正在加载视频...

视频加载失败

"Open weights are inherently secure" Sriram Krishnan

230,903 次观看 • 1 个月前 •via X (Twitter)

35 条评论

macintog 的头像
macintog1 个月前

@sriramk we don't even know how LLMs work, so such claims are really not helping to clarify the situation.

Mike 的头像
Mike1 个月前

@sriramk This is a software mentality being applied to ai models which is wrong. No one knows how the models work. So it's impossible to say they're 100% secure.

Evan Kirstel #B2B #TechFluencer 的头像
Evan Kirstel #B2B #TechFluencer1 个月前

@sriramk

Mike Bradley 的头像
Mike Bradley1 个月前

@sriramk Being able to control the entire hosted AI stack tip to tail is certainly more secure than a random third party API that’s for sure. Open weights and Huggingface make that possible 💪❤️

Dirty Indy 🟥🟧🟨 的头像
Dirty Indy 🟥🟧🟨1 个月前

@sriramk When did he become a cyber expert?

joy larkin 的头像
joy larkin1 个月前

@sriramk From which country though and with which guardrails?

Leo McKee-Reid 的头像
Leo McKee-Reid1 个月前

obviously doesn't know better, but @ClementDelangue you must know how dumb this take is. what are we doing here. - open-weight ≠ open-source - and even if it did, transparency ≠ security - interp is nowhere near letting "you have the entire world being able to take it apart" mean anything - there's no patch mechanism in OS, so every flaw ships forever on a million hard drives unless users follow-up - fine-tuning access allows people to strip safety training for a couple hundred $ - open models don't have post-release visibility, while at least closed models can monitor and revoke access - ...list goes on

Morgan 的头像
Morgan1 个月前

@sriramk Love the Picard headshot in the background 🖖

Hitarth Kanakia 的头像
Hitarth Kanakia1 个月前

@sriramk The guy doesn't understand security. He just says what you can do with open weight models and claims that those are reasons that make open weight models secure. "You can just bullshit about things..."

Jango fett 的头像
Jango fett1 个月前

@sriramk This guy like any other product manager has no idea what he’s talking about. They all just speak nonsense

Sarath 的头像
Sarath1 个月前

@sriramk understated aspect of open weight models. we dont have to treat them as black boxes. Ability to access model weights lets one understand and steer them. Still an unsolved problem but making them closed certainly wouldn't help solve it. Case in point: 😅

Michel Tricot 的头像
Michel Tricot1 个月前

@sriramk There's nothing more secure than building in the open. Open weights let developers train models in their own environment... doesn't get safer than that!

KP bhoomika 的头像
KP bhoomika1 个月前

@sriramk Open weights are inherently secure!

Carlo Clores 的头像
Carlo Clores1 个月前

@sriramk I'm all for open weights and open source. But I think the argument is that now "bad guys" have access to powerful models. With closed, you can control who can access it. It's like a handing an assault rifle or rpg to a kid. now you have no control over bad actors.

Nikunj Bansal e/acc 🇺🇸 的头像
Nikunj Bansal e/acc 🇺🇸1 个月前

@sriramk 💯

Akshay 的头像
Akshay1 个月前

@sriramk exactly why Linux is so secure and 90% of our public cloud infrastructure runs on it. Dario is lying.

josh 的头像
josh1 个月前

@nizzyabi @sriramk While I appreciate the sentiment, I do think that shows a lack of imagination to potential vectors

Avaaus 的头像
Avaaus1 个月前

@sriramk Massive respect for Sriram but i cant unsee it.

Abdo Dameen MSc 的头像
Abdo Dameen MSc1 个月前

@sriramk So is owning a laptop. Laptops are inherently good for watching movies and browsing YouTube. But if you sold it to a hacker they can abuse it and use it to hack other people. Do you see how stupid this logic is?

1011001 的头像
10110011 个月前

@sriramk Need to buy some homelab tech

Antoine Martel 🔨 的头像
Antoine Martel 🔨1 个月前

@sriramk are you people serious? i thought this was ironic... "if you build a rocket in public, everyone can look at it, so it's safe"

Nash 的头像
Nash1 个月前

@sriramk This intuition is wrong. It’s like saying you understand how the chicken lived just from looking at the omelette

donkey_j_kong 的头像
donkey_j_kong1 个月前

@sriramk But we already see evidence of poisoned data attacks on models, closed and open source. We can expect these large scale data based attacks to continue and be more sophisticated. It will only take 1 of a 10 billion tool calls to hit large scaled usages.

Chuff 的头像
Chuff1 个月前

@sriramk Open weight models are easily injected with malicious instructions and you'd never know unless you hit a specific node.

Abdullahi 的头像
Abdullahi1 个月前

@sriramk The angle to security concerns with open weight models is more focused on the average person who just wants "AI“. They don’t have the bird’s-eye view of the core mechanics of how these models work, and it is always the case of take it as it’s given.

randomCrapola 的头像
randomCrapola1 个月前

@sriramk Can't stand this guy.

seminarahost 的头像
seminarahost1 个月前

@sriramk the most secure systems we run are the ones we can inspect and modify ourselves. the trust comes from transparency not promises. open weights is the only model that lets you actually verify the claims

siddhant 的头像
siddhant1 个月前

@sriramk alpha take. opensource is the way to go.

sivat.eth 的头像
sivat.eth1 个月前

@sriramk yes; but

QM 的头像
QM1 个月前

@sriramk of course they are. I just never got the logic of the rumors that they aren't. You have access to the weights and run it yourself. OTOH, you send a bunch of proprietary data to a third party when using a frontier hosted model.

Khurrum 的头像
Khurrum1 个月前

@sriramk Usually you hear people say that there's Chinese propaganda, and then that is just automatically linked to them somehow being less safe. I've seen Chinese models be far less diplomatic about China than ChatGPT. It's usually more that specific topics are off-limits.

𝑫𝒂𝒏𝒊𝒆𝒍 𝑺𝒄𝒐𝒕𝒕 𝑴𝒂𝒕𝒕𝒉𝒆𝒘𝒔 🇦🇺 的头像
𝑫𝒂𝒏𝒊𝒆𝒍 𝑺𝒄𝒐𝒕𝒕 𝑴𝒂𝒕𝒕𝒉𝒆𝒘𝒔 🇦🇺1 个月前

We wouldn't be as aware of how subtle yet powerful engineered biases in AI can be without examining open models. The point being that if open models manifest such phenomena then it is reasonable to suspect that closed systems also have "issues" that may impact on their value in a given role. They are not conscious or sentient in the human sense but we do need to treat them like employees that have been entrusted with a high impact role, and vet them accordingly.

David Hendrickson 的头像
David Hendrickson1 个月前

@sriramk At the very least the open weights can be loaded, monitored and tested for poisoning

shan 的头像
shan1 个月前

@sriramk Open weights do offer an advantage but it's not as transparent as you might think. These weights are large arrays of numbers that are too abstract for our current technology to reeason about. We can only go off of sandboxing it and testing outputs.

Steven Enamakel 🐥 的头像
Steven Enamakel 🐥1 个月前

@sriramk the many-eyes point is exactly what i was thinking about recently, well said @sriramk 👏

相关视频