4 ms·
This is kind of a stupid argument. How about make a slightly stronger claim like "models won't break symmetric crypto" ? I mean, language models aren't even tra
by danielmarkbruce 2mo ago
This is kind of a stupid argument. How about make a slightly stronger claim like "models won't break symmetric crypto" ? I mean, language models aren't even trained to break symmetric crypto. There is not good reason to think they will. It seems possible to train a large model to do it though.
- catlifeonmars 2mo agoAgreed that many of the articles claims are a bit weak. One point is reasonably strong though: symmetric crypto may not be breakable (battle tested).
- danielmarkbruce 2mo agoIt probably isn't. But if you laid 20-1 I'd bet a large model will break an industry used standard within 10 years. That's a loose framing of a bet, but I think you get my point, even if you think my numbers suggest too much optimism.
- Monarch909 2mo ago[dead]
- tptacek 2mo agoTo train a large model to do what? Break AES? How would that work?
- danielmarkbruce 2mo agoTrain on plaintext, ciphertext -> key.
- tptacek 2mo agoLLMs aren't literally science fiction.
- danielmarkbruce 2mo agoWell, again, i'm not talking about a language model.... And, just because what I'm saying isn't especially likely to work, it's not obvious that it cannot. Very large models are doing all manner of things that very smart people thought were not possible just 6 or 7 years ago.
- insanitybit 2mo agoIt's unclear what you are talking about then. Because the idea of training "ciphertext -> plaintext" for language models is absolutely bonkers, so what are you suggesting?
- danielmarkbruce 2mo agoI can't tell if you are serious at this point. I literally say, twice, that I'm not talking about a language model. And I also say the model would predict the key...not the plaintext.
- insanitybit 2mo agoAnd I'm asking you to describe the model.
- danielmarkbruce 2mo agoOuput: 128 logits. Input: maybe 10 samples of plaintext,ciphertext (using the same key), so maybe a 2560 length tensor. Loss function: binary cross entropy on the true key bits. Architecture: anyone's guess. If you were in a place to debate this, you would have known the above (or something similar) is what I was suggesting when i said train on plaintext, cipertext -> key, and you'd have some deep mathematical insight as to why no architecture known is likely to work. And you would also know I wouldn't be here talking to you about it if I really had a solid idea of an architecture that is likely to work.
- inigyou 2mo agoI suggest you do this experiment yourself. You can try model architectures as big as your computer can fit. It won't work because these algorithms are designed to have no patterns at all. People have already tried. More classically, you can try feeding the problem into a SAT solver. People have tried that too. Doesn't work - it just grinds until you run out of memory or patience, finding no useful results. You can also try doing it by hand and see if you get anywhere (you won't). People have tried. This is an adversarial problem. The problem is literally designed to be resistant to all kinds of analysis. That's the point. Even real attacks, like SHAttered (different kinds of attack on a different kind of algorithm) manage to find conditions where the probability of finding a solution is raised to 2^-70 or so, and then they let it grind on their biggest compute clusters until they find one. And that problem (finding a collision in a cryptographic hash function) is one that's especially amenable to grinding. If you're mounting a known plaintext attack it's unlikely your adversary will answer 2^70 encryption requests for you.
- danielmarkbruce 2mo ago>> It won't work because these algorithms are designed to have no patterns at all Every encryption algorithm proposal has this property of being designed to have no patterns....
- inigyou 2mo agoAnd some of them still have no known patterns! Even the "broken" ones have only really subtle patterns. SHAttered was only 2^17 times faster than brute force. It took 2^63 attempts instead of 2^80 that bruteforce would take (which was arguably already too low).
- danielmarkbruce 2mo agoYup, sure. But my claim is that I believe it's better than 20-1 against that a model can break it. The fact that many encryption schemes have later been shown to be fragile and that very very large models seem to be able to things we can't explain well, and that you can create enormous amounts of training data for this problem makes my claim not so far fetched.