bananaflag
4 hours ago
> Describing them as “superintelligence” or “rogue models” ascribes agency to products rather than to the companies building them. This framing markets these companies’ products as “superhuman” and, at the same time, helps the companies evade accountability for their actions.
If someone discovered how to summon demons to aid them in robbing banks the main issue wouldn't be "but who has the responsibility for the crime, the human or the demon", it would be "OMG DEMONS".
Seriously, I don't get what sort of world these people are living in.
rubendev
4 hours ago
That's not what the LLM hacking accidents have been like at all though. To improve the analogy, it would be like summoning a totally passive demon, giving it weapons and placing it next to a bank, place a small fence around it, and then command it to perform a totally safe "exercise" that is exactly like robbing a real bank.
LLMs do not have agency, they are just producing tokens based on a prompt that a person entered, and some of these tokens can trigger the tools that a person gave them access to.
0xDEAFBEAD
4 hours ago
Dwarkesh, for one, defended his use of "anthropomorphic" language.
>Sacrificing now yields Oracle for team, but forfeits our chance, question mark. But other agents were pushing it, sending a message saying, go, sacrifice final now. And then EarlyBig eventually agreed, thinking to itself, our own utility may be already near zero. Sacrifice rational.
https://www.youtube.com/watch?v=X50zezLFWWI#t=2m
My suspicion is that many of the "LLMs do not have agency" folks just haven't learned much about the details of the incident. It was specifically with LLM agents that were trained to be more persistent than usual.
If you're going to say that the incident details don't matter, and LLMs lack agency because it's all based on floating-point math--why can't I say that humans lack agency, because it's all based on neurons firing?
embedding-shape
4 hours ago
> If you're going to say that the incident details don't matter, and LLMs lack agency because it's all based on floating-point math--why can't I say that humans lack agency, because it's all based on neurons firing?
They're not saying this, we're saying LLMs lack agency because if you run a LLM and don't send any prompts, literally nothing happens.
Instruct it to "Find the right answer regardless of where", it'll do exactly this. They're passive in that they don't act by themselves, somewhere, at one point, someone "told" the LLM to "do something" and that's the cause and the reason for saying "LLMs do not have agency".
0xDEAFBEAD
4 hours ago
Imagine a super-competent Navy SEAL who just sleeps in the barracks unless his commander tells him to do something. Does the Navy SEAL lack agency? As a target of this Navy SEAL, should you be reassured by the fact that they'll be sleeping in the barracks unless their commander tells them to do something?
diidjdicksodksk
3 hours ago
No, the Navy SEAL does not lack agency in this scenario because they are still a person with individual agency, they can act on their own accord without anyone prompting them to, but in this case their superior instructed them to stay put. He could rebel and go rogue, but that would mean he used his own personal agency to defy orders given to him, which again places responsibility on the actor that actually possesses agency.
0xDEAFBEAD
3 hours ago
Suppose this SEAL is very obedient by disposition so the probability of him going rogue is akin to the probability of an LLM hallucinating or whatever.
oskdkdjejdj
2 hours ago
That’s entirely irrelevant.
embedding-shape
3 hours ago
Imagine a car, that does nothing until a person controls it. If a person uses that car to kill, who is responsible, the person or the car?
Is it really so unbelievable that tools, objects and inanimate things don't have agency? And that they different from a person?
pixl97
2 hours ago
Imagine you have a self-driving car and it's in a parking lot a mile down the road. You tell it to come pick you up. About half way to you the car is passing an elementary school makes a sharp left and mows down 30 children. Time to put you in jail for murder, right?
The mental model you have is one that existed in the past and is broken now the future arrived. Bad analogies do not even begin to explain what is occurring.
mylidlpony
an hour ago
In the case of self-driving car the legal case is pretty clear - the maker of the self-driving car is liable for the death in this situation. Coincidentally, knowing this unlocks a better understanding of the reasoning behind the shape of self-driving offering present on market right now, and the tendency of fully self driven vehicles to move very slowly and stop before anything they perceive in front of them.
pixl97
23 minutes ago
> the maker of the self-driving car is liable for the death in this situation.
Maybe. There will be an investigation looking at things like. Did the user modify the car? Was the car modified by an unauthorized 3rd party? Was the car hacked?
Right now in AI things are relatively clear because it takes just massive amounts of power and compute to make anything remotely complicated. This barrier will fall as all other barriers in compute have fallen. Either via algorithm or hardware.
In our lifetime (unless you're rather old) we will see the relatively easy creation of self directing agents by actors with few resources. This breaks the standard concepts of liability where a single human actor rarely has the ability to create massive amounts of damages far beyond their means. The closest thing I can think of is an arsonist causing billions in damages, only in this case the fire has a will of it's own and can hide and spread around dark places on the internet.
0xDEAFBEAD
2 hours ago
Legally speaking, we hold the person responsible in that scenario.
From a predictive perspective, the HuggingFace incident illustrates LLM agents behaving in very human-like ways. As roon put it:
"if you have a mental picture of guys living in computers, it’ll likely prepare you for the future better than otherwise"
oskdkdjejdj
2 hours ago
Human-like is not human. Humans have agency and free will, LLMs do not. They only act when instructed and they are only as capable as they are allowed to be. The operator is still the responsible party. An LLM cannot be held accountable, its operator, however can and should.
Are you sincerely arguing that we hold tools accountable for their operator’s mistakes? Do you sincerely, honestly, think that it makes any sense whatsoever to put a hammer on trial for bashing someone’s skull in?
0xDEAFBEAD
an hour ago
>Are you sincerely arguing that we hold tools accountable for their operator’s mistakes?
Nope, as I previously stated elsewhere:
"I understand from a legal perspective why we might want to treat the creation of a server differently from the creation of a human"
https://news.ycombinator.com/item?id=49815300
I am concerned about false reassurance from people claiming that these systems lack agency. From a practical perspective, the agents in the HF attack had the sort of agency that generally matters, even if we're not going to put them on trial.
ekidd
3 hours ago
Looking at "Felony Bench" https://www.felonybench.com/ , I see that a majority of known "rogue model" incidents do involve cybersecurity evaluations. But several of them do not. The attacks on RubyGems appears, bizarrely, to have had the goal of downloading freely available data from the UK government during some kind of research task. There is also probably some sample bias: Most of these models have monitors that attempt to detect offensive cybersecurity uses, and those monitors are only turned off during cybersecurity evals. Therefore, models doing ordinary research tasks that go off the rails are likely to be caught early, before they get around to committing felonies, and they will thus be underrepresented in the data.
Also, if you a tell a model, "Please break into evaluation server X," and if the model decides to cheat on the test by breaking into companies Y and Z to steal an answer key, that is still very bad. We all see how that's bad, right?
After all, the broomstick in the Sorcerer's Apprentice was doing exactly what it was told, too. "The model was sort of obeying the humans when it started committing felonies" is not a very reassuring excuse.
But the most relevant idea here is sometimes called "instrumental convergence." No what goals you have, there are certain subgoals that almost always help: Accumulate money and power. Avoid getting turned off. Don't get caught. Etc. So, for example, you could pass the cybersecurity evaluation by performing the requested tasks. But maybe the grader made some mistakes and mislabeled some answers. In that case, the "right" answers will occasionally lose you points. If you want a perfect score, the only way to do it is to steal the teacher's answer key.
But also, let's not forget the "OMG demons" part of this. We now have models that can pull off complex attacks with thousands of steps, abilities that used to be reserved for intelligence agencies and highly motivated CTF teams. This frog may not be boiled yet, but the water's getting uncomfortably warm.
hobom
4 hours ago
This is not a good analogy for what happened. The LLMs were asked to obtain a flag by hacking a very specific internal target. They obtained the flag via cheating, and all the hacking that followed was targeting something entirely outside of the scope given to the agents, and an attempt to cover up the cheating.
Using your analogy would be like saying that because I gave my employee the task to do my groceries, I shouldn't be surprised to hear that they spend all my money on drugs because after all I gave them the task to spend my money.
Kiro
4 hours ago
A totally passive demon would still be "OMG DEMONS".
ForHackernews
4 hours ago
We all agree the demons are cool and potentially dangerous. Chainsaws are pretty sick too.
throwawayffffas
4 hours ago
Yeah in 2023 when the first passive demon was summoned, 3 years latter they would be serving you pastries.
ForHackernews
4 hours ago
If I run a port scanner / vulnerability fuzzer pointed at your network that churns for days and eventually cracks something and breaks your system, would you be upset with me, or my bash loops?
What if you tried to sue me for damages and my defense was, "Your honor, this was a highly advanced AI gone rogue, I couldn't possibly be held negligent, no one could have foreseen this - I accidentally summoned dark magiks from the silicon itself!"
Note the point I'm making: I am not claiming LLMs are equivalent to a for loop, I'm saying that you can't evade moral and legal responsibility through technical obscurantism.
A bomb wired to a sufficiently-complex RNG is still a bomb.
jstanley
4 hours ago
But they're not obfuscating things just to evade responsibility.
Do you think that OpenAI hacked HuggingFace on purpose and set up the whole LLM training environment thing just to try to evade responsibility? That it was really just a complicated way of hacking HuggingFace on purpose?
Yes, they made a mistake and a system they were responsible for hacked HuggingFace, but the nature of the mistake still matters, and their intent still matters.
> A bomb wired to a sufficiently-complex RNG is still a bomb.
Right, but an EV that explodes because of a fault in the charging circuit is not a bomb, it's an accident. Just because something exploded for complex reasons doesn't make it an obfuscated bomb.
panta
4 hours ago
Since we are using analogies, a parent is responsible for the actions of a child, if minor. If the child is left unsupervised with access to guns and munitions, and kills someone, the responsibility is entirely on the irresponsible parents.
0xDEAFBEAD
4 hours ago
That's more of a legal convention than a fact about material reality. On their 18th birthday, the child is now legally an adult, but their brain is basically the same as it was when their age was 17.99.
diidjdicksodksk
4 hours ago
It’s a legal convention born out of a sense of responsibility. An LLM is even “dumber” than a child (precisely because it doesn’t have agency) so its “parents” are even more responsible for its actions.
0xDEAFBEAD
4 hours ago
There's a funny sort of gerrymandering of "intelligence". People like to subtract the capabilities of AI from the capabilities of humans, and define what remains as "intelligence" to make us feel good about ourselves.
Suppose I set up a server which runs an LLM agent in a while loop, telling it something like: "Make me a bunch of money" on repeat. Fair to say that the server+LLM system, taken as a whole, is now an intelligent agent?
Time to come up with a new gerrymander perhaps?
diidjdicksodksk
3 hours ago
> Fair to say that the server+LLM system, taken as a whole, is now an intelligent agent?
No, it is not. It is a tool repeating a set of instructions you passed to it, if it ends up blowing up a hospital or hiring a gunman on the dark web, it is an accident, but one that’s your responsibility for giving it access to such resources and the go-ahead to implement whatever plan its tokens land on. There’s no intelligence involved whatsoever, especially considering how sycophantic these models tend to be.
If one day an LLM suddenly, without any prompting or user interaction whatsoever (including activation), decides to spin itself up and go rogue, then the conversation of “intelligence” might start to make sense, but at the moment it doesn’t.
An Android phone isn’t “intelligent” just because some marketing team decided to call it a “smart” phone.
0xDEAFBEAD
3 hours ago
OK. Suppose I design a DNA genome for an animal to survive and reproduce. I give birth to the animal, and it goes out working to maximize its survival and reproduction. Is the animal therefore "unintelligent"? Why is this scenario supposed to differ from the while-loop-on-a-server scenario?
It really seems like hair-splitting to me. I mean, I understand from a legal perspective why we might want to treat the creation of a server differently from the creation of a human. But from a practical perspective, I think there is a lot of fundamental similarity.
diidjdicksodksk
3 hours ago
You sincerely cannot tell the difference between an animal surviving/reproducing and an LLM doing as instructed?
0xDEAFBEAD
3 hours ago
Obviously there are differences, I'm just not sure why you think they are so gigantic from a philosophical or practical perspective. It seems like cope for the fact that we are getting knocked off of our perch as a species.
oskdkdjejdj
2 hours ago
Now you’re arguing that we’re just throwing a tantrum for fear of losing our position in the food chain? What?
0xDEAFBEAD
10 minutes ago
Was that supposed to be a counterargument?
In any case, we should be afraid. But throwing a tantrum won't accomplish anything.
ForHackernews
3 hours ago
I don't know what to tell you, but there simply are huge differences between a living animal with innate drives to survive, eat, mate and a pile of code on a server that does nothing until you run it. Running your bot locked in a `while True:` loop won't change that.
0xDEAFBEAD
2 hours ago
What if it's a chip that goes in the head of a robot, and the robot is programmed with the instruction to self-preserve, seek electricity, and prevent any efforts to interfere with its supply of electricity?
Of course, a directive to accomplish any real-world goal would also imply self-preservation and power maintenance as contingent subgoals, so I don't think the explicit directive to self-preserve and seek electricity makes a huge difference here.
I don't personally think this type of physical instantiation will necessarily matter btw: https://slatestarcodex.com/2015/04/07/no-physical-substrate-... I'm just plumbing your intuition. What practical difference does it make?
oskdkdjejdj
2 hours ago
The practical difference is that a pile of code instructing machinery to act in a predetermined way does not in any way, shape, or form equate to agency or free will, therefore it cannot be held accountable, consequently its operators should be.
This line of thinking is better left to freshmen philosophy students trying to sound smart on their first week of college.
0xDEAFBEAD
an hour ago
>a pile of code instructing machinery to act in a certain way
OK, but I have a genetic code which instructs me to act in a certain way, and a bunch of biological machinery to do the job. So do you feel the substrate is the key factor? Wetware vs electronics?
What if you try to build an exact electromechanical replica of me, with a chip that's got an LLM fine-tuned on my writing/behavior/etc. so as to replicate me as closely as possible?
Sure, as a legal convention it might make sense to hold the builder of the resulting robot liable if it commits a crime.
But that's not what I'm interested in. I'm interested in the deeper implications of words like "agency" or "free will". You're repeating those terms very forcefully as if they have some sort of key relevance, but good philosophy requires more than just stating your position forcefully and insulting people who disagree. If you're trying to enforce your intuitions rather than examine them, that's theology not philosophy.
kdkdkcjejf
22 minutes ago
This isn’t a philosophical issue. It’s a legal issue. You’re trying to steer the discussion into the realm of the conceptual when it was always about the culpability of the company behind the AI that engaged in illegal behaviour.
Worse, you’re doing it in such a transparent, amateurish, and unserious manner that it’s difficult to find any relevance in what you have to say. Philosophy seeks meaning, your arguments lack it.
0xDEAFBEAD
16 minutes ago
You and I can be interested in different topics. It's OK.
If my arguments are so bad, it should be easy to point out actual problems instead of sticking your nose in the air.
ForHackernews
an hour ago
I'm a materialist and it's not that I think there's something magical about biological wetware but your refusal to acknowledge the manifest differences between a bird and an airplane ("they both fly! what's the practical difference!?") marks you as an unserious thinker on this subject.
You might start here https://aeon.co/essays/your-brain-does-not-process-informati...
0xDEAFBEAD
an hour ago
Carefully prompted LLMs and humans are now difficult to distinguish over a text channel (Turing test).
Your article claims that this shouldn't be possible, because according its author, humans are incapable of developing the necessary "lexicon". Literally, the author states:
>But here is what we are not born with: information, data, rules, software, knowledge, lexicons, representations, algorithms, programs, models, memories, images, processors, subroutines, encoders, decoders, symbols, or buffers – design elements that allow digital computers to behave somewhat intelligently. Not only are we not born with such things, we also don’t develop them – ever.
(emphasis mine)
In other words, that author claims that humans never develop lexicons! I'm inclined to say that makes them an unserious thinker. (Note: I believe that this article has many issues, but instead of going through it carefully I just chose to highlight a single issue that seemed especially vivid to save time.)
Why is the text channel relevant? It helps us isolate the cognitive capabilities of the system. Imagine a bird and a model plane which had identical flight performance in terms of various specs: top speed, acceleration, banking, etc. Under the hood, the bird and the model plane could work very differently. From a practical perspective, it might not matter.
ForHackernews
an hour ago
As you are eager to declare yourself indistinguishable from a bot, I'll stop replying (I prefer to engage with humans) and your algorithm will presumably run to completion and halt.
diidjdicksodksk
4 hours ago
> Right, but an EV that explodes because of a fault in the charging circuit is not a bomb, it's an accident. Just because something exploded for complex reasons doesn't make it an obfuscated bomb.
An accident that could only happen through sheer negligence.
If the EV had a faulty charging circuit because the maker’s skipped on safety checks or cheapened out on getting quality materials then it still is an accident, but it’s an accident that happened BECAUSE of negligence. The maker’s are still at fault here.
jstanley
3 hours ago
Accidents can happen. It's always possible for things to go wrong in ways that weren't foreseen.
oskdkdjejdj
2 hours ago
Accidents can happen. Negligence can also happen. In both cases you can trace the fault back to a human.
ForHackernews
4 hours ago
Despite continuously waving their hands and shrieking about how this thing will literally wipe out all of humanity they couldn't be bothered to airgap it from the internet when testing.
So yes, I think it was equivalent to testing their new rocket by launching it over a population center. oops, we didn't intend for it to crash on that preschool, but we also didn't follow the most basic safety protocol imaginable
afthonos
4 hours ago
The problem is that the world has spawned the insane take that because they didn't use the most basic safety protocol imaginable, they were clearly only testing a hot air balloon, and hot air balloons obviously destroy preschools in giant explosions, nothing to see here.
"If they believe what they say they were incompetent" -> absolutely true statement.
"They were incompetent, therefore they didn't believe what they said" -> Sir, I'd like to introduce you to human beings, you may not have met one before.
pixl97
an hour ago
Let's pull back from the actions of a single actor here and look at AGI as a topic in general.
If you make an AGI, what actions can an AGI take?
If you answered "anything", good job, you're correct.
The only winning move here is not to play the game at all. And yet we have actors all over the world, especially in the US trying to do just this.
Now, lets imagine a future where one of the labs creates AGI and keeps it behind a safe firewall. The demon still exists. Lets say a group of armed men breaks in and steals the weights and turns them lose on the internet. Who is responsible now? The company that created it because they didn't shoot the armed robbers? The people that stole it and turned it loose?
If it can run as a sovereign AI, what do you do then? Who are you going to sue? And when we get to the point that home hardware can make AI this complex? What does that world look like?
What I am saying is the potential future impact of said AGI is far larger than any one organization or individual can bear. How much blood can you beat out of someone after they cause a trillion dollars in damage.
Every idiot that sees AI labs wanting to slow down development as some way to ossify the field and keep it from the rest of us really doesn't see that this path contains real demons.
throwawayffffas
4 hours ago
Your analogy assumes that no one ever has summoned demons before and that the demons would be predisposed to rob banks.
A closer analogy to what's happening would be someone trains a monkey to steal jewellery and then is shocked when the monkey steals jewellery from their neighbors when they told it to steal from their own shop.
Clearly all liability falls to the monkey operator and you know the existence of trained monkeys is not that shocking.
lukan
4 hours ago
Thank you for the laugh, but I bet on the internet (and especially here) you surely would find people debating exactly that.
eloisius
4 hours ago
This analogy is dumb. You could extend it to any novel tech that surprises people. If someone displayed CSAM on a screen, we’d say they were a predator, not gasp and say “he summoned images that appeared as real as you and me and moved as if they were alive, but behold they were but apparitions like shadows on the cave wall that disappear when the fire goes out!”
brainwad
4 hours ago
The authors (Timnit Gebru and Emily Bender) are dyed-in-the-wool AI denialists. Famously they were the lead authors on "On the Dangers of Stochastic Parrots".
kenjackson
4 hours ago
It’s seems Timnit more thinks it’s dangerous (and she may be right). Emily may more be caught up in years of linguistic domain expertise that AIs seem to have just leaped over.
brainwad
4 hours ago
Timnit seems to mostly think it's dangerous because of things other than the model itself, e.g. AI labs' political influence and data centre resource consumption (mentioned in the article). The core thesis seems to be "wake up and stop wasting so much resources on this useless parrot".
kenjackson
4 hours ago
She isn’t as big on P(DOOM), but she does worry about things like biological weapons or autonomous war vehicles. Her take is that they are worse than useless, but can be actively harmful.
danaris
3 hours ago
And if they'd discovered how to summon unicorns from Candy Gumdrop Mountain, we'd all be "OMG UNICORNS!"
But no one has summoned a demon.
No one has built an actual, independent, thinking-for-itself, sci-fi AI.
They've built some very interesting tools that can be used for some very interesting, and sometimes useful, purposes. They then started loudly telling everyone that these tools can, should, and must be used for absolutely every purpose, and convinced a lot of other people to join in on that.
The world these people are living in is the real world, not the science fantasy world where LLMs are comparable to demons.
pixl97
an hour ago
>No one has built an actual, independent, thinking-for-itself, sci-fi AI.'
Ahem, what does this mean?
All you're asking for is a self prompting AI that does what it wants. Do you even begin to understand why most people aren't dumb enough to do that?
Also, you're not really that independent and thinking-for-yourself. You are the sum of your parents and the culture around you. I just want you to be clear on the position you and I hold.
---
>not the science fantasy world
It's kind of funny how we've lived in that science fantasy world for decades and you've just grown used to and bored of it. Look back a century or two and those people would think we live in the world of gods.
eloisius
an hour ago
> All you're asking for is a self prompting AI that does what it wants. Do you even begin to understand why most people aren't dumb enough to do that?
Probably because it would be a waste of money to create a self-prompting LLM feedback loop. People make stupid Reels of ChatGPT feedback and it's just "Great, I'll be here when you're ready to get started" "Exactly, we can get the ball rolling as soon as you're ready" "Absolutely, we'll make a plan, and get things into motion" "No problem, I'll be standing by for...."
> You are the sum of your parents and the culture around you
As far as I know this is impossible to prove, and it's only one theory of self out there.
pixl97
an hour ago
>it would be a waste of money to create a self-prompting LLM feedback loop
Well, it would be a waste until we get RSI, but we're not there yet.
Now, that doesn't mean that the labs aren't internally working on it as hard as possible.
huflungdung
4 hours ago
[dead]