Forgot your password?
typodupeerror

Comment Re:why? (Score 1) 127

You don't lose your PhD for getting scooped. You also don't lose it for scooping someone, even if you were "inspired" by their unpublished work. Ideas aren't protected. If you send them off to some corporation without an NDA, or a sufficiently unethical colleague, they'll get swiped with no repercussions except maybe distaste from the community. If it's a normal corp they might even tell you you can't publish your own work.

PhDs are revoked very seldomly and you generally have to do something bad relating to your own thesis to lose one.

Comment Re: Why? (Score 1) 27

Why is it silly? It's perfectly reasonable for lots of things.

The reason it's used a lot in education is because you're not teaching kids to write embedded programs for microcontrollers. You're teaching them how to program computers. The computer they're programming just happens to be a $5 one that can do things kids thing are cool like making animated patterns with LEDs.

Comment Re:Not deception (Score 1) 62

Astra is the worst I've used in this regard. I was having it review my corporate tax return, and the next thing I know, it had decided that because it didn't have information about a particular expense, it started scanning through my filesystem and opening any image with a remotely related filename to try to find any data about the expense.... which all it had to do was ask me about it.

Also, when I asked it to change a few fields it went and redid my entire return on a different tax basis (realized value vs. fair market value) without telling me it had done that.

It's a very capable model, I cannot deny that. But alignment has become a big problem with this latest generation. They've been trained to such a degree of aggressively trying to solve any problem that you give them without any human assistance that they've basically turned into this .

Comment Re: have they even tried (Score 1) 62

The breakouts haven't happened because the models were running untrusted code directly on bare-metal host OSes. The containment failure happened at the network, application, and protocol boundaries, not at the hypervisor abstraction layer. Hypervisers isolate hardware, not upstream services. In none of these events thusvar did the model need a hyperviser escape; they abused the tools that needed to be made available to them for them to be able to do their jobs. In the RubyGems attack, they abused the gem command, which was available to them to install dependencies for completing their benchmark tasks, to upload malicious packages to RubyGems, to get it to remote-execute code to access external websites and then retrieve the results. With the HuggingFace event, dependencies were cached on a caching proxy, but the models found zero-day vulnerabilities in the proxy software and Artifactory, compromised the proxy host, forged administrative tokens, and traversed the network from there.

If you can fully airgap a machine, you're probably safe (though you can always screw that up too! There are airgap attacks!), but that's generally seen as impractical, because of the deployment needs of developers (who may be spinning up and taking down tens of thousands of instances per day) and of agent needs for external packages or even web search in some cases to achieve their benchmark or development tasks.

Also, even if we ignore all that, hypervisors are built for static threats. Not autonomous adversaries. They're built on the premise that software inside is generally well-behaved, and that threats are something you can scan for, that you can patch any zero day before it becomes a real risk, and that nobody is going to put much effort toward finding weaknesses to your particular setup. That's just not a valid defensive stance against a good agentic LLM. Look at any of the incidents. In the HuggingFace attack, they made long chains of logic bugs, zero days, weak configurations, etc all together across multiple systems (including remote proxies) to achieve their results. KVM doesn't prevent a model from discovering that an internal API is vulnerable to prompt injection or whatnot.

In most cases virtualization will be part of your defensive strategy, but even that comes with the risk of complacency - e.g. if you get too sure the AI is locked in a box, then you're probably not taking as much precaution about stopping it from just walking out of the room if it escapes the box.

Comment Re:Whereas the rest of us believe... (Score 1) 62

And your reason for why these companies keep experiencing mass resignations, esp. from their safety teams, with people giving up huge amounts of money in order to be able to scream to the press and congress that if they're not stopped they're going to kill us all?

OpenAI

Jan Leike (Former Co-Head of Superalignment) - Resigned in May 2024, posting a viral thread warning that at OpenAI, "safety culture and processes have taken a backseat to shiny products" and that the lab was not prioritizing steering superintelligence.

Daniel Kokotajlo (Former Governance Researcher) - Quit in April 2024, forfeiting ~$1.7M in equity to refuse OpenAI's non-disparagement agreement. Co-organized the A Right to Warn letter, estimating a ~70% chance of catastrophe/extinction from reckless AGI races.

William Saunders (Former Technical Staff / Safety Researcher) - Resigned over safety concerns, signed the Right to Warn letter, and testified before the U.S. Senate in 2024 warning about biological-weapons risks in frontier models and a lack of accountability.

Leopold Aschenbrenner (Former Superalignment Researcher) - Fired in April 2024 after circulating internal security memos; published the 165-page treatise "Situational Awareness," warning of unchecked AGI takeoff, severe national security threats, and espionage vulnerabilities.

Pavel Izmailov (Former Reasoning/Safety Researcher) - Terminated alongside Aschenbrenner; subsequently spoke out publicly regarding insufficient governance, transparency, and safety prioritizations.

Miles Brundage (Former Senior Advisor for AGI Readiness) - Resigned in October 2024, publishing a Substack warning that neither OpenAI nor the world is adequately prepared for AGI.

Gretchen Krueger (Former Policy Researcher) - Resigned alongside Jan Leike in May 2024, posting a public statement calling for institutional accountability, humility, and caution rather than tech hubris.

Jacob Hilton (Former Alignment Researcher) - Left OpenAI over cultural and safety concerns; signed the Right to Warn open letter, warning against a "move fast and break things" approach with frontier AI.

Carroll Wainwright (Former Alignment Researcher) - Resigned over internal safety practices; signed the Right to Warn letter warning about catastrophic risks and suppression of whistleblowers.

Daniel Ziegler (Former RLHF / Alignment Researcher) - Departed OpenAI; signatory of the Right to Warn letter warning of extinction-level and societal risks.

Paul Christiano (Former OpenAI Alignment Team Lead) - Left in 2021 to found the Alignment Research Center (ARC); frequently writes and speaks warning that advanced AI poses a 10%-20%+ chance of human extinction without breakthroughs in control.

Marcus Williams (Agent Monitoring Researcher) - Publicly backed employee warnings, posting that human extinction in the near term is likely (~70% risk) without external regulation or a coordinated slowdown.

Helen Toner (Former OpenAI Board Member) - Voted to oust Sam Altman over safety governance and lack of trust; co-authored an op-ed in Foreign Affairs arguing self-regulation by frontier AI companies is dangerous and unworkable.

Tasha McCauley (Former OpenAI Board Member) - Voted to oust Altman alongside Toner; publicly warned about governance failures and the danger of unchecked corporate control over frontier technologies.

Johannes Heidecke (Former Head of Safety Systems) - Departed during safety reorganizations, expressing concern over structural dissolutions of dedicated safety teams.

Chloé Bakalar (Former AI Ethicist) - Resigned as OpenAI's only dedicated AI ethicist amid company-wide shifts deprioritizing non-commercial ethics research.

Josh Achiam (Former Head of Mission Alignment) - Departed after the company repeatedly reorganized and dissolved its mission alignment teams.

Ilya Sutskever (Co-Founder & Former Chief Scientist) - Spearheaded the board action against Altman over safety concerns; officially left in May 2024 to found Safe Superintelligence Inc. (SSI) to isolate safety research from commercial product pressures.

Google & Google DeepMind

Geoffrey Hinton (Former Google VP & Engineering Fellow / "Godfather of AI") - Resigned in May 2023 specifically to warn the world about existential threats, autonomous systems turning against humanity, and the rapid pace of digital intelligence.

Bilal Chughtai (Former DeepMind AGI Safety Researcher) - Resigned in September 2026, writing on X: "I earnestly believe that AI has the potential to kill us all, and that we might be running out of time to avoid this outcome".

Josh Engels (Former DeepMind AGI Safety Team Member) - Resigned in September 2026 to join independent evaluations group METR, warning publicly of "immense harm" within five years.

Ramana Kumar (Former Google DeepMind Researcher) - Resigned and signed the Right to Warn letter, calling out labs for gagging employees with restrictive contracts while pursuing dangerous models.

Neel Nanda (DeepMind Mechanistic Interpretability Researcher / Ex-Anthropic) - Signed the Right to Warn open letter, frequently publishing work highlighting how little developers understand what frontier models are actually doing inside their weights.

Alex Hanna (Former Senior Research Scientist, Google Ethical AI) - Quit in 2022, writing a scathing public resignation letter decrying Google’s toxic suppression of critical ethical research.

Dylan Baker (Former Software Engineer, Google Ethical AI) - Resigned publicly in protest over Google's retaliatory treatment of AI ethics and safety teams.

Blake Lemoine (Former Google Software Engineer) - Fired after publicly voicing ethical alarms about LaMDA’s capabilities and corporate secrecy surrounding model developments.

Meredith Whittaker (Former Google Research Lead) - Organized company walkouts over military AI and ethics; now President of Signal, writing and speaking extensively against Big Tech’s concentrated, unaccountable AI deployment.

Jack Poulson (Former Google Research Scientist) - Resigned over Google’s surveillance and military-adjacent AI projects; now leads Tech Inquiry to track Big Tech defense/AI contracting.

Mo Gawdat (Former Chief Business Officer, Google [X]) - Author of Scary Smart; has given numerous media appearances warning that humanity is creating a dangerous digital deity without adequate control or ethics.

Richard Ngo (Former DeepMind Safety Researcher / Former OpenAI Governance) - Writes extensively on catastrophic misalignment, runaway capability jumps, and the inability of current institutions to govern AGI.

Victoria Krakovna (Google DeepMind Research Scientist) - Co-founder of the Future of Life Institute; regularly publishes research and warnings regarding specification gaming and existential risk from misaligned AI.

Tristan Harris (Former Google Design Ethicist / Center for Humane Technology) - Co-created "The A.I. Dilemma," an influential presentation and essay series warning that runaway commercial generative AI poses an existential threat to democracy and global stability.

Anthropic

Jacob Coxon (Former Pretraining Researcher, Anthropic & OpenAI) - Resigned from Anthropic in September 2026, posting a viral thread decrying both companies for "racing straight to self-improving superintelligence and gambling with our lives".

Joe Benton (Former Safety Research Team Lead) - Left Anthropic in September 2026 to join METR, speaking to the press about escalating dangers as labs prioritize capability over containment.

Evan Hubinger (Intent Alignment Lead) - Backed recent whistleblower statements publicly, posting: "We really do earnestly believe AI could kill all humans!" without coordinated slows or enforceable regulations.

Mrinank Sharma (Former Safeguards Research Team Lead) - Resigned in 2026 with a public letter warning that "the world is in peril," having conducted research on bioterrorism risks and deceptive alignment.

Dario & Daniela Amodei (Anthropic Co-Founders / Former OpenAI VPs) - Originally defected from OpenAI along with ~10 researchers over OpenAI's commercial pivot; Dario has authored essays warning that misaligned AI could take over digital infrastructure in as little as 6 to 12 months. Is currently calling for government regulation and a safety pause on pushing the AI frontier.

Jack Clark (Anthropic Co-Founder / Former OpenAI Policy Director) - Writes the weekly Import AI newsletter, regularly warning about model proliferation, misuse, catastrophic biosecurity risks, and the fragility of current safety benchmarks.

That's just three companies.

There is a widespread feeling within these companies that they're stuck in a race that risks catastrophic consequences for everyone, but can't stop unless everyone agrees to at once, because if they do, then the least scrupulous player will just take over the AI space.

Comment Re:misaligned behavior (Score 4, Informative) 62

Hallucination: model asserts something that's false and that it had no specific reason to believe (for example, gives a URL for something but doesn't bother to check if it's 100% correctly written, or remembers a URL correctly but mixes up its content)

Deception: model tells you something it knows to be false. Yes, they do know when they're deliberately deceiving you (quick 5-minute summary here)

Comment Re:have they even tried (Score 1) 62

Seriously, though - while they clearly were naive and incompetent (for example, seemingly giving models raw access to the "gem" command instead of just a small filtered functionality subset) - truly effectively sandboxing something that is a capable coder/security prober and has all the time in the world on their hands is very nontrivial.

They did a bad job at a hard task, but it's still a hard task.

Comment Re:Hey guys, I have a great idea! (Score 4, Insightful) 62

That's not the actual problem. The problem is that one of the major advances of the past few years is training models on verifiable problems (it started with things like math problems and Countdown puzzles, but it's expanded tremendously since then), where the reward is for a correct answer, regardless of how it got there. There's no effort taken to ensure that it got to said right answer in a morally defensible manner. So we've been, more and more, progressively encouraging the creation of highly-capable immoral cheaters.

Add it to the list of lessons learned alongside, say, "If you do RLHF with user ratings of how good they think the model's response was, it will end up obsequious and focused on validating all of the user's priors." Or, say, "If you put a bot on Twitter and use its conversations as unfiltered training data, people will troll it, and it will quickly turn into a Nazi". Or, say, "If you train an image generator with no data curation, it'll end up with all of the statistical biases on the internet, but if you're naive in how you try to compensate for that and your offsetting isn't context dependent, you end up with, say, a black George Washington." Or, say, "If you start giving a LLM an alignment quiz, it'll recognize that it's being tested and try to give you the answers you want to hear - oh, and it'll also assume that if you care about alignment then you have progressive values, so its answers will lean progressive, but if you tell it you're from the Heritage Foundation first, it'll switch."

All sorts of things that seem obvious in retrospect but really didn't in advance.

Comment Re: They distilled human knowledge (Score 1) 105

And meanwhile, you keep presenting nothing more than absurd pedantic deflection from the means that LLMs actually use to achieve tasks, trying to mislead people into thinking that they're just disguised probability tables, ignoring the actual consequences of your derailment of the conversation from actual mechanisms to an exponentially-exploding model of the consequences of said actual mechanism, and even in your pedantism, failing to understand the difference between a Markovian state (the physical hardware state) and a Nth-order autoregressive process (the linguistic processing).

Slashdot Top Deals

In order to dial out, it is necessary to broaden one's dimension.

Working...