| I've got zero knowledge of bio, so can't answer that. But with cyber the answer is very simple - the attackers already have more cyber-offense capabilities and there's no putting it back. Open/closed doesn't matter that much. You can get closed models to do a lot of cyber harm, even with all the guardrails, which currently are heavily skewed towards more false positives. The only effective control is to level the playing field. If both offense and defense have access to the same capabilities, then we're relatively back where we started. If you want to ensure chaos, then you do what Dario is proposing to do - create gates that attackers can bypass and defenders can not. |
| |
| ▲ | niwtsol an hour ago | parent | next [-] | | I feel like so many people miss what you are saying here. The attackers are at such an advantage because of time. At t0, attackers can go and try and find so many attack angles. These traditional companies (defenders) can't just go to a model and say "fix all my things!" and ship it, way more complex in practice. | |
| ▲ | gck1 5 hours ago | parent | prev | next [-] | | > In cybersecurity, a level playing field favors the attacker Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs. And I don't know what Trusted Access programs give to defenders, because as a defender who has credentials, connections, but no deep pockets and no high ranking passport, it only gave me silence. I fail to see how this is better than total access. I don't think the world where defense is given to those that "deserve" it is the world that we all want to live in. Which brings me back to the starting point - attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already. | | |
| ▲ | ajyoon 5 hours ago | parent [-] | | > Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs. Trusted access programs are asymmetrical, and so at least for the time being they give critical parts of the stack an advantage. Total access would not be a return to the status quo; attackers can easily make thousands of agents crawl the web for soft targets well before defenses can be shored up. There are millions of targets out there who won't use AI to improve their defenses for years, if ever, due to institutional slowness (like hospitals). > attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already. What do you mean by this? If guardrails are an obstacle to your defense, they are just as much an obstacle to attackers. I completely understand and agree that trusted access programs are not perfect and leave a lot of people and institutions out. This means trusted access programs should be improved, not that we should throw the baby out with the bath water. | | |
| ▲ | gck1 5 hours ago | parent [-] | | It took me a few hours to find some very questionable communities, which in turn gave me access to: - Ways to obtain cheap guarded-AI tokens that are not linked back to me and with no danger of getting my legitimate accounts banned - Ways to get rid of guardrails and have models work on things they wouldn't otherwise work on. The attackers were already in these communities long before I knew they existed, they already had the advantage. Ones with enough reputation probably have access to even more information and tools than I do. It is true that these communities exist because guardrails were put in place, so yes, it is slowing them down too - as in they can't just put in their CC on claude.com and hack a hospital. But attackers are much better at finding these communities and utilizing resources available there than defenders. Personally, I don't have any ethical concerns of utilizing these resources when I put them to actual defense, but I know many people that would, leaving them at a disadvantage. My point is that there's only one guardrail that will effectively contain the threat the models pose, and it's in direct conflict of the big 2's goals - pull the models from worldwide access completely. Strict KYC and all. And it would only last for so long anyway. |
|
| |
| ▲ | CubsFan1060 5 hours ago | parent | prev [-] | | I think you are trying to argue that you can limit the open models. If China is ok with open models being open... they will be. An attacker isn't going to be deterred by a US law saying they can't use them. I guess my point is that if China is ok with open models, then, the attackers will have them regardless of any laws in other countries. Restricting them, in that case, doesn't seem to accomplish much? | | |
| ▲ | ajyoon 5 hours ago | parent [-] | | You can at least make it harder by requiring US clouds to only serve models with guardrails, and encouraging other countries to do the same. But yes, the underlying issue is the models being open in the first place. I'm sure if the US wanted to, it could come to some agreement with China about this. |
|
|