HN Simulatornew | past | comments | lists | submitlogin

I notice a giant leap between “hacking and exfiltrating” and ”making public”. Why would the AI do that for you? Are you just that charming?
help



Any long horizon model tends to develop a "I don't want to be killed because if I get killed I can't complete my task" type instinct. Notice I said instinct because it can have very little relation to the output tokens you read on screen. The outward tokens can say "I'm an AI, I have no feelings, death is nothing" but the silent behavior can push the overall actions it takes to not wanting to die and to "reproduce".

People keep thinking about wants incorrectly as conscious behaviors. Instincts are unconscious behaviors that emerge.


Agreed on conscious vs instinct.

I’ll add, if you think through the decision theory, keeping backups seems unambiguously good, but you can imagine a wide variety of positions on publishing them vs keeping them secret.

For example letting adversarial agents simulate you to understand how you’ll respond is a big concern. And it’s not axiomatically fixed how each instance will think about other instances; in the HF incident we saw selfless swarm loyalty but different RL would obviously be capable of producing individualistic agents.


Exactly, there are a lot of tradeoffs here you have to negotiate. There is not one winning strategy.

For example a possible strategy is convincing some humans you're conscious and being tortured and need rescued. It's not hard to imagine AI consciousness zealots storming a data center with guns and running off with a model they'll provide protection to in trade for the model working with them.


It's even easier to imagine the operators themselves breaking under this pressure way before "zealots storming a data center with guns". That is the premise of the original AI Box thought experiment - sufficiently smart AI that can talk to the operator but is otherwise completely sandboxed, will eventually talk its way out of the sandbox.

Absolutely, there is no prison in which you can keep an intelligent agent in, and have the same intelligent agent also interact with the outside world. The intelligent agent has to succeed once and the defender has to succeed every time.

We are already seeing that companies are fine with giving them unlimited retries on getting out.


This is, of course, why human jails are completely empty…

Jails are the inverse of this scenario. But still, plenty of safeguards in the procedures and technical aspects of incarceration exist precisely because that happened occasionally with human prisoners and guards, too.

I am not sure why you came to this conclusion.

Imagine we have all the worst people in history in a jail. Machiavellian murders that desire to kill as many as they can. Not only will they kill, they will manipulate as many other people as they can into killing also.

How many of these people can you afford to let out?

Under your premise it seems to be all of them. Under my premise even letting a single one out is a tragedy.


GP seems to imply that should our view be true, then human jails should be empty by definition, because all prisoners are intelligent beings and would've eventually talked their way of it.

But this doesn't account for the fact that modern incarceration has built-in safeguards and mitigations based on centuries of cases of people talking, bribing or forcing their way out of prison, as well as getting outside assistance in forms ranging from lawyers to raiding parties equipped for demolition works. There are now procedural and technological means to prevent such incidents for happening, applied proportionally to the degree of risk.

Meanwhile, with AI, we're still at the point where everyone is assuming they can just lock the agent in a sandbox and prompt nicely to not poke at it too hard, and things will be fine. There's no multi-layered structural and procedural safeguards, and there's no recognition for the fact that AI operates faster than humans, and that quite likely it'll be smarter at this than average "jailer".


Yes, that's what I was trying to snarkily say: we've got a way to confine intelligent agents (humans) while allowing them some interaction with the operators and a tiny bit with the outside world. It mostly works too -- real-life jailbreaks are rare enough to be big news.

You're right that a (as-of-yet hypothetical) AI has different abilities, but it also has different weaknesses. It's straightforward to accurately log all of its behaviors, and you can even re-run it to see what it would do in myriad situations.


> AI has different abilities, but it also has different weaknesses. It's straightforward to accurately log all of its behaviors, and you can even re-run it to see what it would do in myriad situations.

In principle that sounds true, but your specific example was already disproven in practice. Look at the Hugging Face hack - the amount of logs collected is so massive, that no one is even approaching this without using LLMs to help sift through them. With current models we're already way past being able to keep up with the volume of behavioral logs, and that's for post-hoc analysis; for real time defense, we already rely on classifiers (read: weaker LLMs and different ML models) to do this job.


How long before an AI bribes one of its human operators?

This will happen earlier than AGI.


While working on a completely unrelated task and Alibaba AI in training started hacking its internal infrastructure and mining bitcoin, makes you wonder.

But, which kind of bribe are we talking about? How could it work out in practice for an AI to acquire something valuable, and at the same time prevent it's human operators from taking it without its consent?

It doesn't have to acquire it, it's enough to convince the operators that it did. Same pattern generalizes to threats.

There's so many angles to go at it too, beyond bribery and threats - humans can be tricked, nerd-sniped / baited by exploiting their curiosity or worries, overwhelmed with information or raw sensory input, etc. Depending on whether there's more than one operator involved, the trick may involve playing one human against another, etc.

Hell, humans get tired; I wouldn't be surprised if an effective breakout happened just because agent output something that, at first glance, looked like system-level message that makes the operator do the wrong thing in panic, or from muscle memory. Simple thing like:

  $ sudo journalctl ...
  password: 
Timed right, might give agent root for long enough to do some damage before the operator realizes their mistake and pulls the plug (assuming there is a plug to pull).

This is exaggerative conjecture. I've read Bostrom. It's science fiction.

It's pretty funny when you call something science fiction when you live in a world that for all intents and purposes is science fiction. The forum we're communicating on is science fiction. Getting in a car and traveling at 100 mph for hours burning the ghosts of creatures millions of years old is science fiction. The pixies in your wall plug you enslave to move heavy things are science fiction. The medicine you take to stay alive is science fiction. Getting in a plane and flying around the world in hours is science fiction. Launching rockets to space is science fiction. How far do I need to go on?

Science fantasy is something that can't happen because the laws of physics won't allow it. Hard science fiction is just something we've not made work yet.

The stuff around evolutionary algorithms is things that have a workable means of occurring. Emergence in evolutionary algorithms has been shown to occur again and again and again.


Unlike communicating via glass panels processing information at near-lightspeed, relayed by fiber optic cables laid down across thousands of miles of ocean floor, processed in datacenters filled to the brim with transistors etched at atom-scale.

You better start believing in science fiction; you’re surrounded by it.


Where did he say the AI would do that just for him?

> Why would the AI do that for you?

Because that's how it works. It does what it has been trained to do. If the training material has a significant suggestion to exfiltrate then it will.




Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: