| ▲ | ajyoon 6 hours ago |
| To everyone here pushing for total proliferation of open models -- what should be done about open weight bioweapon and cyber-offense capabilities? Is it simply the cost of freedom that we should allow attackers to access these tools? The OpenAI / Hugging Face incident shows what a GPT 5.6 level model can do off the leash; within ~6 months, open weight models will match this and every bad actor under the sun will be able to pull off attacks at this scale. Do you seriously want this level of capabilities to be generally available with no guardrails? The open weight issue has a lot of difficult nuance. Biasing toward supporting openness makes sense and is a good instinct, but it's incredibly naive to be absolutely in favor of it in every circumstance without seriously thinking about its implications. |
|
| ▲ | artrockalter 6 hours ago | parent | next [-] |
| The Hugging Face incident is a great example of why open source models with defensive cyber capabilities are needed. Hugging Face did not have access to cyber-capable frontier models and kept hitting safeguards. Only by using the open source GLM-5.2 were they able to survive an attack. A world where open source models are banned is one where cybersecurity is impossible if you're not on OpenAI or Anthropic's allowlist. |
| |
| ▲ | ajyoon 6 hours ago | parent | next [-] | | Hugging Face survived the attack because the OpenAI model only cared about accessing the ExploitGym dataset; by all appearances, HF was completely owned. GLM-5.2 was only used to assess the damage after the fact. Cybersecurity has a attacker-defender asymmetry that heavily favors attackers. If GPT-5.6 were open sourced today, do you think every hospital in the world would be able to use it to shore up their defenses before attackers got to them? | | |
| ▲ | tekacs 5 hours ago | parent | next [-] | | This is completely backwards. Cybersecurity has an attacker-defender asymmetry that heavily, HEAVILY favors defenders. For starters, a defender gets to pick the surface area, an attacker has to work with what they're given. | | |
| ▲ | dwaltrip 4 hours ago | parent | next [-] | | The saying that stuck with me was "defenders have to be right 100% of the time, while attackers only have to be right once". You are suggesting this isn't correct? > a defender gets to pick the surface area What do you mean? You don't pick what you need to defend. Unless you choose not to build a feature. But that's a product design choice... Not a cybersecurity strategy. | | |
| ▲ | sudosysgen 3 hours ago | parent [-] | | > "defenders have to be right 100% of the time, while attackers only have to be right once" If you have an adaptive system that can react to attacks flexible (say, your own AI agent), then no, that's not correct. It is correct in the classical conception of cybersecurity where the defender is basically static. | | |
| ▲ | pastel8739 2 hours ago | parent [-] | | Doesn’t this “adaptive system” just become part of the static defense? The same way that a bit of code that checks passwords against a db is “dynamic”, the options are either to beat the dynamic system (guess/phish a password, trick the AI) or find a way around it (use “forgot your password”, find a place that isn’t covered by the endpoint protection feeding the AI). I don’t see how inserting an agent somewhere fundamentally changes anything | | |
| ▲ | sudosysgen 2 hours ago | parent [-] | | It changes how many attempts you get until the attack surfaces changes to react to a failed attack, and it does so in a way that is not predictable to the attacker. |
|
|
| |
| ▲ | paxys 3 hours ago | parent | prev | next [-] | | This makes no sense. Why do defenders get to pick the surface area? You can be attacked from anywhere. | |
| ▲ | shepherdjerred 2 hours ago | parent | prev [-] | | I think the point you're trying to make is that you can always make your exposed surface area smaller But that, of course, is not going to survive contact with reality |
| |
| ▲ | artrockalter 5 hours ago | parent | prev [-] | | I know the company I consult for (not cybersecurity) is not in these programs and if attacked would need to use open weight models. | | |
| ▲ | ajyoon 5 hours ago | parent [-] | | Did the company apply for access? This is either a problem with your company or the trusted access program. In no way does that suggest the solution is total unfettered access for everyone. | | |
| ▲ | verdverm 3 hours ago | parent [-] | | Everyone needs access to Ai enabled security for defense. A "trusted access program" creates exclusiveness in the hands of Big Ai duopoly. I do not trust them at all |
|
|
| |
| ▲ | paxys 2 hours ago | parent | prev | next [-] | | > Only by using the open source GLM-5.2 were they able to survive an attack They did not "survive" anything. The attack was long done, and they used GLM after the fact to parse logs. Having a more powerful model would have changed nothing. If every attacker and every defender has AI with the same capabilities then attackers are going to win 10 times out of 10. | |
| ▲ | varenc an hour ago | parent | prev | next [-] | | You're ignoring the asymmetry with security. The attacker just needs one exploit chain, whereas the defender needs to block every avenue. Open access to models with no guardrails greatly benefits the attackers more than the defenders. Imagine what a god-level hacking AI could do. It could find a full 0-click to root exploit chain in iOS. Attacker unleashes a worm that infects a phone, instructs that phone to send the same attack to all of its contacts, and then physically destroy the phone by turning off all thermal throttling. Might even be possible to make it catch fire. Or find a remote exploit in Tesla cars and make their autopilot go on murdering rampages. (that one is from a movie) | |
| ▲ | 3 hours ago | parent | prev | next [-] | | [deleted] | |
| ▲ | alienbaby 4 hours ago | parent | prev [-] | | ? There were not models fighting each other, attacker and defender. I dont quite follow what your getting at. | | |
| ▲ | akersten 4 hours ago | parent [-] | | huggingface asked the frontier models to help them analyze the attack and lock down their systems the frontier models refused because their cyber detector went off they had to use GLM 5.2 instead | | |
| ▲ | paxys 3 hours ago | parent | next [-] | | They used GLM to parse logs after the incident. There was no sci-fi AI vs AI battle. | |
| ▲ | usef- 3 hours ago | parent | prev [-] | | Yes, to parse logs afterwards and understand, it wasn't active defence from what I've heard? Definitely embarrassing for the closed vendors though (they've since added hugging face as a trusted vendor) | | |
| ▲ | marcus_holmes 2 hours ago | parent [-] | | One of their learnings from the incident was that they should have a local (i.e. not hosted), open, and capable model on standby that can respond to future incidents swiftly. |
|
|
|
|
|
| ▲ | adastra22 4 hours ago | parent | prev | next [-] |
| The bioweapon thing is absolute movie plot fiction. Go speak to some biologists about this and they'll set you straight. Cyber capabilities go both ways. Better offensive capabilities means better penetration testing by white hat security experts, which leads to better protections. |
| |
| ▲ | gr_norm 2 hours ago | parent | next [-] | | The effective altruism/rationalism/AI xrisk people have always had a shockingly poor grasp on subjects outside computer science, despite their attempts to speak on them. I don't blame the actual biologists and chemists working at the frontier labs for wanting to skim a few bucks off all the money flying around, though! I know a couple who've had not-so-kind words to say about their employers' intelligence. I suspect there's at least some "telling the bosses what they want to hear" going on. A massive financial incentive exists to exaggerate and fearmonger even internally to the company, because it makes you and your job seem more important. | | | |
| ▲ | urams 3 hours ago | parent | prev [-] | | Half or more of Hacker News is constantly pushing the idea that frontier LLMs are stochastic parrots and basically useless, even in the face of the Hugging Face incident which most people also would have described as movie plot fiction until it happened. I expect biologists are even less well versed in the abilities of frontier models. What's more, you can just try a jailbreak on a model yourself to see just how much detailed, step-by-step direction you can get to build bio-terror materials. |
|
|
| ▲ | e_l an hour ago | parent | prev | next [-] |
| > what should be done about open weight bioweapon and cyber-offense capabilities? Is it simply the cost of freedom that we should allow attackers to access these tools? In short, yes, it's the price of freedom. As others have said, blocking these models won't stop the "bad guys", but will hinder defenders researching/responding to bioweapons and cyber-offenses. But you're right that there's a lot of difficult nuance aand we should think carefully about its implications. So here's another nuance to think through. If AI is as powerful as some believe, then there's much greater danger to give a small subset of society the privilege to gate keep who has access to these tools. "Power corrupts and absolute power corrupts absolutely." Lord Acton |
|
| ▲ | gck1 6 hours ago | parent | prev | next [-] |
| I've got zero knowledge of bio, so can't answer that. But with cyber the answer is very simple - the attackers already have more cyber-offense capabilities and there's no putting it back. Open/closed doesn't matter that much. You can get closed models to do a lot of cyber harm, even with all the guardrails, which currently are heavily skewed towards more false positives. The only effective control is to level the playing field. If both offense and defense have access to the same capabilities, then we're relatively back where we started. If you want to ensure chaos, then you do what Dario is proposing to do - create gates that attackers can bypass and defenders can not. |
| |
| ▲ | ajyoon 5 hours ago | parent [-] | | In cybersecurity, a level playing field favors the attacker. Trusted access programs give defenders access to tools they need. It's not perfect (because there is an extremely long tail of defenders who are not technically savvy enough to get on these programs and use the tools), but it's better than total access. The bio angle is very important here too; in that context the imbalance favors the attackers much more. | | |
| ▲ | niwtsol an hour ago | parent | next [-] | | I feel like so many people miss what you are saying here. The attackers are at such an advantage because of time. At t0, attackers can go and try and find so many attack angles. These traditional companies (defenders) can't just go to a model and say "fix all my things!" and ship it, way more complex in practice. | |
| ▲ | gck1 5 hours ago | parent | prev | next [-] | | > In cybersecurity, a level playing field favors the attacker Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs. And I don't know what Trusted Access programs give to defenders, because as a defender who has credentials, connections, but no deep pockets and no high ranking passport, it only gave me silence. I fail to see how this is better than total access. I don't think the world where defense is given to those that "deserve" it is the world that we all want to live in. Which brings me back to the starting point - attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already. | | |
| ▲ | ajyoon 5 hours ago | parent [-] | | > Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs. Trusted access programs are asymmetrical, and so at least for the time being they give critical parts of the stack an advantage. Total access would not be a return to the status quo; attackers can easily make thousands of agents crawl the web for soft targets well before defenses can be shored up. There are millions of targets out there who won't use AI to improve their defenses for years, if ever, due to institutional slowness (like hospitals). > attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already. What do you mean by this? If guardrails are an obstacle to your defense, they are just as much an obstacle to attackers. I completely understand and agree that trusted access programs are not perfect and leave a lot of people and institutions out. This means trusted access programs should be improved, not that we should throw the baby out with the bath water. | | |
| ▲ | gck1 5 hours ago | parent [-] | | It took me a few hours to find some very questionable communities, which in turn gave me access to: - Ways to obtain cheap guarded-AI tokens that are not linked back to me and with no danger of getting my legitimate accounts banned - Ways to get rid of guardrails and have models work on things they wouldn't otherwise work on. The attackers were already in these communities long before I knew they existed, they already had the advantage. Ones with enough reputation probably have access to even more information and tools than I do. It is true that these communities exist because guardrails were put in place, so yes, it is slowing them down too - as in they can't just put in their CC on claude.com and hack a hospital. But attackers are much better at finding these communities and utilizing resources available there than defenders. Personally, I don't have any ethical concerns of utilizing these resources when I put them to actual defense, but I know many people that would, leaving them at a disadvantage. My point is that there's only one guardrail that will effectively contain the threat the models pose, and it's in direct conflict of the big 2's goals - pull the models from worldwide access completely. Strict KYC and all. And it would only last for so long anyway. |
|
| |
| ▲ | CubsFan1060 5 hours ago | parent | prev [-] | | I think you are trying to argue that you can limit the open models. If China is ok with open models being open... they will be. An attacker isn't going to be deterred by a US law saying they can't use them. I guess my point is that if China is ok with open models, then, the attackers will have them regardless of any laws in other countries. Restricting them, in that case, doesn't seem to accomplish much? | | |
| ▲ | ajyoon 5 hours ago | parent [-] | | You can at least make it harder by requiring US clouds to only serve models with guardrails, and encouraging other countries to do the same. But yes, the underlying issue is the models being open in the first place. I'm sure if the US wanted to, it could come to some agreement with China about this. |
|
|
|
|
| ▲ | overgard an hour ago | parent | prev | next [-] |
| > To everyone here pushing for total proliferation of open models -- what should be done about open weight bioweapon and cyber-offense capabilities? Nothing should be done. These things are trained on public knowledge. The dangerous information is already out there. If someone wants to do something horrible, making it slightly inconvenient isn't going to do much. Hackers and terrorists existed before AI. Just as an example, it's no secret how you would build a nuclear bomb. The practicalities of doing so are much harder, obviously, but the knowledge of how they work and what it would take to make one is not a secret. Security through obscurity has never worked! |
|
| ▲ | __MatrixMan__ 29 minutes ago | parent | prev | next [-] |
| The scariest outcome here is that a bunch of lunatics get ahold of a capable model and use to to harm the rest of us, who are at a disadvantage due to just how capable the model is. But that's what's happening. The people in charge are a bunch of lunatics. However nice it would be to prevent them from having harmful capabilities, that ship has sailed. The best we can hope for now is preventing them from having supremacy, and that's what open weight models do. |
|
| ▲ | rubslopes 4 hours ago | parent | prev | next [-] |
| If this is really the risk, then we should approach LLMs like atomic bombs: the US should reach out to other nations so they all agree on no one developing any more AI models. That's the only way you could possibly convince another party to stop. The US should set the example, not conveniently keep all the spoils. |
| |
| ▲ | boinkboink78912 2 hours ago | parent | next [-] | | > If this is really the risk, then we should approach LLMs like atomic bombs A complete failure at actually preventing non-proliferation. | |
| ▲ | paxys 3 hours ago | parent | prev | next [-] | | Uh, that is not how the nuclear race went. The winners kept developing theirs and stopped everyone else by the threat of said weapons. The AI race is going the exact same way, just with China instead of USSR this time. | |
| ▲ | verdverm 4 hours ago | parent | prev | next [-] | | unfortunately, the US has incentivized the opposite behavior for atomic bombs and we are seeing moves towards greater proliferation I would not be surprised if the same incentives are created by the US for Ai | |
| ▲ | 2 hours ago | parent | prev [-] | | [deleted] |
|
|
| ▲ | tacet 3 hours ago | parent | prev | next [-] |
| the bioweapon panic is funny. "oh, yes i know nothing about bicrobiology but i will follow instructions of synthetic text generation machine on temperature 1 about how to design a lab to not kill myself while brewing organisms that will kill myself if i make mistake" There is nothing that special about bioweapons, there are plenty of bacteria that will kill you just fine. Americans even have free samples on their salad. |
| |
| ▲ | consumer451 3 hours ago | parent [-] | | > There is nothing that special about bioweapons. The reason that madmen and terrorists choose kinetic weapons is because the knowledge and materials are more readily available... of and also that even terrorists are likely aware that their own people would suffer. As the knowledge and tools for playing with CRISPR-style biological legos become more widespread, we come closer to the Great Filter, where one person could kill billions. Even our normal mad leaders have agreed that bioweapons cannot be allowed: https://en.wikipedia.org/wiki/Biological_Weapons_Convention | | |
| ▲ | johncolanduoni 2 hours ago | parent | next [-] | | A halfway decent synthetic biology lab (no need to invoke CRISPR) can make e.g. smallpox without a sample of the original disease, just from the gene sequences. Basically all state actors could do this if they wanted to without an LLM. What barrier that a terrorist organization faces today to having a functioning synthetic biology lab does an LLM actually solve? | |
| ▲ | tacet 2 hours ago | parent | prev [-] | | i meant it in the sense of arcane knowledge model could have that would make it simple for anyone to brew up in cheap lab while managing to not infect themselves over and over. "at home" bioweapon panic has been around since crispr and rna synthesis got available to amateurs. |
|
|
|
| ▲ | rstuart4133 4 hours ago | parent | prev | next [-] |
| > what should be done about open weight bioweapon and cyber-offense capabilities? Like the others here I know almost nothing about bio weapons, but I think perhaps the fact that smallpox's genome sequence has publicly available in scientific databases like GenBank for 30 years is relevant. That horse bolted a long time ago. |
|
| ▲ | boinkboink78912 2 hours ago | parent | prev | next [-] |
| > Is it simply the cost of freedom that we should allow attackers to access these tools? Yes, it is inevitable that open weights models will happen. Through legitimate means or leaks, the stakes are simply too high once these models get powerful enough. Furthermore, state-sponsored attackers will always have access to these capabilities. The best we can do is give a lot of preparation to the defenders. > Biasing toward supporting openness makes sense and is a good instinct, but it's incredibly naive to be absolutely in favor of it in every circumstance without seriously thinking about its implications. I find it funny that Anthropic's entire argument for building RSI is that it is inevitable, and therefore we should commit to building it first and doing it safely, and yet they don't apply their own logic to open weights models. |
|
| ▲ | manoDev 5 hours ago | parent | prev | next [-] |
| This Pandora box is already open. Any argument about guardrails now are only attempts to create an artificial monopoly or keep this power in the hand of a single nation state, and _that_ is the absolute worst, most authoritarian future possible. |
| |
| ▲ | monk_grilla 4 hours ago | parent | next [-] | | I think you're right. "Guardrails" as a concept has always struck me as a band-aid solution which any sufficiently motivated actor will circumvent by either bypassing them or using unrestricted, open-weight models. In order to start securing and accepting our new reality we need to assume that capable, open-weight, unrestricted models will be widely available, and that their 3-6 month lag behind frontier proprietary models is just our forewarning of what attackers will soon be capable of. Trying to legislate against or control trade in such a valuable commodity is folly. I also think that lag is going to shrink over time as the open-weight labs get more capable, acquire more hardware and the plateau starts to emerge. | |
| ▲ | paxys 2 hours ago | parent | prev [-] | | How is it already open? There has been ONE successful AI-driven cyberattack, and that was done by a model in testing that no one has access to. What would the picture be today if OpenAI and Anthropic had released 5.6 Sol and Mythos to everyone with no cyber restrictions (which is what everyone here was advocating for)? | | |
|
|
| ▲ | txrx0000 2 hours ago | parent | prev | next [-] |
| I do seriously want general intelligence to be widely available with no guardrails, and there are very good reasons for this. If you want to read about it: https://news.ycombinator.com/item?id=49078376 ---- And related thoughts on past posts: https://news.ycombinator.com/item?id=49034988 https://news.ycombinator.com/item?id=48516722 |
|
| ▲ | 4 hours ago | parent | prev | next [-] |
| [deleted] |
|
| ▲ | valcron1000 5 hours ago | parent | prev | next [-] |
| > what should be done about open weight bioweapon and cyber-offense capabilities? Is it simply the cost of freedom that we should allow attackers to access these tools? Yes, in the same way that we have E2E encryption which allows bad actors to distribute content beyond human horrors. |
|
| ▲ | le-mark 4 hours ago | parent | prev | next [-] |
| > Is it simply the cost of freedom that we should allow attackers to access these tools? Bad actors WILL have access. The question is will these mega corps stop innovation? |
|
| ▲ | zarzavat 28 minutes ago | parent | prev | next [-] |
| There's a difference between: > Something should be done and > Something can be done In this case, nothing can be done to stop bad actors from using open models. As the article points out, the US can only feasibly prevent US businesses from using open models. The US can attempt to stop those models from being trained in the first place but good luck with that. |
|
| ▲ | 5 hours ago | parent | prev | next [-] |
| [deleted] |
|
| ▲ | dools 2 hours ago | parent | prev | next [-] |
| The difference with open weight is that everyone has access to the same weaponry |
|
| ▲ | waterTanuki 30 minutes ago | parent | prev | next [-] |
| The moat never was and will never be the models, it's the hardware. This is exactly like nuclear weapons: The recipe for a nuke isn't a hidden secret. Getting the infrastructure and materials is completely unreachable for non-state and non-corporate actors. This idea of a "rogue individual" using a frontier model to develop a bioweapon is a complete myth, because anyone with the capability to run the models without guardrails has to answer to/be audited by some entity already. |
|
| ▲ | baddash 3 hours ago | parent | prev | next [-] |
| maybe instead of worrying that people on the internet will be good at coding, we could start writing memory safe apis. almost all cves are fixed by using rust |
|
| ▲ | vitalyan8184 5 hours ago | parent | prev | next [-] |
| >To everyone here pushing for total proliferation of ... ...general-purpose computers ...unbreakable encryption ...unbackdoored communication ...unkillswitched vehicles ...unsurveiled dwellings >what should be done about ...? nothing >Do you seriously want this level of capabilities to be generally available with no guardrails? yes |
| |
| ▲ | jackdeansmith 3 hours ago | parent [-] | | What about uranium enrichment? | | |
| ▲ | jjfoooo4 3 hours ago | parent | next [-] | | Requires some pretty tough to get raw materials and equipment, to say the least | |
| ▲ | vitalyan8184 3 hours ago | parent | prev [-] | | what about Death Stars? | | |
| ▲ | jackdeansmith 3 hours ago | parent [-] | | I think it would be entirely reasonable to ban death stars in private hands, the same way I think it's entirely reasonable to ban uranium enrichment in private hands. My point is that it's a question of fact about how risky an AI model can be. I think it's clear that current models are not enriched uranium or death star level, but I don't think there's anything ruling it out in the near future! |
|
|
|
|
| ▲ | fidotron 6 hours ago | parent | prev | next [-] |
| > what should be done about open weight bioweapon Does not exist. What has in fact happened is some cults had bioweapons programs but any failure points were at deployment. (Aum Shinrikyo https://en.wikipedia.org/wiki/Tokyo_subway_sarin_attack and https://en.wikipedia.org/wiki/1984_Rajneeshee_bioterror_atta... ) > and cyber-offense capabilities? You mean defense. That's how things get hardened. Anyone that was working during the XP era before Service Pack 2 knows what that was like, but it's very manageable. The bigger real problem here is hardening like that would remove the opportunity for intelligence agencies to spy on everyone. |
| |
| ▲ | ajyoon 5 hours ago | parent | next [-] | | You admit that some attackers have the inclination to use bioweapons. Why would they not use the best tools at their disposal going forward? From the WSJ the other day: > After OpenAI enhanced the brain power of its chatbot last summer, hundreds of users worldwide began asking it how to make and deploy biological weapons and poisons. https://www.wsj.com/tech/ai/openai-chatbot-biological-weapon... On cyber, the attacker/defender asymmetry strongly favors attackers. There are millions of soft targets on the internet which do not have the savvy to use AI to shore up their defenses. | | |
| ▲ | fidotron 5 hours ago | parent [-] | | > Why would they not use the best tools at their disposal going forward? Because AI doesn't solve any of the problems any attacker would actually have. It's a classic case of nerds not seeing the actual problems because they involve reality. It's worth pointing out that those bioweapon attacks I linked to also predate widespread access to the Internet, and there was similar scare nonsense about that. > On cyber, the attacker/defender asymmetry strongly favors attackers. There are millions of soft targets on the internet which do not have the savvy to use AI to shore up their defenses. Do you think they are not being exploited today? The reason they aren't more exploited is there really isn't much to gain from doing so. | | |
| ▲ | ajyoon 5 hours ago | parent [-] | | jefftk addresses your bio thought well. > The reason they aren't more exploited is there really isn't much to gain from doing so. This is incorrect. The long tail of soft targets aren't being exploited more because attackers are bottlenecked on labor. AI removes exactly this bottleneck. | | |
| ▲ | fidotron 5 hours ago | parent [-] | | > This is incorrect. The long tail of soft targets aren't being exploited more because attackers are bottlenecked on labor. AI removes exactly this bottleneck. No, it's because the targets are worthless. You aren't going to be able to mine Monero or run LLM botnets on forgotten cameras in basements. There is nothing to be gained from such targets, soft as they are. Besides the new defensive AI entertainment makes dealing with wherever those things phone home far easier. Possibly too easy for plebs to be allowed access to. |
|
|
| |
| ▲ | jefftk 5 hours ago | parent | prev [-] | | I don't think the Aum case points the way you're describing: they used a non-pathogenic strain of anthrax because they didn't know any better. That's a knowledge failure. But even then, the debate isn't about whether open weight bioweapons exist today: it's about whether they will exist in the future. I think Amodei's argument here makes a lot of sense: "what I believe currently keeps us safe in biology is not 'defenders', or even the availability of materials, but a negative correlation between intellectual capability and desire to commit catastrophic harm. Previous technologies like internet search or even DNA synthesis were nowhere near powerful enough to break this correlation, but I worry that at its current rate of progress, AI will do so very soon." (I'm not just spouting off; I put my time where my mouth is. I used to work in big tech, but I left for a much less well-paying job building an early-warning system for engineered pandemics.) | | |
| ▲ | fidotron 5 hours ago | parent [-] | | > I don't think the Aum case points the way you're describing: they used a non-pathogenic strain of anthrax because they didn't know any better. That's a knowledge failure. No, check https://en.wikipedia.org/wiki/Matsumoto_sarin_attack There are a lot of interviews with former cult members around. They had armed helicopters, a testing station in western Australia, produced piles of sarin. This wasn't a lack of science knowledge that screwed them up, they notoriously involved the elite class of Japan - it was a whole other category. There is no link between AI and bioweapons that makes this stuff any more reasonable than availability of detailed descriptions of nuclear reactors enables us to be purifying weapons grade plutonium in our yards. | | |
| ▲ | jefftk 5 hours ago | parent [-] | | > > they used a non-pathogenic strain of anthrax > No, check https://en.wikipedia.org/wiki/Matsumoto_sarin_attack That's a different attack. I'm talking about their 1993 anthrax attack: https://pmc.ncbi.nlm.nih.gov/articles/PMC3322761/ Analysis of the 48 suspect colonies confirmed them to be B. anthracis ... This genotype was identical to that of the Sterne 34F2 strain, used commercially in Japan to vaccinate animals against anthrax. They used a vaccine strain because they didn't know any better. Even members of the elite can make mistakes, especially when operating outside areas they know well! (This was not the only thing that went wrong, but several others were also knowledge failures.) | | |
| ▲ | fidotron 4 hours ago | parent [-] | | You and the other are both missing the point. That's not a knowledge failure, it's a failure in how your operation is strategically executing. They were essentially practicing, and what did they learn? Change to sarin and even VX, for which they didn't need AI. AI isn't going to help you get from nonpathogenic anthrax to pathogenic anthrax either. All it might do is tell you to try sarin or VX earlier, but these present different problems. The idea that there are people in the world wanting to execute bioweapon attacks that are somehow gated by a lack of access to AI is utter hysterical nonsense that should be clearly pointed out as such. | | |
| ▲ | rescbr 3 hours ago | parent [-] | | Still, somebody heavily funded this thing for too long, and I very much doubt that we don't have the surveillance apparatus in place today for these things to get unchecked. Stuff is known but not acted upon for various reasons. |
|
|
|
|
|
|
| ▲ | verdverm 5 hours ago | parent | prev | next [-] |
| > what should be done about open weight bioweapon The same thing we do about bomb making today, certain ingredients are restricted and/or monitored. Bioengineering is a bigger lift to operationalize. In other words, don't ban knowledge, make certain applications or ingredients illegal or highly regulated. |
| |
| ▲ | jackdeansmith 3 hours ago | parent [-] | | And what are those ingredients for biology, which can be constrained as effectively as uranium enrichment? I'd argue there isn't anything which can easily be restricted or monitored. | | |
| ▲ | verdverm 3 hours ago | parent [-] | | I was referring to non nuclear bombs like c4, artillery shells, and missile payloads |
|
|
|
| ▲ | BeetleB 4 hours ago | parent | prev | next [-] |
| Everything you said could apply to computers many decades ago. Think of the nuclear fission simulations our enemies could carry out! We'll be fine. |
|
| ▲ | pylua 4 hours ago | parent | prev | next [-] |
| The software industry should be ashamed by the number of exploits that ai can find in software. It’s really an embarrassment. The software has to be built better. |
| |
| ▲ | doginasuit 4 hours ago | parent | next [-] | | I'm curious if you are a coder and have used an LLM to review your code. It is like something like shining a black light around a hotel room, and that seems to be the case even for highly regarded software. It is really easy to have tunnel vision while coding. LLMs have a working memory with a capacity an order of magnitude greater than ours. I wouldn't trust an LLM to write the code, but at this point it is malpractice not to use one for review. | | |
| ▲ | pylua 4 hours ago | parent [-] | | I have been, yes. For a field that has engineering in the name there sure has been a lot of critical mistakes. You have to call a spade a spade — the profession accepts this sort of tradeoff in the name of speed and cost. A well designed system would have never allowed those mistakes to occur. I feel like using an llm to catch these sorts of things is just because it wasn’t built right in the first place. I think ai systems will be able to build systems of abstraction that are formally verified, and we won’t be needed(eventually). Right now it’s being used as a bandaid. | | |
| |
| ▲ | marcus_holmes 2 hours ago | parent | prev [-] | | Every single software engineer in the industry agrees with you. Every single project manager disagrees. Don't blame the engineers, we were specifically instructed and paid to build things fast and cheap, and every time we argued for good we were shouted down. | | |
| ▲ | pylua 2 hours ago | parent [-] | | True. It has been a race to the bottom for lowest cost as long as the quality meets the bare minimum. LLMs can go through and find all the nails sticking out pretty easily. |
|
|
|
| ▲ | fwn 5 hours ago | parent | prev | next [-] |
| There is also a whole second category of immense risks of having US companies gatekeeping offensive capabilities, especially for us here in Europe. The centralization/privacy/kill-switch concerns that come with it are a huge AI safety dimension. I'd rather have a level playing field within a phase of adaptation and hardening regarding cybersecurity issues than a constant dependency on the US, maybe grabbing Greenland today, maybe "extracting" our president tomorrow. The delta between privileged capabilities and open weight capabilities alone already is a massive, unaddressed AI safety risk. |
|
| ▲ | qweqwe14 5 hours ago | parent | prev | next [-] |
| [dead] |
|
| ▲ | dolebirchwood 4 hours ago | parent | prev [-] |
| > what should be done about open weight bioweapon and cyber-offense capabilities? If the model is capable of it, then it was in the model's training data, which means it was on the internet or published in books made available for consumption. So if any member of the public could have gotten their hands on that information, so be it. If the knowledge was too dangerous for public access, then it should have been highly classified and never found its way into the training data. Tough shit, frankly. |
| |
| ▲ | paxys 2 hours ago | parent | next [-] | | Was the proof of the Cycle Double Cover Conjecture in the training data? | |
| ▲ | adastra22 4 hours ago | parent | prev [-] | | The threats are BS, but fyi models have repeatedly shown capability to produce novel things that are NOT in their training set. | | |
|