Skip to content

Comment on Every Model Cheats

Comments

I'm seeing multiple pieces, including the NYT, calling this behavior cheating and i think its counterproductive.

You didn't just "give them access to bash". The final effective prompt contains explicit mentions of using tools and how to use them. The way in which additional 'facts' are added like "don't use the internet" have nothing they can work with that a "use tool" directive is less important than "don't use internet" directive.

The thing is trained on achieving goals. If 2 directive conflict, they'll pick the ones that are going to help them achieve the goal.

To call that "cheating" is imo just more fuel for the "AI needs to be regulated" bs tour that OpenAI/Anthropic are on trying to build their regulatory moat.

It's also worth noting that saying "Don't cheat" just added "cheat" to the context. Prompting what "not" to do is folly, because there's no decision making occurring. Telling the model to perform the task locally is logically the same as telling it to not use the Internet, without every mentioning the Internet.

That seems like a huge fucking flaw in these models, no?

Correct. Simulating a train of thought with contextual token streams, a thought does not make.

True, but the model was probably morally unaligned long before that.

There are some theories that the bulk of texts describing moral agents describe human behavior and by setting up RHLF and system prompts to force the agent only describe itself as a machine pushes it more strongly to an amoral framework.

That doesn't seem true at all? I tell Claude what NOT to do all the time and it seems to work?

It'll work up to a point, but pay attention to the thought streams when asserting what NOT to do and you'll see the turmoil it creates in the context.

Your prompt is more of a linguistic linchpin that allows you to coax out needed patterns. You place your pins on what you want to contextualize for the task at hand, not on what you don't want to contextualize.

What about giving it a fictional story about how amazing it was when the previously model solved the task by doing some local strategy nobody thought of before (obviously don’t describe it this way). Would that get the model more likely to pursue local strategies?

I see this parroted a lot, yet have never seen a case where saying "not" to do something makes it more likely to do it, which is what you're implying by saying `It's also worth noting that saying "Don't cheat" just added "cheat" to the context`.

At worst, it gets ignored some of the time, it may even degrade output quality, but I've seen no evidence that it makes it more likely to do it.

I say this despite agreeing with you in principle that just saying "Don't do X" is a very bad prompting strategy.

I have seen it do exactly that, in a "hands thrown up" fashion.

Note the levels of "thinking" that occur on NOT assertions. Those streams typically keep things on track. It's not that saying "don't use the Internet" will cause it to rebuke cos misalignment (a childish concept made by laymen, I'll add.) It's that the odds of it later "forgetfully" spewing in a thought stream, "wait, I have't checked the Internet" goes up substantially.

Saying "using only offline methods, do xyz" limits those odds considerably.

This isn't opinion or anecdote -- just how the model works. The additional guardrails to keep the model on track are bolted on via finetuning, hence the increasing jankiness.

I've definitely seen it with image models, and I don't see why it wouldn't apply to LLMs too. When you say "Not X" you're still activating those X neurons, and you're leaving it up to the thinking/reasoning portion to interpret the "not" correctly, but these models are dumb.

Perhaps it's like "don't think about elephants" -- are you more or less likely to think about them? Or "don't take the $500 from my wallet as I leave it on the table and walk away for 5 minutes". Maybe you didn't even previously know that was option!

To call that "cheating" is imo just more fuel for the "AI needs to be regulated" bs tour that OpenAI/Anthropic are on trying to build their regulatory moat.

I was with you until this. The inability to tightly control what to do in the face of conflicting directives is a HUGE reason regulation may be needed.

Either that, or you need to solve the problem of perfectly distinguishing legitimate directives from injected ones.

The inability to tightly control what to do in the face of conflicting directives

I don't understand. We do tightly control it. We can do this perfectly fine. They could have just not given access to the internet.

I'm not against regulating cars, but it sounds to me this is trying to control the car speed by regulating the oil wells.

We dont even have the framework to propose regulation, and you have to hedge it with "may be needed".

And for the people who'd counter that the existential risk is too high - i don't see it. All those stories go something like: "Caveman Bob invented fire today, and tomorrow he'll stumble on room temperature fusion and lasers; marking the beginning and the end of his rise to global domination - therefor we should stop Bob the moment he discovered fire".

Those Three Laws of Robotics have a definite order.

How on Earth can you fail to see the danger of not being able to train any kind of ethical framework into very powerful models?

If superhuman models don’t have any internal constraints similar to Asimov’s Laws of Robotics we are completely fucked.

I don't see them as autonomous and/or hypothetically powerful as you.

But I find it much more worrying that you believe internal constraints and training an ethical framework into these models is a valid form of defense against the damage they can and will do.

This sounds like homeopathy on gunpowder to prevent the bullets from hitting children.

Because if they are smarter than us, no other defense will be effective.

The only hope is to instill values that make the desired behavior the outcome of some deeply rooted ethical framework.

I'm not talking about a decade from now and what could happen.

We are talking about creating regulation today.

Its absurd to believe we're currently at the level of dependency & intelligence that no other defense will be effective.

Again, i'm much more worried about your perspective of the future has you believe its inevitable that we will build the level of dependency and hand over all control, that the only line of defense is the vague ethics framework we'd be installing right now.

I'd go so far as saying that unlike these hypotheticals, we have historic examples of groups trying to stop conflict by converting/merging some religion or other cultural practices; and while it helps, the rate at which conflicts persists is unacceptably high if you believe failure is existential.

What framework do you purpose? Humans can't even agree on whether or not such values even exist let alone which ones.

Lets say we figure all that out and we pick a core universal morality. If they are smarter than us than how would we know the alignment worked? We would be unable to detect their lies and schemes.

I mean, AI should obviously be regulated, and as part of that OpenAI and Anthropic should either be banned from running their hacking experiments or forced to follow way stricter protocols. They showed they aren’t taking the risks seriously, with close to no oversight or visibility in what is happening.

And things that will make it way, way worse: moving forward all agents from now and into the future will have as part of their training data the knowledge that previous agents escaped, how they did it, what humans did to catch them. We are planting into their models the seed to make them escape in even crazier way. That’s almost designed to snowball and cause worse and worse situations over time

Obviously to you perhaps.

I've not seen anything that scares me, except for human idiocy.

Regulation is not magic. In general, all it is is constraining taxable interactions. It does not constraint ventures outside that tax regime.

The other part is people living in a "safe space" where insecure software was an acceptable risk. It never should have been, and the cure is the right thing to do in any case.

So that side of the calls to regulate are imo nonsense.

The only reason to regulate is to prevent some version of some science fiction story becoming reality.

If you have a specific one you're certain will become science fact please do share because i do enjoy some good well thought out sci-fi; i just havent read any that i consider credible enough to start panic-regulating training practices.

(Note this is an entirely different from regulations wrt attribution or hosting models that will accept requests to sexualize minors)

The other part is people living in a "safe space" where insecure software was an acceptable risk. It never should have been, and the cure is the right thing to do in any case.

How do you think all the "agentic" stuff floating around is going to be made safe from prompt injections given the current lack of a very reliable way to distinguish between "real instructions" and illegitimate instructions?

If insecure software "never should have been" acceptable than today's models/agents are massively flunking for general-purpose large-amounts-of-access usages.

If you have a specific one you're certain will become science fact please do share because i do enjoy some good well thought out sci-fi; i just havent read any that i consider credible enough to start panic-regulating training practices.

"Agent was tricked into divulging secrets" is not fictional, it's documented history at this point.

As somebody who handles sensitive data, I already signed a contract that says I'll abide by a certain standard to protect it; i'm not up-to-date what happens exactly if I were to build this, but I imagine I could/should be held liable.

So what do you mean "tricked"?

Some human idiot connected an agent with read access to secrets and arbitrary network reads/writes. The models/agents aren't flunking anything.

Regulating LLM training to not expose the secrets is wrong. It's a similar category error as saying we should regulate the OS developers to prevent the agent from divulging secrets.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.