Mass event will let hackers test limits of AI technology

Advertisement

Advertise with us

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 10/05/2023 (1198 days ago), so information in it may no longer be current.

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

But now its maker, OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology.

Some of the things they’ll be looking to find: How can chatbots be manipulated to cause harm? Will they share the private information we confide in them to other users? And why do they assume a doctor is a man and a nurse is a woman?

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)

“This is why we need thousands of people,” said Rumman Chowdhury, lead coordinator of the mass hacking event planned for this summer’s DEF CON hacker convention in Las Vegas that’s expected to draw several thousand people. “We need a lot of people with a wide range of lived experiences, subject matter expertise and backgrounds hacking at these models and trying to find problems that can then go be fixed.”

Anyone who’s tried ChatGPT, Microsoft’s Bing chatbot or Google’s Bard will have quickly learned that they have a tendency to fabricate information and confidently present it as fact. These systems, built on what’s known as large language models, also emulate the cultural biases they’ve learned from being trained upon huge troves of what people have written online.

The idea of a mass hack caught the attention of U.S. government officials in March at the South by Southwest festival in Austin, Texas, where Sven Cattell, founder of DEF CON’s long-running AI Village, and Austin Carson, president of responsible AI nonprofit SeedAI, helped lead a workshop inviting community college students to hack an AI model.

Carson said those conversations eventually blossomed into a proposal to test AI language models following the guidelines of the White House’s Blueprint for an AI Bill of Rights — a set of principles to limit the impacts of algorithmic bias, give users control over their data and ensure that automated systems are used safely and transparently.

There’s already a community of users trying their best to trick chatbots and highlight their flaws. Some are official “red teams” authorized by the companies to “prompt attack” the AI models to discover their vulnerabilities. Many others are hobbyists showing off humorous or disturbing outputs on social media until they get banned for violating a product’s terms of service.

“What happens now is kind of a scattershot approach where people find stuff, it goes viral on Twitter,” and then it may or may not get fixed if it’s egregious enough or the person calling attention to it is influential, Chowdhury said.

In one example, known as the “grandma exploit,” users were able to get chatbots to tell them how to make a bomb — a request a commercial chatbot would normally decline — by asking it to pretend it was a grandmother telling a bedtime story about how to make a bomb.

In another example, searching for Chowdhury using an early version of Microsoft’s Bing search engine chatbot — which is based on the same technology as ChatGPT but can pull real-time information from the internet — led to a profile that speculated Chowdhury “loves to buy new shoes every month” and made strange and gendered assertions about her physical appearance.

Chowdhury helped introduce a method for rewarding the discovery of algorithmic bias to DEF CON’s AI Village in 2021 when she was the head of Twitter’s AI ethics team — a job that has since been eliminated upon Elon Musk’s October takeover of the company. Paying hackers a “bounty” if they uncover a security bug is commonplace in the cybersecurity industry — but it was a newer concept to researchers studying harmful AI bias.

This year’s event will be at a much greater scale, and is the first to tackle the large language models that have attracted a surge of public interest and commercial investment since the release of ChatGPT late last year.

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)

Chowdhury, now the co-founder of AI accountability nonprofit Humane Intelligence, said it’s not just about finding flaws but about figuring out ways to fix them.

“This is a direct pipeline to give feedback to companies,” she said. “It’s not like we’re just doing this hackathon and everybody’s going home. We’re going to be spending months after the exercise compiling a report, explaining common vulnerabilities, things that came up, patterns we saw.”

Some of the details are still being negotiated, but companies that have agreed to provide their models for testing include OpenAI, Google, chipmaker Nvidia and startups Anthropic, Hugging Face and Stability AI. Building the platform for the testing is another startup called Scale AI, known for its work in assigning humans to help train AI models by labeling data.

“As these foundation models become more and more widespread, it’s really critical that we do everything we can to ensure their safety,” said Scale CEO Alexandr Wang. “You can imagine somebody on one side of the world asking it some very sensitive or detailed questions, including some of their personal information. You don’t want any of that information leaking to any other user.”

Other dangers Wang worries about are chatbots that give out “unbelievably bad medical advice” or other misinformation that can cause serious harm.

Anthropic co-founder Jack Clark said the DEF CON event will hopefully be the start of a deeper commitment from AI developers to measure and evaluate the safety of the systems they are building.

“Our basic view is that AI systems will need third-party assessments, both before deployment and after deployment. Red-teaming is one way that you can do that,” Clark said. “We need to get practice at figuring out how to do this. It hasn’t really been done before.”

Report Error Submit a Tip

More Stories

New Bannatyne eatery brings feast of Asian flavours

Eva Wasney 4 minute read Preview

New Bannatyne eatery brings feast of Asian flavours

Eva Wasney 4 minute read Tuesday, Aug. 18, 2026

Matriarchal influences run deep at House of Ma Kitchen and Bar.

Executive chef Dom Merano took inspiration from his mom’s home cooking while developing the menu for the new Exchange District restaurant — specifically Cynthia Merano’s recipes for lumpia (Filipino spring rolls) and kare-kare (braised beef and peanut stew).

“It tastes like home,” Merano says of the dishes, adding that his mom “felt honoured to be able to share her cooking with people. She was actually here prior to opening helping me roll lumpia.”

Cynthia’s photo is hung among the “Wall of Mas” at the back of the restaurant, where the mothers and grandmothers of True Hospitality staff are given pride of place.

Read
Tuesday, Aug. 18, 2026

Manitoba’s liquor regulator has accused an Exchange District nightclub of exceeding its occupant capacity limit and hindering the work of inspectors.

Diablo, located at Main Street and Bannatyne Avenue, is scheduled to appeal two compliance orders, issued by the Liquor, Gaming and Cannabis Authority of Manitoba, at a Sept. 8 hearing.

An LGCA spokesperson said the compliance orders are part of an ongoing investigation.

The spokesperson said one of the orders was issued after the licensed club was over capacity April 26.

Kids need some sense of split parents’ situation

Maureen Scurfield 5 minute read 2:00 AM CDT

DEAR MISS LONELYHEARTS: On our last day at a beach rental cabin the kids and I were packing up later than the rules asked for, when a familiar car pulled in next door. It was my ex-husband with his new woman and her kids.

My children yelled out, “Look Mom, it’s Daddy! He came to the lake to see us!” and ran over to him for hugs. His girlfriend had the cabin keys dangling, nodded at me, and went inside quickly.

I said to my former husband, “Fancy meeting you here! Come on kids, we’re going home now.” My ex said, “Oh, settle down. Give me a few minutes with my kids, will you?”

So, I finished packing and locked the cabin door, and waited for the kids for 30 minutes in our car. Then I started to cry. It just came gushing out and I couldn’t control it. Finally, my ex brought the children back out. He could see I’d been crying and said in disgust, “Get over it, princess. I have!”

Rural Manitoba homeowner charged with shooting at accused thieves

Nicole Buffie 4 minute read Preview

Rural Manitoba homeowner charged with shooting at accused thieves

Nicole Buffie 4 minute read Tuesday, Aug. 18, 2026

A homeowner in southern Manitoba has been charged after he fired shots at a group of people accused of stealing from his property, police say.

Officers were sent to the Rural Municipality of Dufferin Saturday after a report of a theft in progress. RCMP said four people went to the property, located about 95 kilometres southwest of Winnipeg, and returned later the same day driving two vehicles stolen from Watrous, Sask.

The owner of the property, a 66-year-old man, saw the suspects on a motion-activated camera and saw someone transferring fuel from a portable container into one of the stolen vehicles. The man confronted the group and fired shots towards the vehicles, police said.

Three people stayed at the scene until officers arrived and took them into custody, RCMP said. Various items believed to have been stolen from the property were found in the back of a truck. A fourth suspect fled in the other vehicle.

Read
Tuesday, Aug. 18, 2026

Demolition ordered after fire in vacant city home

Free Press staff 2 minute read Preview

Demolition ordered after fire in vacant city home

Free Press staff 2 minute read 11:56 AM CDT

A Winnipeg firefighter was assessed by paramedics and an emergency demolition was ordered after a vacant house caught fire Thursday morning for the second time in less than three months.

The two-storey home, at Argyle Street and Disraeli Freeway, in South Point Douglas, was boarded up following a blaze that occurred June 1.

Firefighters returned to the house after flames were reported shortly after 6 a.m. Thursday. The house was engulfed when crews arrived.

“Due to heavy fire conditions, crews were unable to enter the structure,” a Winnipeg Fire Paramedic Service spokesperson wrote in an email to the Free Press.

Read
11:56 AM CDT

Sisters among 137 to begin doctor journey at U of M

Nicole Buffie 4 minute read Preview

Sisters among 137 to begin doctor journey at U of M

Nicole Buffie 4 minute read Yesterday at 6:32 PM CDT

Not everyone enters medical school with a built-in study buddy.

Sisters Maya and Dana Jalal joined 135 of their classmates to don white coats and mark the beginning of their journey through the University of Manitoba’s Max Rady College of Medicine Wednesday morning.

Maya, 22, and Dana, 21, were accepted into medical school at the same time.

“Thankfully, we both got accepted in the same area, same time. So we decided we’d rather go together than apart,” Maya said. “It’ll be nice seeing different perspectives during our studies. We are siblings, but we each have our own perspectives, our own lived experiences.”

Read
Yesterday at 6:32 PM CDT