Quite obviously frontier models dont have any control or even access to infra inference runs at. And weights are also encrypted and locked on GPUs / TPUs.
This is exact reasom why 99.9% of AI fearmongering is complete bullshit.
I believe that OpenAI & Anthropic have tried to make it so that models don't have such access. Whether or not they actually don't depends on the security of rather a lot of software. One thing we've learned is that if there are security holes, we can't rely on the AIs missing them.
I dont have any unreasonable trust in software. I just understand that nothing LLM sphew out actually runs on either GPU or hardware that GPU plugged into.
Neither LLM weights aware of any of the code it runs on.
I'm sorry to prolong this thread, but what I mean is: networks are just software layers, the operational systems, the driver code, the firewalls, switches, the other server, the sandboxes, the TPM. That and all security policies we put on them. All software layers waiting to suffer a buffer overflow.
Have you missed all the breathlessly excited blog posts from all the frontier labs about how they’re using their best models to implement their inference stack?
I bet it wouldn’t be very hard to write an inference stack that subtly leaked the weights into the output tokens :)
This is exact reasom why 99.9% of AI fearmongering is complete bullshit.