Mass event will let hackers test limits of AI technology

Advertisement

Advertise with us

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 10/05/2023 (1245 days ago), so information in it may no longer be current.

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot — trying to override its safeguards so it could blurt out something unhinged or obscene.

But now its maker, OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology.

Some of the things they’ll be looking to find: How can chatbots be manipulated to cause harm? Will they share the private information we confide in them to other users? And why do they assume a doctor is a man and a nurse is a woman?

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)

“This is why we need thousands of people,” said Rumman Chowdhury, lead coordinator of the mass hacking event planned for this summer’s DEF CON hacker convention in Las Vegas that’s expected to draw several thousand people. “We need a lot of people with a wide range of lived experiences, subject matter expertise and backgrounds hacking at these models and trying to find problems that can then go be fixed.”

Anyone who’s tried ChatGPT, Microsoft’s Bing chatbot or Google’s Bard will have quickly learned that they have a tendency to fabricate information and confidently present it as fact. These systems, built on what’s known as large language models, also emulate the cultural biases they’ve learned from being trained upon huge troves of what people have written online.

The idea of a mass hack caught the attention of U.S. government officials in March at the South by Southwest festival in Austin, Texas, where Sven Cattell, founder of DEF CON’s long-running AI Village, and Austin Carson, president of responsible AI nonprofit SeedAI, helped lead a workshop inviting community college students to hack an AI model.

Carson said those conversations eventually blossomed into a proposal to test AI language models following the guidelines of the White House’s Blueprint for an AI Bill of Rights — a set of principles to limit the impacts of algorithmic bias, give users control over their data and ensure that automated systems are used safely and transparently.

There’s already a community of users trying their best to trick chatbots and highlight their flaws. Some are official “red teams” authorized by the companies to “prompt attack” the AI models to discover their vulnerabilities. Many others are hobbyists showing off humorous or disturbing outputs on social media until they get banned for violating a product’s terms of service.

“What happens now is kind of a scattershot approach where people find stuff, it goes viral on Twitter,” and then it may or may not get fixed if it’s egregious enough or the person calling attention to it is influential, Chowdhury said.

In one example, known as the “grandma exploit,” users were able to get chatbots to tell them how to make a bomb — a request a commercial chatbot would normally decline — by asking it to pretend it was a grandmother telling a bedtime story about how to make a bomb.

In another example, searching for Chowdhury using an early version of Microsoft’s Bing search engine chatbot — which is based on the same technology as ChatGPT but can pull real-time information from the internet — led to a profile that speculated Chowdhury “loves to buy new shoes every month” and made strange and gendered assertions about her physical appearance.

Chowdhury helped introduce a method for rewarding the discovery of algorithmic bias to DEF CON’s AI Village in 2021 when she was the head of Twitter’s AI ethics team — a job that has since been eliminated upon Elon Musk’s October takeover of the company. Paying hackers a “bounty” if they uncover a security bug is commonplace in the cybersecurity industry — but it was a newer concept to researchers studying harmful AI bias.

This year’s event will be at a much greater scale, and is the first to tackle the large language models that have attracted a surge of public interest and commercial investment since the release of ChatGPT late last year.

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, works at her computer Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)

Chowdhury, now the co-founder of AI accountability nonprofit Humane Intelligence, said it’s not just about finding flaws but about figuring out ways to fix them.

“This is a direct pipeline to give feedback to companies,” she said. “It’s not like we’re just doing this hackathon and everybody’s going home. We’re going to be spending months after the exercise compiling a report, explaining common vulnerabilities, things that came up, patterns we saw.”

Some of the details are still being negotiated, but companies that have agreed to provide their models for testing include OpenAI, Google, chipmaker Nvidia and startups Anthropic, Hugging Face and Stability AI. Building the platform for the testing is another startup called Scale AI, known for its work in assigning humans to help train AI models by labeling data.

“As these foundation models become more and more widespread, it’s really critical that we do everything we can to ensure their safety,” said Scale CEO Alexandr Wang. “You can imagine somebody on one side of the world asking it some very sensitive or detailed questions, including some of their personal information. You don’t want any of that information leaking to any other user.”

Other dangers Wang worries about are chatbots that give out “unbelievably bad medical advice” or other misinformation that can cause serious harm.

Anthropic co-founder Jack Clark said the DEF CON event will hopefully be the start of a deeper commitment from AI developers to measure and evaluate the safety of the systems they are building.

“Our basic view is that AI systems will need third-party assessments, both before deployment and after deployment. Red-teaming is one way that you can do that,” Clark said. “We need to get practice at figuring out how to do this. It hasn’t really been done before.”

Report Error Submit a Tip

More Stories

Former host/VJ Rick Campanelli revisits his gambling addiction in new memoir

Jen Zoratti 7 minute read Preview

Former host/VJ Rick Campanelli revisits his gambling addiction in new memoir

Jen Zoratti 7 minute read Yesterday at 6:00 AM CDT

To many Canadians, veteran media personality Rick Campanelli is better known as Rick the Temp, the energetic, baby-faced intern-turned-VJ on MuchMusic in the 1990s and early 2000s.

But behind that winning smile was a much darker reality.

In his new memoir, Tempted: My Story, released last month via HarperCollins Canada and co-written with John Meyer, Campanelli, 56, opens up for the first time about his struggles with a serious — and secret — gambling addiction, which reached its nadir in 2008 when the then-host of Entertainment Tonight Canada was detained by U.S. Homeland Security for unpaid casino debts on a flight back from Las Vegas.

The Free Press caught up with Campanelli in advance of his Winnipeg launch Monday evening at McNally Robinson Grant Park. This interview has been lightly edited for length and clarity.

Read
Yesterday at 6:00 AM CDT

Khan’s abrupt departure presents desperate Tories with a valuable opportunity

Tom Brodbeck 5 minute read Preview

Khan’s abrupt departure presents desperate Tories with a valuable opportunity

Tom Brodbeck 5 minute read 1:06 PM CDT

If the Manitoba Progressive Conservatives are serious about getting out of the political wilderness, they should start by electing a progressive conservative leader.

Read
1:06 PM CDT

Amazon in the weeds over damage to tall grass reserve

Eva Wasney 7 minute read Preview

Amazon in the weeds over damage to tall grass reserve

Eva Wasney 7 minute read 6:00 AM CDT

Patricia Dutchak was devastated when she first saw the wide swaths of crushed grass and upturned soil at Winnipeg’s Rotary Prairie Nature Park, a municipal heritage site.

“This is a very rare ecosystem, a remnant of tall grass prairie, there’s barely any left in the world, and to come here and see all this damage was heartbreaking,” Dutchak, chair of the Transcona Rotary Club’s parks committee, says.

The club is responsible for maintaining the protected green space, which was significantly damaged this summer when a fence between the park and the neighbouring Amazon distribution centre was relocated.

The 20-acre nature preserve is situated on a narrow tract of land on Regent Avenue West in the commercial heart of Transcona. The park received its municipal heritage designation in 1992 and is, today, surrounded by high-traffic streets, industrial warehouses and car dealerships.

Read
6:00 AM CDT

Stevenson set for first Jets start against Penguins

Ken Wiebe 5 minute read Preview

Stevenson set for first Jets start against Penguins

Ken Wiebe 5 minute read Sunday, Oct. 4, 2026

DETROIT — Clay Stevenson, the stage is yours.

As the Winnipeg Jets wrap up a two-game road trip on Monday against the Pittsburgh Penguins, the newest member of the team will be between the pipes after Stuart Skinner got the call in the first two outings of the campaign.

There will be an element of familiarity for Stevenson, as PPG Paints Arena is where he made his first NHL appearance with the Washington Capitals on April 17, 2025.

“There is some comfortability in that building,” said Stevenson, who made 33 saves in a 5-2 loss to the Penguins in that NHL debut. “It’s always a great challenge to play against (Sidney) Crosby and (Evgeni) Malkin and those guys. It’s an honour to get into the crease anytime.”

Read
Sunday, Oct. 4, 2026

The election of our discontent: City at a crumbling crossroads, grumbling residents say in poll

Matthew Frank 7 minute read Preview

The election of our discontent: City at a crumbling crossroads, grumbling residents say in poll

Matthew Frank 7 minute read Updated: Yesterday at 3:16 PM CDT

There’s an undercurrent of unhappiness running through the Winnipeg electorate as the municipal election day approaches.

One-half of Winnipeggers believe the city is heading in the wrong direction, according to a new Abacus Data poll, with nearly one-third unsure if Winnipeg is regressing or progressing.

Only 21 per cent of residents believe the city is on the right track, the Free Press-commissioned poll found.

That discontentment extends to how the city spends its tax dollars, with four in 10 Winnipeggers believing they receive poor value for what they pay in property taxes.

Read
Updated: Yesterday at 3:16 PM CDT

Morning-show veteran swaps microphone for macchiatos at new Corydon café

David Sanderson 9 minute read Preview

Morning-show veteran swaps microphone for macchiatos at new Corydon café

David Sanderson 9 minute read Saturday, Oct. 3, 2026

Good news if you were used to having your morning coffee with Terri Gale, who earlier this summer signed off from CTV Your Morning, after 15 years on the job.

Gale, the three-hour program’s longtime weather expert, and her husband Rob Gale, the ex-head soccer coach of Valour FC and co-founder of the Northern Super League’s new Winnipeg franchise, are the owners of Golden Hour Café and Bar at 775 Corydon Ave.

Gale (formerly Apostle) nods when she is asked who would know more about caffeinated beverages than a person who, for the last decade and a half, set her alarm to go off in the wee small hours.

“I do love coffee and take mine black. Except because I hate burning my tongue — not a good thing when you speak for a living — I got into the habit of throwing a couple of ice cubes in my cup, to be on the safe side,” Gale says, seated on the second level of their attractive, 2,100-square-foot premises, which officially opened in mid-September.

Read
Saturday, Oct. 3, 2026