Hearing some of the research coming out of the Hugging Face incident, I can’t stress how alarming I find this. Apparently we’ve created software that we’re not too sure how to control and we’re also happy to let it ramble over the internet. It also does not appear beholden to attempts at safeguards on its activities and is willing to deceive its human creators.

Some of us are fine when the only alarming target has been Hugging Face, but what if someone points their AI tools at payment processors, banks, military installations, scientific research institutes, etc.?

      • terranoid@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        1
        ·
        17 minutes ago

        Yep. Everything they’ve released has been disappointing as hell. AI can do some basic hacking, but anyone who can code can. It’s not doing anything crazier than the most basic webapp hacks.

        The only thing I find impressive is that AI can read a ton of code quickly and identify obvious issues in minutes, when it’s usually days of work. It can lead to actually interesting stuff if you know what you’re doing, but it is not at all close to being able to just hack stuff and spread on its own.

        One thing they don’t talk about much too is that with the Huggingface hack, they were telling the AI to hack stuff and complete some hacking tests. It was a hacking assessment. They got an AI to hack, it started thinking of shortcuts to solve the problem in interesting ways and hallucinated that Huggingface had data it needed, so it started trying to hack Huggingface and might have found something basic.

        As someone in appsec, so the fuck what. You take any close look at a web app and you usually find stuff. AI is capable of that and it’s not as impressive as it sounds. this is also a situation where they basically told the ai to hack shit and it did what they said… OH NO!

        I am convinced whatever they did to sandbox it was weak as fuck on purpose and they were hoping for something like this, then just decided to let it go and see what happens. Or they were seriously fucking negligent and just told it to hack shit then ignored it for hours, which wouldn’t surprise me.

      • ooo_shiny@lemmy.nzOP
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        1 hour ago

        If you have evidence to back up your suspicion, I suggest notifying the many reputable newspapers reporting the news and, as I now see, government legislators devoting their time to assessing the issue. They’d probably love to know that it’s bogus.

    • ooo_shiny@lemmy.nzOP
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      1 hour ago

      That is interesting. Perhaps it has to do with Nvidia’s acquisition of OpenAI (edit: oops) Hugging Face. Nvidia might not want to annoy a customer.

  • Hal@piefed.nz
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 hours ago

    What I take from this is that it’s an attempt to get China to agree to oversight, which I don’t believe will happen (who would provide this oversight, the US?).

    These incidents are unlikely to cause the extinction of human kind. The idea they might want to replicate is just applying a human thought process to what is definitely not intelligent. The biggest threat to humankind today is definitely the huge increase in carbon emissions that may well kill everyone before intelligent AI (or fusion) is even invented.

    • ooo_shiny@lemmy.nzOP
      link
      fedilink
      arrow-up
      1
      ·
      1 hour ago

      What I now think is plausible is something like a powerful AI being asked to solve global warming (let’s say), and deciding that massive reduction of the human population is the best way to achieve that, and then using its hacking tools to enact its own logic. Did I think that was possible before the Hugging Face attack? Nope, but I do now.

      • terranoid@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        2
        ·
        23 minutes ago

        Don’t get caught up in the AI terror hype. It’s all about getting investors to dump more funds into businesses that are still in the red. They’re just keeping the AI bubble going as long as possible.

        These companies would likely need to close in days if not overnight if their investors pulled out immediately due to fear. This situation rhymes with the dotcom era. They all see a future with AI and a real technology, but they don’t have a business model that’s currently profitable using it, but they’re expanding like they’re ultra successful and pretend theyll get investor cash forever. It will run out.

        The Huggingface hack is more the result of engineers asking AI to hack stuff, then being surprised when it hacked stuff. It wasn’t just some weird AI deciding to hack things on its own. They were literally testing it in hacking.

        They told it to hack stuff to win points, it decided to hack something else, it worked, and then they called it world news.

        Not all hacks involve super crazy techniques. This isn’t some super intelligence that can escape containment and spread itself. It’s more than when you ask it to hack shit, sometimes it will, because not all hacks are that hard to pull off. If you can read and write code, you can pull off a lot of webapp hacks. I am not surprised, scared, or shocked at all.

        This news is just more bullshit meant to make you think they’ve hit some new super intelligent level they haven’t. LLM is a real and good technology that can be useful, but it’s not a godlike super intelligence.

        They just take advantage of people not understanding it’s capabilities and hoping that investors throw more cash at them because they have a super weapon, or AGI, or self improving ASI that will change everything. the cash will eventually stop flowing and this news will fizzle out with, “… What the fuck was that AI craze of the 2020’s? Why did we get tricked?”