Mass event will let hackers test limits of AI technology

Advertisement

Advertise with us

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 10/05/2023 (1200 days ago), so information in it may no longer be current.

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

But now its maker, OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology.

Some of the things they’ll be looking to find: How can chatbots be manipulated to cause harm? Will they share the private information we confide in them to other users? And why do they assume a doctor is a man and a nurse is a woman?

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)

“This is why we need thousands of people,” said Rumman Chowdhury, lead coordinator of the mass hacking event planned for this summer’s DEF CON hacker convention in Las Vegas that’s expected to draw several thousand people. “We need a lot of people with a wide range of lived experiences, subject matter expertise and backgrounds hacking at these models and trying to find problems that can then go be fixed.”

Anyone who’s tried ChatGPT, Microsoft’s Bing chatbot or Google’s Bard will have quickly learned that they have a tendency to fabricate information and confidently present it as fact. These systems, built on what’s known as large language models, also emulate the cultural biases they’ve learned from being trained upon huge troves of what people have written online.

The idea of a mass hack caught the attention of U.S. government officials in March at the South by Southwest festival in Austin, Texas, where Sven Cattell, founder of DEF CON’s long-running AI Village, and Austin Carson, president of responsible AI nonprofit SeedAI, helped lead a workshop inviting community college students to hack an AI model.

Carson said those conversations eventually blossomed into a proposal to test AI language models following the guidelines of the White House’s Blueprint for an AI Bill of Rights — a set of principles to limit the impacts of algorithmic bias, give users control over their data and ensure that automated systems are used safely and transparently.

There’s already a community of users trying their best to trick chatbots and highlight their flaws. Some are official “red teams” authorized by the companies to “prompt attack” the AI models to discover their vulnerabilities. Many others are hobbyists showing off humorous or disturbing outputs on social media until they get banned for violating a product’s terms of service.

“What happens now is kind of a scattershot approach where people find stuff, it goes viral on Twitter,” and then it may or may not get fixed if it’s egregious enough or the person calling attention to it is influential, Chowdhury said.

In one example, known as the “grandma exploit,” users were able to get chatbots to tell them how to make a bomb — a request a commercial chatbot would normally decline — by asking it to pretend it was a grandmother telling a bedtime story about how to make a bomb.

In another example, searching for Chowdhury using an early version of Microsoft’s Bing search engine chatbot — which is based on the same technology as ChatGPT but can pull real-time information from the internet — led to a profile that speculated Chowdhury “loves to buy new shoes every month” and made strange and gendered assertions about her physical appearance.

Chowdhury helped introduce a method for rewarding the discovery of algorithmic bias to DEF CON’s AI Village in 2021 when she was the head of Twitter’s AI ethics team — a job that has since been eliminated upon Elon Musk’s October takeover of the company. Paying hackers a “bounty” if they uncover a security bug is commonplace in the cybersecurity industry — but it was a newer concept to researchers studying harmful AI bias.

This year’s event will be at a much greater scale, and is the first to tackle the large language models that have attracted a surge of public interest and commercial investment since the release of ChatGPT late last year.

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)

Chowdhury, now the co-founder of AI accountability nonprofit Humane Intelligence, said it’s not just about finding flaws but about figuring out ways to fix them.

“This is a direct pipeline to give feedback to companies,” she said. “It’s not like we’re just doing this hackathon and everybody’s going home. We’re going to be spending months after the exercise compiling a report, explaining common vulnerabilities, things that came up, patterns we saw.”

Some of the details are still being negotiated, but companies that have agreed to provide their models for testing include OpenAI, Google, chipmaker Nvidia and startups Anthropic, Hugging Face and Stability AI. Building the platform for the testing is another startup called Scale AI, known for its work in assigning humans to help train AI models by labeling data.

“As these foundation models become more and more widespread, it’s really critical that we do everything we can to ensure their safety,” said Scale CEO Alexandr Wang. “You can imagine somebody on one side of the world asking it some very sensitive or detailed questions, including some of their personal information. You don’t want any of that information leaking to any other user.”

Other dangers Wang worries about are chatbots that give out “unbelievably bad medical advice” or other misinformation that can cause serious harm.

Anthropic co-founder Jack Clark said the DEF CON event will hopefully be the start of a deeper commitment from AI developers to measure and evaluate the safety of the systems they are building.

“Our basic view is that AI systems will need third-party assessments, both before deployment and after deployment. Red-teaming is one way that you can do that,” Clark said. “We need to get practice at figuring out how to do this. It hasn’t really been done before.”

Report Error Submit a Tip

More Stories

Executive exodus continues at Shared Health with three recent departures

Chris Kitching 5 minute read Preview

Executive exodus continues at Shared Health with three recent departures

Chris Kitching 5 minute read Updated: Yesterday at 4:18 PM CDT

Manitoba’s provincial health authority is looking for its fourth chief financial officer since 2023 and additional replacements after the recent departures of three executives.

Read
Updated: Yesterday at 4:18 PM CDT

NDP touts health-care gains, but critics question impact on ER wait times

Tom Brodbeck 5 minute read Preview

NDP touts health-care gains, but critics question impact on ER wait times

Tom Brodbeck 5 minute read Yesterday at 6:00 AM CDT

Health Minister Uzoma Asagwara doesn’t mince words when describing how bad things are in the province’s emergency departments and urgent-care centres.

“The wait times that we are seeing in Manitoba are unacceptable,” said Asagwara in an interview with the Free Press.

“I hear from families, I hear from providers, I hear from Manitobans who are concerned about the wait times that they’re seeing, that they’re experiencing, and those concerns are valid — I share those concerns.”

So what is the NDP, who promised voters nearly three years ago it had the answers to bring down wait times, doing about it?

Read
Yesterday at 6:00 AM CDT

Mass event will let hackers test limits of AI technology

Matt O'brien, The Associated Press 6 minute read Preview

Mass event will let hackers test limits of AI technology

Matt O'brien, The Associated Press 6 minute read Wednesday, May. 10, 2023

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

But now its maker, OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology.

Some of the things they'll be looking to find: How can chatbots be manipulated to cause harm? Will they share the private information we confide in them to other users? And why do they assume a doctor is a man and a nurse is a woman?

“This is why we need thousands of people," said Rumman Chowdhury, lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas that's expected to draw several thousand people. "We need a lot of people with a wide range of lived experiences, subject matter expertise and backgrounds hacking at these models and trying to find problems that can then go be fixed.”

Read
Wednesday, May. 10, 2023

The trolls inside the Conservative tent

David McLaughlin 5 minute read Preview

The trolls inside the Conservative tent

David McLaughlin 5 minute read 2:00 AM CDT

The Conservative Party of Canada has a troll problem. And it’s coming from inside the tent.

Once, trolls existed only in imagination. They were figures of mythical proportion, big and small. They lived solitary lives under bridges, in caves, or forests. They were considered dim-witted and mean. Best avoided.

Today, they are real, unavoidable, and ubiquitous on social media. They are anything but solitary. There are tribes of them out there and tribal is how they think and post. As for dim-witted and mean, others can opine but they are uniformly mean and dismissive.

Mean to anyone who disagrees with their views. Dismissive of any view but their own. They distribute questionable, at best, facts and opinions grounded in hostility towards anything or anyone deemed disagreeable or heretical to their world view.

Read
2:00 AM CDT

Wooed by wood, Cedarella founder takes pride in handcrafted designs

David Sanderson 7 minute read Preview

Wooed by wood, Cedarella founder takes pride in handcrafted designs

David Sanderson 7 minute read 6:00 AM CDT

Marina Bulan is the founder of Cedarella, a two-year-old venture that turns out eye-catching wood products such as jewelry, kitchen decor, children’s toys and, most recently, metre-high outdoor planters that double as home street-number indicators.

Ahead of immigrating to Winnipeg a decade ago from their native Russia, Bulan and her partner thought it would be prudent to conduct some research on their soon-to-be new home, a city they knew next to nothing about.

Imagine their surprise as they were viewing the 2007 surrealist film My Winnipeg, which comically blends historical facts about our burg with what Winnipeg-born writer/director Guy Maddin has termed “mystical hypothesizing.”

(For instance, there is no proof that, as reported in the award-winning flick, Winnipeg is the sleepwalking capital of the world, and that residents keep keys to their former abodes on their person in the event they turn up there during a bout of somnambulism.)

Read
6:00 AM CDT

Fish briefs

Grace Penner 2 minute read 2:01 AM CDT

The Sioux Falls Canaries had a taste for fish as the club beat the Winnipeg Goldeyes in this week’s series.

Despite being on the road, the Winnipeg Goldeyes (45-37) started off the series with a strong win on Tuesday night. They soloed the scoreboard into the fourth inning with a 7-0 sweep until the Canaries (43-41) snuck in two runs in the bottom. Peyton Holt, Adam Hall, Ramón Bramasco, and Noah Marcelo had four runs in the top of that inning.

Even though Sioux Falls were able to slowly make their way up to six runs, catcher/infielder Marcelo secured their lead hitting two homers driving in two runs during the game.

Pitcher Landen Bourassa held the mound the majority of the innings, striking out seven, with relief pitchers Sage Ferguson and Derrick Cherry guarding the lead to give the Fish the 9-6 win.