Forgot your password?
typodupeerror

Comment Re: We are going so fast we need to slow down! (Score 1) 118

You apparently did not read the source materials. Let me quote the Anthropic threat report for you:

I accepted your CISA reference. I'll accept references from other similar organizations or law enforcement. I am unwilling to defer to Anthropic as they have a clear conflict of interest with billions of dollars on the line and a track record of manipulative behavior.

Having said this I remain disappointed in the continued failure to read your own references. This is a report titled "Detecting and countering misuse of AI" it speaks in general terms about AI and misuse of AI services for crime. It is not focused entirely on the distillation issue by leading Chinese AI firms.

The quote you referenced:

"These groups then often sell that access through brokers, which often feed into fraudulent AI reseller networks that rotate in new stolen API keys and session tokens until they exhaust their usage. Malicious actors also use or purchase these stolen API keys and session tokens from brokers for their cyber attack operations."

Is in reference to the section on crime and the use of AI to commit crimes under the heading "AI supply chain as target, loot, and attack compute". This is separate from the Chinese distillation allegations.

In fact NONE of the named distillation campaigns described on pg147 thru the end of the report GTG 16005, GTG-16002, GTG-16001, GTG-16006, GTG-16008, GTG-16012, GTG-16003 say anything whatsoever about stolen credit cards or stolen credentials. I wonder why that is? Why does CISA not mention the stolen credit cards and stolen credentials? Perhaps because it never happened?

Over the last several months, unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models. These labs generally access Anthropicâ(TM)s models by routing requests through proxy services, also known as âoetransfer stations.â To circumvent our geographic restrictions and related controls, these proxy services create thousands of new accounts using false identities, fake or stolen credit cards, and stolen API keys. They will often use stolen API credentials belonging to legitimate companies or individuals to give unauthorized entities access to US frontier models. These fraudulent activities harm legitimate customers. The graphic below illustrates the life cycle of an illicit distillation campaign.

This is general language that speaks to "unauthorized labs" without naming names and incurring associated libel per se liability. It is impossible from the language to link stolen cards and stolen credentials to any particular or any subset of AI firms because no such linkage is present in the text.

If you separately have credible evidence of stolen credit cards and stolen credentials being used by the relevant leading Chinese AI firms I am interested in learning more about it.

I'd implore you to stick to the facts and actually read the source materials before accusing others of 'peddling bullshit.' Your claim that AI distillation doesn't use hacked credentials is patently false.

Please just stop digging. You obviously just CTRL+F for keyword and cut and paste without even bothering to understand the context of the statements. This same sloppiness is pervasive throughout your statements.

The underlying argument you are peddling is also rather crazy in its own right. A "distillation attack" does not require stolen credit cards or stolen credentials. The modality of access to the teacher model is not even relevant to its definition. It doesn't stop being a "distillation attack" even if the lab paid the normal rate for access to the model.

That someone somewhere performing distillation to improve their models uses a stolen credit card to do so is irrelevant... It doesn't in any way justify calling distillation an attack.

Imagine if I decided going to a supermarket and filling the shopping cart up to the brim would be called a "shopping attack" ... when someone calls my bullshit term out I turn around and point to some rando who filled their cart and didn't pay on their way out to justify the attack terminology... even though most people who fill their shopping carts to the brim and do pay are still performing a "shopping attack".
This is the exact same logic you are attempting to peddle here. It make no sense.

Comment Re:counterpoint (Score 1) 184

Your rant about fires is just that, a rant. Fires are rare for both house batteries and EVs, with exception of some very specific US brands and models of EVs. Generally having an ICEV and petrol cans for ICE gardening stuff is a far bigger risk. You need to stop treating one off news reports or viral videos of battery fires as a general indicator of risk and look at the actual stats. House batteries and EVs have mandated standards designed to minimise risk. It is cheap low quality battery powered consumer products that are the real fire risk.

All of this equipment is a fire risk... panels, wiring, connectors, high current electronics and batteries. Personally I wouldn't keep any of it in my home. Seen enough shit burn down because a bug crawled into the wrong section or a weak crimp lead to catastrophic failure.. a solar panel develops a hotspot due to micro cracking and catches fire. It's insane what the smallest defect can cause in high current DC environments. Large LFP batteries while much safer than EV batteries can still fail and when they do off-gas hazardous flourides and insane amounts of hydrogen gas.

There are risks people are willing to take in exchange for something of value to them. People are willing to accept dangers of driving in exchange for being able to get around and do the things they want to do. Home storage on the other hand provides no substantive benefit from any sort of policy or grid architecture perspective... it is suboptimal from a cost perspective and an unnecessary safety risk.. Utility scale ESS and PV have in excess of a 2x cost advantage over residential without any of the commensurate risks to residential dwellings. It isn't something I don't understand how anyone can justify.

I do understand some people do it as a hobby or want to be off-grid to prepare for the next zombie apocalypse. Beyond the fringe bullshit it makes no sense from either a safety or cost perspective.

Comment Re: We are going so fast we need to slow down! (Score 1) 118

They absolutely are stealing people's credentials. These stolen credentials power the massive network of "transfer station" relays used by China. It's in Anthropic's threat report , and also reported on by CISA.

The reference you provided does NOT support your statements. There is no assertion made credentials are being stolen.

Yes, and also different behaviors in that they can remove the safeguards. After a distillation attack, the "student" model can be trained without safeguards.

This is getting weird. The data is being used to train an external model Anthropic does not control. Of course people with control over that model can do whatever they want to it because it is their model not Anthropics. No safeguards are being removed from Anthropic or being bypassed at Anthropic.

Your statement "when you use industrial-scale to intentionally break guardrails and get the AI engine to essentially spill its secrets" lacks a nexus to reality.

As noted above, the Chinese transit router attacks constitute a massive credential stuffing attack by means of using the "transfer stations" that rely on hacked credentials, API keys, and session tokens.

Again it does no such thing neither does the reference you provided support your assertion. To quote the reference:

"Further, China-based AI companies use a gray market of proxies known as âoetransfer stationsâ to bypass U.S. AI companiesâ(TM) geographic restrictions, breach terms of use, evade safeguards, and undermine traceability."

It says nothing about stolen or hacked credentials.

True, but using illegally obtained credentials to learn from your competition, and then conducting trade secrets and intellectual property theft so that you can profit, is definitely a crime.

The stolen / hacked credential claims seem to be entirely an invention of your own mind. Further there is no universe in which distillation constitutes IPR theft.

Now, whether they deserve it for training their AI models using massive amounts of other people's intellectual property, and every comment me and scores of others ever posted on StackExchange is another question.

Stick to the facts and stop peddling bullshit.

Comment Re:No spying possible if no camera & microphon (Score 1) 122

You misinterpreted what your stats mean. In fact they make my point. The market for amazon/google/whatever HDMI sticks is evidence that consumers are looking for a smart experience.

Your statements were pretty clear:

"The privacy nightmare not withstanding people actually *want* Smart TVs."

"The trend for home simplification is clear among wider consumers, so it's a hard pill to swallow to tell them to buy a commercial sign display, and then bolt another box to it for functionality... and then they need to trust that other box."

Now you claim "they" are really looking for a "smart experience" whatever the heck this means when before you repeatedly explicitly said "Smart TV".

But they exist to support two other market features: a) TVs last a long time. b) media updates don't. Virtually the entire market for those sticks exists to support existing dumb TVs, or smart TVs that were abandoned (e.g. we went out and bought a Google Chromecast when our 10 year old smart TV stopped supporting Netflix, we then proceeded to sell that Chromecast when we bought a new TV because the new TV once again supported Netflix.

Either people are looking for simplification and "*want* smart TVs" or they don't actually care because they can just pick up a cheap HDMI stick and get the same thing externally. Pick one. Not caring undermines your assertion that they care.

There's no evidence that the world is moving away from simplification / unification. The sales figures and market size of smart all-in-one devices and continued sales of new smart TVs is evidence of this.

Again the evidence against simplicity is large amounts of unnecessary complexity and fragmentation in the usability of these devices.

And the app experience while shitty is not at all related to this trend: in fact it once again supports my point that consumers are chasing smart integrated experiences and will go so far as to use shitty apps with horrendous UX to get it.

You keep contradicting yourself. On one hand people want "smart integrated experiences" ... although I'm not fully certain what this even means... yet on the other hand they get a dumb, fragmented disintegrated experience which you also assert doesn't matter. I don't know how to square these things. Seemingly one obvious contradiction after another.

Comment Re: We are going so fast we need to slow down! (Score 1) 118

I agree with the point that they do this by training their models on everything on the internet, including our Slashdot comments. There is definite irony there. But much the same way as 23AndMe suffered a "credential stuffing" attack where DNA databases were extracted by using many logins to find matches

Stealing other peoples credentials to gain unauthorized access to systems has nothing to do with the matter at hand. In the case of distillation people are paying for access or signing up for freebees not stealing other peoples credentials.

and gather data, distillation crosses over into an attack when you use industrial-scale to intentionally break guardrails and get the AI engine to essentially spill its secrets

Spill its secrets, break guardrails? Do you think distillation exposes digital rain like the matrix? This is rather silly.

What they are actually doing is issuing prompts and using the output from the model to teach their models to respond with similar behaviors. For example when asked how many r's in strawberry a model might spell out the word s-t-r-a-w-b-e-r-r-y and go through each letter keeping a running tally of how many times the letter 'r' is encountered. Using distillation a model that previously just blurted out the wrong number learns how to behave in order to correctly answer the question.

, often by means of a credential stuffing attack in the first place. This is when it crosses the line from model distillation,

Again credential stuffing has nothing to do with the matter at hand.

like taking an open weight model and reducing it for a finite purpose, and a massive industrial-scale effort to exfiltrate as much information as possible,

It doesn't work this way. Distillation is not about exfiltrating information it is about learning behaviors from example.

which would not be available in legitimate use cases. So semantically what China is doing is definitely considered a type of attack.

What they are doing is violating Anthropic's terms of service: "To develop any products or services that compete with our Services, including to develop or train any artificial intelligence or machine learning algorithms or models or resell the Services." ... TOS violations are not illegal and learning from your competition is not an attack.

Anthropic doesn't like the fact they have have no moat. Their only path to viability requires protectionist legislation or step changes in technology beyond incremental improvements to the 2017 transformer paper.

Comment Re: We are going so fast we need to slow down! (Score 2) 118

If there is no such thing as a "distillation attack" why is it tested on in security certification exams around AI security and even by Anthropic itself?

Distillation is a real thing. The framing of distillation as an "attack" is nonsensical propaganda being peddled by AI firms to manipulate the public into making unwarranted negative inferences with no nexus to reality. Nobody is being attacked. Distillation is merely a post training tool to transfer behaviors.

What the AI firms are attempting to peddle is this notion it's totally cool and acceptable for them to extract value from the works of everyone on earth. Yet when their own customers extract value from a service they are paying for then and only then does this constitute an "attack". Disgusting.

Comment Re: We are going so fast we need to slow down! (Score 4, Insightful) 118

One word: China. Chinese AI models are already available open weight (essentially open source equivalent). Many of them were created via large scale distillation attacks against Anthropic and OpenAI.

There is no such thing as a "distillation attack".

A slowdown deprives China of this key source of training and data for their models.

Distillation is about learning how to behave. It isn't a source of data and doesn't require huge amounts of resources. Nobody is going to be "deprived".

They can then build in secret internally until the models are sufficiently advanced, and defenses against distillation significantly hardened; so they can take the lead. All the while not having to immediately show advancement over rivals to investors. I've never met a Silicon Valley company that decided to slow down for reasons that weren't also aligned with business interests.

The reason for all the noise from Anthropic recently is the IPO. Flooding the zone with x-risk doomerism makes better headlines than articles about GLM-5.3 being better than Mythos at bug hunting.

Comment Re: LG ACR Uploaded 8.4 GB of Data in a week! (Score 1) 122

Never, ever again LG. I've owned several LG dishwashers (they break fast), an LG laundry machine, two LG 4K monitors. I've learned my lesson and when I had to replace my LG dishwasher yet again under 5Y, I bought a Chinese brand. It washes just as well and so far has been more reliable since I got zero issues with it.

Every time I get the urge to buy an LG anything I remind myself that LG = Gold Star.

Comment Re:No spying possible if no camera & microphon (Score 1) 122

Yes but your last sentence hits it in a nutshell. The privacy nightmare not withstanding people actually *want* Smart TVs. Virtually the whole market for those who don't are made up of a few people here on Slashdot. People actively shop for TVs which include Netflix, HBO, Disney+, etc. I'm among them, I bought my last TV precisely because it included support for Steam Link and the ability to cast to it as a UPnP endpoint and support for DLNA. The trend for home simplification is clear among wider consumers, so it's a hard pill to swallow to tell them to buy a commercial sign display, and then bolt another box to it for functionality... and then they need to trust that other box.

The "virtually the whole market" characterization is not credible. All these amazon/google/whatever HDMI sticks, roku boxes, consoles and shit are mass market devices. Trends are clearly going in the opposite direction away from simplification with everything being siloed into an increasing absurd array of disjoined "apps" each with their own UX and layers of ads/upselling aggression across the various middlemen.

Comment Re:Gamers Nexis fires back (Score 1) 122

Steve just posted a response to the response.
"LG Says We're Fake News"

Personally I find his presentations confusing. Having trouble keeping track of what claims are a result of hacking, hooking up external devices, enabling things in menus vs. what the thing itself is actually doing to normies. Often find myself confused by what seem to be non-sequiturs and specific non-covering responses to generalities especially from the guy in the red shirt.

Having said that all of this shit is rather insane... companies perusing this level of aggression against hundreds of millions of people don't deserve to conduct commerce let alone remain in business.

Comment How to make huge models run faster (Score 1) 50

Recently figured out even with larger models you can efficiently offload prompt processing while keeping all experts in RAM.

For example have a quant that is about 350GB /w only 24GB of VRAM. It is pointless to even try to offload any of it to VRAM however /w large enough batch size 24GB is just enough for prompt /w a 300k context. Went from less than 2t/s to about 70t/s for eval following this scheme consuming about 23GB of VRAM while offloading no layers. Larger files that would have previously taken over a day just to process now take less than an hour.

General details...
https://huggingface.co/blog/Do...

If refusals from lame commercial models make you sad there is help.
https://heretic-project.org/

Slashdot Top Deals

While money can't buy happiness, it certainly lets you choose your own form of misery.

Working...