this post was submitted on 15 Jun 2024
122 points (93.0% liked)

Privacy

31975 readers
615 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 61 points 5 months ago (14 children)

There are VERY FEW fully open LLMs. Most are the equivalent of source-available in licensing and at best, they're only partially open source because they provide you with the pretrained model.

To be fully open source they need to publish both the model and the training data. The importance is being "fully reproducible" in order to make the model trustworthy.

In that vein there's at least one project that's turning out great so far:

https://www.llm360.ai/

[–] [email protected] 13 points 5 months ago (6 children)

Fortunately, LLMs don't really need to be fully open source to get almost all of the benefits of open source. From a safety and security perspective it's fine because the model weights don't really do anything; all of the actual work is done by the framework code that's running them, and if you can trust that due to it being open source you're 99% of the way there. The LLM model just sits there transforming the input text into the output text.

From a customization standpoint it's a little worse, but we're coming up with a lot of neat tricks for retraining and fine-tuning model weights in powerful ways. The most recent bit development I've heard of is abliteration, a technique that lets you isolate a particular "feature" of an LLM and either enhance it or remove it. The first big use of it is to modify various "censored" LLMs to remove their ability to refuse to comply with instructions, so that all those "safe" and "responsible" AIs like Goody-2 can turned into something that's actually useful. A more fun example is MopeyMule, a LLaMA3 model that has had all of his hope and joy abliterated.

So I'm willing to accept open-weight models as being "nearly as good" as a full-blown open source model. I'd like to see full-blown open source models develop more, sure, but I'm not terribly concerned about having to rely on an open-weight model to make an AI system work for the immediate term.

[–] [email protected] 8 points 5 months ago (1 children)

I suppose the importance of the openness of the training data depends on your view of what a model is doing.

If you feel like a model is more like a media file that the model loaders are playing back, where the prompt is more of a type of control over how you access this model then yes I suppose from a trustworthiness aspect there's not much to the model's training corpus being open

I see models more in terms of how any other text encoder or serializer would work, if you were, say, manually encoding text. While there is a very low chance of any "malicious code" being executed, the importance is in the fact that you can check the expectations about how your inputs are being encoded against what the provider is telling you.

As an example attack vector, much like with something like a malicious replacement technique for anything, if I were to download a pre-trained model from what I thought was a reputable source, but was man-in-the middled and provided with a maliciously trained model, suddenly the system I was relying on that uses that model is compromised in terms of the expected text output. Obviously that exact problem could be fixed with some has checking but I hope you see that in some cases even that wouldn't be enough. (Such as malicious "official" providence)

As these models become more prevalent, being able to guarantee integrity will become more and more of an issue.

[–] [email protected] 1 points 5 months ago

Even if you trained the AI yourself from scratch you still can't be confident you know what the AI is going to say under any given circumstance. LLMs have an inherent unpredictability to them. That's part of their purpose, they're not databases or search engines.

if I were to download a pre-trained model from what I thought was a reputable source, but was man-in-the middled and provided with a maliciously trained model

This is a risk for anything you download off the Internet, even source code could be MITMed to give you something with malicious stuff embedded in it. And no, I don't believe you'd read and comprehend every line of it before you compile and run it. You need to verify checksums

As I said above, the real security comes from the code that's running the LLM model. If someone wanted to "listen in" on what you say to the AI, they'd need to compromise that code to have it send your inputs to them. The model itself can't do that. If someone wanted to have the model delete data or mess with your machine, it would be the execution framework of the model that's doing that, not the model itself. And so forth.

You can probably come up with edge cases that are more difficult to secure, such as a troubleshooting AI whose literal purpose is messing with your system's settings and whatnot, but that's why I said "99% of the way there" in my original comment. There's always edge cases.

load more comments (4 replies)
load more comments (11 replies)