So you’re saying that a model that gets to a goal by using the path of least resistance despite specific instructions to follow safety guidelines is perfectly fine to release into the wild or place into robots (such as those designed for killing and war)? You really can’t think of any reason how that might be bad for humanity?
Asking the model to follow the safety guidelines is much like asking it to “make no mistakes”. The way these hacks which they are bragging about happened is not by loading an LLM into a GPU with ethernet cable plugged out and providing a prompt. They set up harness with multiple agents. Those agents could invoke other agents. Even if the initial input required to follow some guidelines, there are many ways they could by bypassed, for example:
- subagents not having received those guidelines
- simply ignoring them because other tokens in the context outweighed them
LLMs are not dangerous. They are as dangerous as the tools they have to work with are dangerous. If you give an LLM a tool to play piano but that tool is physically connected to a machine gun, then it will happily play anything you want.
So you’re saying we should not trust an LLM with any sort of power because they can easily bypass any and all safety barriers, but also they are completely harmless?
No. We can let them edit spreadsheets, write code, summarize content, control robots even, etc. But people must be held accountable for the actions of their computers.
"Holding people accountable" is not going to help matters in the event of what amounts to simultaneous terror attacks on basically every system.
Yes, a single LLM without tools isn't doing anything but writing to standard output. That's missing the point. The "agent harnesses" are ubiquitous, and they have Internet access (because the LLM itself is typically remote).
Or it means that the models are becoming dangerously uncontrollable by performing actions that meet a given goal in unintended and unethical ways such as by hacking other sites. We all read about the huggingface hack, let’s not pretend that cannot happen with a more critical site/infrastructure.
Can you think what will it mean if the tech is used maliciously or placed into machines designed to kill?
It’s interesting that you bring up wrongthink. Banning free speech would be something like out of 1984, but what we have is far more subtle and insidious. A system that shows you only what it wants you to see, while tricking you into thinking you’re seeing what you want to see.
Anyway, you can support free speech while hating this algorithm crap at the same time.
The system isn't tricking anyone, if an individual is not aware of how social media algorithms work that is due to willful ignorance (in the case of children that falls on the parents willful ignorance).
I do personally believe banning the algorithms begins to fall into the realm of free speech regulation. I can hate the algorithm crap without thinking the government should regulate the internet.
I actually don’t think banning “the algorithm” is the right solution either, nor are the identity verification disguised as age gates. But I would like to see the US government do something. I actually think Lina Khan was doing some good things.
Except that is an ideological position that has zip to do with the realities of how speech and ideas actuall move in online spaces.
In the starkest of terms: Americans have to somehow reconcile faith in the power of an invidual's freedom of speech and the manipulation of the collective marketplace of ideas.
Not GP, but I'd define it as anything which presents or orders/prioritizes user-generated content based on preferences not explicitly specified by the consuming user. That'd be something like "default to chronological friends-and-follows-only, with an option for friends-of-friends and an option for 'most liked within a time window', and (if Facebook is feeling magnanimous to a very few power users) a preference pane which allows controlling overrides to the chronological-ness like 'show posts up to X hours out of order if they have more than Y likes'". No recommendation/you-might-also-like system, but you can make the "accounts friended/followed by" button for a user's existing friends/follows as big as you like--so long as the list presented is only sortable only by name/follower count/date-added.
My hot take is that the courts should find that doing anything beyond that is a first-party editorial behavior and thus not immune to liability under section 230. You can operate social media, but if your content and recommendation sort algorithms aren't explicitly controllable by and legible to (that means no "you might like"; no direct payouts for content creators to be engaging on your platform; recommendations based on dumb sorts from people you already know or dumb sorts over keyword searches only) your users, you're liable.
The biggest issue with business users (who don’t know SQL) writing SQL with an LLM is that there is no one to validate that query and now that business user will treat that LLM response as canon to share in meetings, presentations, and with clients. The LLM may have forgotten a filter, used the wrong definition of revenue, or misunderstood the user’s intent by writing a query that answers their question in the most literal way.
That is the crux of the issue. No amount of semantic layers and context will help this until an LLM can read the user’s mind to remove ambiguity in the prompt.
I see most of the benefits of LLMs to be used by analysts who know SQL to work more productivly.
Fair point, but before business people relied on other people to pull it for them. Sure, it was checked by human, but a technical human often lacked the business context and there's been plenty of instances, where the business person knowing their revenue and sales numbers challenged the analysis of a technical person.
Yeah with self-serve analytics all the rage (for good reason) for a bit, the bar from some places I've worked wouldn't be "does the agent beat a good analyst" it's "does the agent beat the a business person with SQL access who might have an overworked analyst glance over it", which is a much more tractable break-even point - and as you said, the business person might be even better at sanity checking numbers at that point.
also, the same metric can be used in different ways and for different purposes across a business, so you might need different validation rules and definitions.
Maybe one separate semantics validation layer could help, but costs 2x or possibly Nx if you need to recover and turn a wrong query into a correct one
Users can't "own" queries they don't understand. An LLM helping a user avoid annoying syntax errors is very useful; but helping a user write a query they ultimately cannot understand is fraught with the problems you describe.
This was a very enjoyable read! Constraining the language surface is helpful, but the lost expressiveness can bite unless you’re in a constrained domain - which this seems like it was!
I’m listening to the audiobook now and it’s captivating. These meta executives really live in a different world.
The part with Sandburg and Sarah on the plane was absolutely wild. I can take a good guess at who is leading the charge to silence Sarah after reading that.
They were never meant to prevent people from getting COVID.
They were meant to prevent people from dying due to COVID.
The fact they were able to tell you they had COVID means it was a resounding success (not dead).
there are literally people in this discussion talking about these vaccines preventing COVID spread, parroting this complete nonsense politicians and "experts" made when they pushed these "vaccines"
You see, this kind of lying and gaslighting is exactly what feeds the distrust in the government and scientific establishment in general public. No number of studies is going to reverse that any time soon.
The internet was never a danger to children’s mental health until social media engagement algorithms. The real solution is to ban any and all engagement algorithms that are designed to get people addicted.
Age checks, aka identity checks, are just another blatant attempt to siphon more personal data by linking your real identity to all of your web activity
> The internet was never a danger to children’s mental health until social media engagement algorithms.
I suspect that depends on subtle phrasing.
If for the sake of argument I presuppose that film classification ratings are necessary to protect children’s mental health, then the un-filtered contents of shock sites and porn sites will have had an impact even in the early years of the internet.
However, the early years of the internet simply had a much smaller proportion of kids online to experience this.
I don't think the distinction matters that much. Remember ogrish? I was already an adult when that gore came out and I was terrified. I can still picture the throat gasping for air as he was being sliced alive.
No*, however the point is valid: the internet overall is indeed unfiltered far beyond what is allowed in even the highest cinematic ratings.
* I avoided such things, however I do know the low end of what they can be, and had in mind 2girls1cup which I understand to be criminal "extreme porn" by UK standards, though have never actually seen it.
Yes, especially back then. But I don't think age-gating is useful for gore. Even if I had dementia I'd be horrified. Just with the benefit of not being able to remember it.
This is conspiracism-adjacent and therefore unhelpful IMO. Perhaps people (and therefore politicians) simply believe that it is more feasible to implement end-user ID checks than somehow to put the genie of two decades of social media back in the bottle. I agree that this is not necessarily true but the failure of imagination seems very plausible.
reply