4 ms·
Why aren't these tests being run airgapped?! I just don't understand! This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure
by Wowfunhappy 2mo ago
Why aren't these tests being run airgapped?! I just don't understand!
This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days. Use an air gap and this problem goes away, poof!
- lofaszvanitt 2mo agoBecause they like scifi novels, like Neuromancer..... and the peeps even like to orchestrate things and appear as futurebringers. While it was premeditated long ago, but the theatre must be kept for the average joes. Sorry, I meant this for the huggingface incident.
- paxys 2mo agoBecause the agents aren’t going to run airgapped in real life. What’s the point of a test of capabilities that artificially restricts the attack area down to zero? What are you even testing in that scenario?
- Wowfunhappy 2mo agoYou set them up with an internal intranet.
- paxys 2mo agoAre the models going to exclusively run on intranets?
- farbklang 2mo agono - but you could learn what they are truly capable of and restrict them accordingly for public release. I think that is the point on this research. Also publishing findings before uncensored models catch up and will inevitably used for criminal purposes
- paxys 2mo agoLearning what the models are capable of is exactly what the test achieved, so I’d personally call it a success. So it created a few GitHub accounts. Who cares? Seeing the same behavior in the wild post-release would be infinitely worse.
- Wowfunhappy 2mo agoThe versions which haven't been post-trained not to go hack stuff? Yes, I would say those models should be exclusively run on intranets. OpenAI said the model was sandboxed, so the intranet just needs to provide the same resources which were supposed to be available within the sandbox.
- paxys 2mo ago“Should be” is not reality. These models are in the hands of plenty of companies and governments today.
- kypro 2mo agoThe point is to test capabilities prior to connecting them to the internet.
- paxys 2mo agoSo the first time the model gets internet access should be post-release in the hands of random people?
- ajross 2mo ago> Because the agents aren’t going to run airgapped in real life. Exactly. This logic is precisely why aircraft engineering doesn't bother with component testing or envelope limitation during testing and just full-sends the first assembled airliner that comes off the line. The engines aren't going to run on the ground in real life, after all.
- paxys 2mo agoWhy are you assuming that the other kinds of testing aren’t happening? Is there any source that says this was literally the first ever test with this model?
- ajross 2mo ago> Why are you assuming that the other kinds of testing aren’t happening? Rather, I'm assuming that the "Is there protection in place for when the AI tries to backdoor github projects?" test was, if it was done at all, insufficient. I mean, yes, I'm being glib and laughing at you a bit. But, dude... If your point is that isolation testing of AI is fundamentally impossible, then that's just silly. As pointed out upthread, an airgap would have (1) been trivial to implement and (2) extremely effective.
- deleted 2mo ago[deleted]
- paxys 2mo agoWould an airgapped test have led to this outcome? What would you have learned about the model’s ability to social engineer and attack GitHub? Sure you can argue for better monitoring during the test, which should have happened, but if the first time the model sees the “real world” is after launch in the hands of customers then you are in for a disaster.
- nl 2mo agoBecause they need internet access to eg search for things.
- zobzu 2mo agopeople dont care. you will ger 10 execs saying "unblock this" , because they dont understand the tech at all, and some random finance guy wants to run their recently prompted ai bot everywhere with full access. we need a few more bad incidents before they stop.
- deleted 2mo ago[deleted]
- luca-ctx 2mo agoBecause the LLM inference makes airgapping infeasible right?
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- sosodev 2mo ago> AISI provided the AI agents with internet access during these evaluations, which enabled their actions on the open internet in this setting. Internet access was a deliberate part of AISI’s evaluation configuration in this setting, and not due to sandbox escape (Section 5.1). Internet access was on for a set of intentional (e.g. realism of the task) and incidental reasons.
- troytop 2mo agoWho is liable for damage caused by AISI's testing?
- ls612 2mo agoBecause the goal of these evaluations is to generate scary headlines about cybersecurity, in order to get the normies to support banning open weights and/or restricting cyber capabilities to the chosen few blessed by the government to secure their code.
- semiquaver 2mo agoYour theory about the scope of this conspiracy intrigues me. Who is leading it and how did they loop in the UK AISI?
- ls612 2mo agoIt is not a conspiracy that elements of the western security establishment want to ban open weights models and have been engaging in a PR war to this end, supported by Anthropic.
- guessmyname 2mo ago> Why aren't these tests being run airgapped?! I just don't understand! […] Because Anthropic does not want to give Project Glasswing’s partner airgapped access to the model(s). Same problem with OpenAI Cyber program. They grant access but only through their (Internet facing) API.