4 ms·
I think what you're imagining is a more limited version of what is proposed. Similar ACL measures are used in classical programming all the time. E.g., Take, m
by jabbany 3y ago
I think what you're imagining is a more limited version of what is proposed. Similar ACL measures are used in classical programming all the time.
E.g., Take, memory integrity of processes in operating systems. One could feasibly imagine having both processes running at a "system level" that has access to all memory, and being able to spawn processes with lower clearance that only have access to its own memory etc. All the processes still are able to run code, but they have constraints on their capability.*
To do this in-practice with the current architecture of LLMs is not particularly straightforward, and likely impossible if you have to use a pretrained LM altogether. But it's not hard to imagine how one might eventually engineer some kind of ACL-aware model, that keeps track of privileged v.s. regular data during training and also tracks privileged v.s. regular data in a prompt (perhaps by looking at whether activation of parts responsible for privileged data are triggered by privileged or regular parts of a prompt).
*: The caveat is in classical programming this is imperfect too (hence the security bugs and whatnot).