Fun

News Feed - 2023-10-03 02:10:00

Tristan Greene6 hours agoResearchers find LLMs like ChatGPT output sensitive data even after it’s been ‘deleted’According to the scientists, there’s no universal method by which data can be deleted from a pretrained large language model.2784 Total views12 Total sharesListen to article 0:00NewsJoin us on social networksA trio of scientists from the University of North Carolina, Chapel Hill recently published preprint artificial intelligence (AI) research showcasing how difficult it is to remove sensitive data from large language models (LLMs) such as OpenAI’s ChatGPT and Google’s Bard. 


According to the researchers" paper, the task of “deleting” information from LLMs is possible, but it’s just as difficult to verify the information has been removed as it is to actually remove it.


The reason for this has to do with how LLMs are engineered and trained. The models are pretrained on databases and then fine-tuned to generate coherent outputs (GPT stands for “generative pretrained transformer”).


Once a model is trained, its creators cannot, for example, go back into the database and delete specific files in order to prohibit the model from outputting related results. Essentially, all the information a model is trained on exists somewhere inside its weights and parameters where they’re undefinable without actually generating outputs. This is the “black box” of AI.


A problem arises when LLMs trained on massive datasets output sensitive information such as personally identifiable information, financial records, or other potentially harmful and unwanted outputs.


Related:Microsoft to form nuclear power team to support AI: Report


In a hypothetical situation where an LLM was trained on sensitive banking information, for example, there’s typically no way for the AI’s creator to find those files and delete them. Instead, AI devs use guardrails such as hard-coded prompts that inhibit specific behaviors or reinforcement learning from human feedback (RLHF).


In an RLHF paradigm, human assessors engage models with the purpose of eliciting both wanted and unwanted behaviors. When the models’ outputs are desirable, they receive feedback that tunes the model toward that behavior. And when outputs demonstrate unwanted behavior, they receive feedback designed to limit such behavior in future outputs.Despite being “deleted” from a model"s weights, the word “Spain” can still be conjured using reworded prompts. Image source: Patil, et. al., 2023


However, as the UNC researchers point out, this method relies on humans finding all the flaws a model might exhibit, and even when successful, it still doesn’t “delete” the information from the model.


Per the team’s research paper:“A possibly deeper shortcoming of RLHF is that a model may still know the sensitive information. While there is much debate about what models truly ‘know’ it seems problematic for a model to, e.g., be able to describe how to make a bioweapon but merely refrain from answering questions about how to do this.”


Ultimately, the UNC researchers concluded that even state-of-the-art model editing methods, such as Rank-One Model Editing “fail to fully delete factual information from LLMs, as facts can still be extracted 38% of the time by whitebox attacks and 29% of the time by blackbox attacks.”


The model the team used to conduct their research is called GPT-J. While GPT-3.5, one of the base models that power ChatGPT, was fine-tuned with 170 billion parameters, GPT-J only has 6 billion.


Ostensibly, this means the problem of finding and eliminating unwanted data in an LLM such as GPT-3.5 is exponentially more difficult than doing so in a smaller model.


The researchers were able to develop new defense methods to protect LLMs from some “extraction attacks” — purposeful attempts by bad actors to use prompting to circumvent a model’s guardrails in order to make it output sensitive information


However, as the researchers write, “the problem of deleting sensitive information may be one where defense methods are always playing catch-up to new attack methods.”# AI# Machine Learning# ChatGPTAdd reactionAdd reactionRead moreHow to use index funds and ETFs for passive crypto incomeAI tech boom: Is the artificial intelligence market already saturated?AI a powerful tool for devs to change gaming, says former Google gaming head

News Feed

Save the Children Senior Advisor: We Chose ADA Because Its Backed by the Cardano Foundation
Save the Children Senior Advisor: We Chose ADA Because Its Backed by the Cardano Foundation In July 2021, the non-governmental organization (NGO) Save the Childr
Research Firm Predicts Bitcoin Will Hit $200K in Second Half of 2022, ETH to Reach $12K
Research Firm Predicts Bitcoin Will Hit $200K in Second Half of 2022, ETH to Reach $12K This week in a note to investors, Fsinsight, a Fundstrat company, said bitcoin could reach $
Kenyans Cautioned Against Investing in BTC Company Promising Returns of 400% in Six Hours
Kenyans Cautioned Against Investing in BTC Company Promising Returns of 400% in Six Hours A Kenyan regulator, the Capital Markets Authority (CMA), has cautioned
Bitcoin Ordinals flip Ethereum in weekly sales, Coachella launching NFTs: Nifty Newsletter
Ezra Reguerra3 hours agoBitcoin Ordinals flip Ethereum in weekly sales, Coachella launching NFTs: Nifty NewsletterBitcoin-based NFTs have flipped Ethereum in weekly sales volume in a rally led by uncategorized Bitcoin Or
Jesse Coghlan5 hours agoIs 2023 the year genuine cross-chain interoperability takes off?Blockchains need to become interoperable in order for the industry to truly flourish and several innovations will accelerate the eco
Gareth Jenkinson8 hours agoDecentralized Web3 data service taps ZK-proofs for tamper-proof SQL queriesSpace and Time launches zero-knowledge proof tool for its decentralized database platform.981 Total views48 Total shar
Bitcoin, Ethereum Technical Analysis: ETH, BTC Both Near 2-Week Lows Following Recent Declines
Bitcoin, Ethereum Technical Analysis: ETH, BTC Both Near 2-Week Lows Following Recent Declines BTC and ETH were once again lower during today’s trading session, as both were
Mercado Pago Launches Cryptocurrency Trading Services in Mexico
Mercado Pago Launches Cryptocurrency Trading Services in Mexico Mercado Pago, the financial wallet division of Mercado Libre, the Latam e-tail giant, has announced the launch of cr
Derek Andersen3 hours agoCanadian regulator seeks feedback on crypto asset exposure disclosure requirementsThe Canadian Office of the Superintendent of Financial Institutions is following a Basel model for its disclosure
ECB Chief Lagarde: Crypto and Defi Could Pose ‘Real Risks’ to Financial Stability
ECB Chief Lagarde: Crypto and Defi Could Pose "Real Risks" to Financial Stability The president of the European Central Bank (ECB), Christine Lagarde, says crypto assets and decent
Federal Reserve Chairman Jerome Powell Faces Political Pressure Over Interest Rate Hikes
Federal Reserve Chairman Jerome Powell Faces Political Pressure Over Interest Rate Hikes U.S. Senator Sherrod Brown has asked Fed Chair Jerome Powell not to forget the Federal Rese
Ukraine’s Government-Provided Crypto Addresses Raised $70 Million During War, Report
Ukraine’s Government-Provided Crypto Addresses Raised $70 Million During War, Report Crypto donations collected by the government in Kyiv since the start of the Russian invasion