lagrangeinterpolator

joined 1 year ago

Some systems like SynthID (for Google's AI) get around this problem. In fact you don't need to know the LLM's internal state, and defeating it would likely involve breaking up most blocks of 3 words. The oversimplified explanation is that it introduces a function g that gives a score to each word, with the score being (pseudo)randomly determined by your secret key. For each next word the LLM generates, the LLM produces a small list of candidate next words, and the one with the highest score according to g is selected. You should expect that the LLM will generally pick words with a high score, but the score itself is independent of the LLM. To detect a watermark, you need to know g and the secret key, and you check if the average score is much higher than expected from normal text.

Now, one question is, will this bias to the LLM to favor certain words? The solution is that for each next word, you append the last 3 words (nothing special about 3, just a small number) to the secret key for g, and this repeatedly scrambles which words have a high score. To defeat the watermark, you would need to break up most blocks of 3 words. I'm sure there are deeper issues with this, but I have not studied the topic that much.

[–] lagrangeinterpolator@awful.systems 5 points 2 days ago (1 children)

From a technical perspective, I don't really know how to let it track specific users. The goal is that if some AI vendor provides their key, it is easy for them to prove that their AI produced the text. So I guess if a user wanted to show that they generated the text, they could prove it. But usually AI users don't want people knowing that they used the slop cannon. In any case, Anthropic's own announcement states that their watermark does not contain identifying information for users.

In any case, some proud AI users are now frightened that there might be a way for people to identify that they use such a wonderful tool. How will I ever deliver low quality slop for my contracts now?

He said he uses AI for code reviews and translations, and worried an AI label on code shipped to clients could raise questions about authorship or trigger contract penalties.

Having code attributed to Claude "definitely would be not desirable," he said, as he would not want professionally shipped code to carry an invisible marker that could raise questions about authorship, compliance, or client policies.

[–] lagrangeinterpolator@awful.systems 6 points 2 days ago (1 children)

My pet theory is that their reading comprehension has degraded, so this is all they can handle now.

[–] lagrangeinterpolator@awful.systems 12 points 2 days ago* (last edited 2 days ago) (7 children)

Anthropic is now watermarking the outputs of its AI. For once this is some AI news that doesn't completely piss me off, and it's amusing to see all the uninformed boosters get in a tizzy about this.

I actually understand at a reasonable level how this watermarking works. A year ago, I watched Scott Aaronson give a talk about it, and from what I know he was somewhat involved in developing the theory behind it while working for OpenAI. But at the time my thought was, "He is naive if he thinks these companies would ever implement this out of the goodness of their hearts." And I was right; Anthropic is only doing watermarking now thanks to the EU AI Act, even though the theory has long been developed.

Watermarking doesn't mean adding an extra watermark that can be easily removed. It instead directly affects the output of the chatbot itself. Fundamentally, an LLM is still a most-likely-next-word-predictor. More precisely, an LLM produces a probability distribution of what the next word can be. For example, "my pet is a ..." could give a distribution of 60% dog, 30% cat, and 10% axolotl. Normally, an LLM would randomly choose the next word based on this distribution, and this is one reason why LLMs are nondeterministic (there's another parameter called "temperature" that affects this, but no need to get into that).

With watermarking, instead of a truly random choice, the randomness instead comes from a cryptographic pseudorandom generator seeded with a secret key from the AI company. If you don't know the secret key, then you can't really tell that watermarking was used. But if you do know the secret key, then the idea is you can tell when the text was generated by the LLM because you know exactly what word should be next. It would be a freak coincidence if some non-AI text just happened to choose the correct next word every time. Thus, you can provide a service to tell if some text was generated by the LLM. (This technically makes the LLM "deterministic", in a completely useless sense.)

Now, I think this is a step in the right direction, but it has its limits. The biggest problem is that you don't want people to just move to a different LLM without watermarking, and that's exhibit #832593 why government regulation is important. Another issue is that sometimes there is very little randomness in what the next word should be ("The first president of the USA is George ..."). Finally, watermarking can be defeated by editing the output, although you would have to break up most of the blocks of consecutive words. I have a feeling most AI users are not the type to put in extra effort after copy-pasting the output directly from the chat window.

I suppose it will discourage some of the "use cases" of LLMs, such as drowning the world with spam Slopstack essays. Ah, who am I kidding? Everyone could already tell it's AI generated, they don't care!

[–] lagrangeinterpolator@awful.systems 14 points 1 week ago (3 children)

Mathematicians are not entirely happy about OpenAI's ten mathematical results. As it turns out, the proofs did not cite many of the existing techniques in the literature. The plagiarism bot is still a plagiarism bot. https://www.scientificamerican.com/article/openais-latest-math-breakthroughs-commit-research-misconduct-experts-say/

“They are running roughshod over the work of others who came before them in a deliberate way,” says Steven Miller, a mathematician at Yeshiva University, who argues that OpenAI has effectively plagiarized his own research. “It seems completely systematic to me, and it points to research misconduct.”

The LLM-generated proof hinges on a particular mathematical argument that it presented as its own but that actually first appeared in a 2016 paper by Miller and a collaborator.

The discovery stunned Francesco Fournier-Facio, a mathematician at the University of Cambridge, who studies group theory—at least until he “engaged with this breakthrough as I would if a human had written it,” he says. The result, he and some of his colleagues found, wasn’t as novel as it first appeared. Like a number of recent AI breakthroughs, it pasted together ideas from the mathematical literature to build a new theorem. Once again, the LLM’s trick is its superhuman patience for assembling puzzle pieces, not the ability to make some profound intellectual leap.

In particular, Astra’s key mathematical step combined ideas first found in two papers from 2016 and 2019. Andreas Thom, a mathematician at the Dresden University of Technology, who co-authored the 2019 paper, summarized the result on MathOverflow.com, calling it “creative and at the same time elementary.”

He is spending the equivalent of $1 million a year on tokens just to develop this game with 6 concurrent players on a good day. Of course, he isn't actually paying that much. Instead, he just has a dozen different $200/mo Max subscriptions to get the same amount of tokens for $33k a year.

AI economics, baby!

[–] lagrangeinterpolator@awful.systems 12 points 1 week ago* (last edited 1 week ago) (6 children)

Clammy Sammy acknowledges Ed Zitron for the first time! https://xcancel.com/sama/status/2084663673570971990

His response is the Live Laugh Love of 2015 Silicon Valley platitudes:

i would rather be an optimist and work hard than a pessimist posting about why things won't work.

it's much more difficult and the most likely path is failure, but society fails if people don't try.

no amount of "it will never work" essays will drive society forward.

Of course, building data centers that use untold amounts of rare earth metals, electricity, and water while spewing out tons of pollution and scraping every last bit of human content in order to remove people from their jobs by doing them badly is what drives society forward. Profits fail if oligarchs don't try. Actually, the AI companies don't even need profits.

[–] lagrangeinterpolator@awful.systems 15 points 2 weeks ago (3 children)

The OpenAI hacking incident has put everyone on edge. Anthropic, not to be outdone, decides to publicly announce that they have committed not one, not two, but three crimes! Come on! I was told this wasn't a marketing campaign!

[–] lagrangeinterpolator@awful.systems 10 points 2 weeks ago* (last edited 2 weeks ago) (9 children)

Before the days of AI 2027, he became famous in 2024 for posting one of the original pieces of writing in the line-go-up genre: Situational Awareness. It seems that like any good grifter, he used this opportunity to make money (in this case by starting a hedge fund).

[–] lagrangeinterpolator@awful.systems 14 points 2 weeks ago* (last edited 2 weeks ago) (3 children)

There is something about this picture, a warehouse full of books to be destroyed by Anthropic for training data, that just makes me sick. Knowing that they are destroying books in the abstract is bad enough, but seeing the sheer scale of it makes me viscerally angry.

Karen Hao called her book Empire of AI for a very good reason. The empire has all these noble narratives of bringing civilization and progress to the colonies, but in reality the empire only sees resources to be extracted, repackaged, and sold back to their subjects at a fee. Kudos to those who saw this immediately and fought against it. Shame on those who believed in the narrative of progress, to the point where many of them are collaborators with the empire.

Whenever a smarmy fellow on Linkedin posts about how AI is making so much progress in coding or math, I want them to see this picture. I want them to see the videos of families in tears after a data center takes away their home with eminent domain, and other families who have to deal with the resulting pollution. Go beyond the bloodless math of tokens and instead see for yourself what this all truly costs. I hope it was worth it.

It gets worse. I found another article about the same podcast: Sam Altman says AI won't shorten the workweek because humans secretly enjoy being busy.

"Technology, for a long time, has been promising people that they're going to work less and they're going to have all this leisure," Altman said. "But somehow we never get the promise of the four-hour workweek at mass scale in society," he added. "And I don't expect AI to change that."

"It's like a relative game. People are very focused on how they're doing relative to other people," the CEO said.

"I think we're all going to be much busier than we thought we were supposed to be in a post-superintelligence world. We're still going to complain about it, but secretly we're going to be happy," Altman concluded.

The chuds are all at r/accelerate now. "We're the unapologetically Pro-AI alternative to r/singularity, r/futurology, r/artificial & r/technology which are becoming filled with Luddites, Techno-Decelerationists, Techno-Reactionaries, & Anti-AIs."

view more: next ›