend.
I do not have Azure to test it, that is interesting but how come you're only mentioning it now? That's more interesting. Anyway, are you sure you can actually prefill with it? You saying that it restarts from scratch tells me it either isn't actually prefilling (and doing a completion) or that there are filters on top which makes it a moot point.
The documentation doesn't mention prefilling or similar but it does say this: This provides lower level access than the dedicated Chat Completion API, but also [...] only supports gpt-35-turbo models [...]
Shame.
> What you keep going on about is the <|im_start|> token... which is functionally identical to the `Human:` message for Anthropic.
Now you got it? Jesus Christ, but also no, I mean "\n\nAssistant:" which is not added on in Anthropic's backend like OpenAI does, you have to do it yourself as stated in the Anthropic docs which means you can use it as a completion model as stated in the Anthropic docs, which makes it trivial to bypass any and all refusals.
When did I say that? I said they work differently. Claude has nothing in between the prefill and the result, OpenAI has tokens between the last assistant message and the result, this makes it different. You cannot prefill in OpenAI, Claude's prefill is powerful as it effectively allows you to use it as general completion model, not a chat model. OpenAI does not let you do this with GPT.
What fucking user, man? Is it not painfully clear I never spoke in the context of deploying applications?
Your issues with this level of prefilling in the context of deployed apps ARE valid but I have no interest in discussing that specific use case and you really should have realized your arguments were context dependent and not actual rebuttals to what I claimed at the start several comments ago.
Are we done?
Would you say the same if the sentence was given as an example in the user message instead? What would be the difference?
> Frankly comments like yours are why people are so dismissive of LLMs, since you're banking of precognition of what the user wants to sell it's capabilities.
I'm not banking on anything because I never fucking mentioned deploying any fucking thing nor was that being discussed, good fucking lord are you high?
> you're going full Clever Hans
I'm clearly not but you keep on building whatever straw man suits you best.
I DID NOT say that any ONE prefill will make it bypass ALL disclaimers so your "You don't seem to understand that simply getting a result doesn't mean you actually bypassed the disclaimer" is completely unwarranted, we don't have the same use case and you're getting confused because of that.
It can fail in which case you change the prefill but from my experimenting it only fails with very short prefills like in your example where you're just starting the json, not actually prefilling it with the content it usually refuses to generate.
If you changed it to
``` "{ "result": ["you are very annoying.", ```
the odds of refusal would be low or zero.
For what it is worth I tried your example exactly with Claude 2.1 and it generated mean completions every time so there is that at least.
I said that prefill allows avoiding any refusal, I stand by it and your example does not prove me wrong in any shape or form. Generating mean sentences is far from the worst that Claude tries to avoid, I can set up a much worse example but it would break the rules.
Your point about how GPT and Claude differ in how they refuse is completely correct valid for your use case but also completely irrelevant to what I said.
Actually after trying a few Claude versions as well several times and not getting a single refusal or modification I question if you're prefilling correctly. There should be no empty "\n\nAssistant:" at the end.
But I do know how it works, I even said how it works.
The distinction is not without meaning because Claude's prefill allows bypassing all refusals while GPT's continuation does not. It is fundamentally different.
I really don't think so unless I missed something. You can put an assistant message at the end but it won't continue directly from that, there will be special tokens in between which makes it different from Claude's prefill.