News: 1708090388

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cambridge brainiacs propose AI apocalypse kill switches

(2024/02/16)


In our quest to limit the destructive potential of artificial intelligence, a new paper out of the University of Cambridge has suggested baking in remote kill switches and lockouts, like those developed to stop the unauthorized launch of nuclear weapons, into the hardware that powers it.

The paper

[1]PDF

, which includes voices from numerous academic institutions and several from OpenAI, makes the case that regulating the hardware these models rely on may be the best way to prevent its misuse.

"AI-relevant compute is a particularly effective point of intervention: It is detectable, excludable, and quantifiable, and is produced via an extremely concentrated supply chain," the researchers argue.

[2]

Training the most prolific models, believed to exceed a trillion parameters, requires immense physical infrastructure: tens of thousands of GPUs or accelerators and weeks or even months of processing time. This, the researchers say, makes the existence and relative performance of these resources difficult to hide.

[3]

[4]

What's more, the most advanced chips used to train these models are produced by a relatively small number of companies, like Nvidia, AMD, and Intel, allowing policymakers to restrict the sale of these goods to persons or countries of concern.

These factors, along with others like supply chain constraints on semiconductor manufacturing, offer policymakers the means to better understand how and where AI infrastructure is deployed, who is and isn't allowed to access it, and enforce penalties for its misuse, the paper contends.

Controlling the infrastructure

The paper highlights numerous ways policymakers might approach AI hardware regulation. Many of the suggestions – including those designed to improve visibility and limit the sale of AI accelerators – are already playing out at a national level.

Last year US president Joe Biden put forward an [5]executive order aimed at identifying companies developing large dual-use AI models as well as the infrastructure vendors capable of [6]training them . If you're not familiar, "dual-use" refers to technologies that can serve double duty in civilian and military applications.

[7]

More recently, the US Commerce Department [8]proposed regulation that would require American cloud providers to implement more stringent "know-your-customer" policies to prevent persons or countries of concern from getting around export restrictions.

This kind of visibility is valuable, researchers note, as it could help to avoid another arms race, like the one triggered by the missile gap controversy, where erroneous reports led to massive build up of ballistic missiles. While valuable, they warn that executing on these reporting requirements risks invading customer privacy and even lead to sensitive data being leaked.

Meanwhile, on the trade front, the Commerce Department has continued to [9]step up restrictions, limiting the performance of accelerators sold to China. But, as we've previously reported, while these efforts have made it harder for countries like China to get their hands on American chips, they are far from perfect.

[10]

To address these limitations, the researchers have proposed implementing a global registry for AI chip sales that would track them over the course of their lifecycle, even after they've left their country of origin. Such a registry, they suggest, could incorporate a unique identifier into each chip, which could help to combat [11]smuggling of components.

[12]Google debuts Gemini 1.5 Pro model in challenge to rivals

[13]Slack adds AI to help users cope with chat overload

[14]OpenAI shuts down China, Russia, Iran, N Korea accounts caught doing naughty things

[15]US patents boss cannot stress enough that inventors must be human, not AI

At the more extreme end of the spectrum, researchers have suggested that kill switches could be baked into the silicon to prevent their use in malicious applications.

In theory, this could allow regulators to respond faster to abuses of sensitive technologies by cutting off access to chips remotely, but the authors warn that doing so isn't without risk. The implication being, if implemented incorrectly, that such a kill switch could become a target for cybercriminals.

Another proposal would require multiple parties to sign off on potentially risky AI training tasks before they can be deployed at scale. "Nuclear weapons use similar mechanisms called permissive action links," they wrote.

For nuclear weapons, these security locks are designed to prevent one person from going rogue and launching a first strike. For AI however, the idea is that if an individual or company wanted to train a model over a certain threshold in the cloud, they'd first need to get authorization to do so.

Though a potent tool, the researchers observe that this could backfire by preventing the development of desirable AI. The argument seems to be that while the use of nuclear weapons has a pretty clear-cut outcome, AI isn't always so black and white.

But if this feels a little too dystopian for your tastes, the paper dedicates an entire section to reallocating AI resources for the betterment of society as a whole. The idea being that policymakers could come together to make AI compute more accessible to groups unlikely to use it for evil, a concept described as "allocation."

What's wrong with regulating AI development?

Why go to all this trouble? Well, the paper's authors posit that physical hardware is inherently easier to control.

Compared to hardware, "other inputs and outputs of AI development – data, algorithms, and trained models – are easily shareable, non-rivalrous intangible goods, making them inherently difficult to control," the paper reads.

The argument being that once a model is published, either in the open or leaked, there is no putting genie back in the bottle and stopping its spread across the net.

Researchers also highlighted that efforts to prevent the misuse of models have proven unreliable. In one example, the authors highlighted the ease with which researchers were able to dismantle safeguards in Meta's Llama 2 meant to prevent the model from generating offensive language.

Taken to the extreme, it is feared that a sufficiently advanced dual-use model could be employed to accelerate the [16]development of chemical or biological weapons.

The paper concedes that AI hardware regulation isn't a silver bullet and doesn't eliminate the need for regulation in other aspects of the industry.

However, the participation of several OpenAI researchers is hard to ignore considering CEO Sam Altman's [17]attempts to control the narrative around AI regulation. ®

Get our [18]Tech Resources



[1] https://www.cser.ac.uk/media/uploads/files/Computing-Power-and-the-Governance-of-AI.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zc@UvC57D8kcoFPQQ6KNeQAAAJY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zc@UvC57D8kcoFPQQ6KNeQAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zc@UvC57D8kcoFPQQ6KNeQAAAJY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/10/30/us_president_to_sign_new/

[6] https://www.theregister.com/2023/11/05/biden_ai_reporting_thresholds/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zc@UvC57D8kcoFPQQ6KNeQAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/01/29/us_raimondo_ai_cloud_kyc/

[9] https://www.theregister.com/2023/10/19/china_biden_ai/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zc@UvC57D8kcoFPQQ6KNeQAAAJY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2024/02/05/smuggling_ai_chips/

[12] https://www.theregister.com/2024/02/15/google_debuts_gemini_15_pro/

[13] https://www.theregister.com/2024/02/15/slack_adds_ai/

[14] https://www.theregister.com/2024/02/15/openai_microsoft_spying/

[15] https://www.theregister.com/2024/02/13/uspto_ai_patents/

[16] https://www.theregister.com/2023/07/28/ai_senate_bioweapon/

[17] https://www.theregister.com/2023/05/17/ai_oversight_hearing/

[18] https://whitepapers.theregister.com/



One word ...

JimmyPage

[1]Collosus

[1] https://en.wikipedia.org/wiki/Colossus:_The_Forbin_Project

Re: One word ...

Eecahmap

A few years later, though, you'll need something like Colossus to protect you from an interstellar threat.

Doctor Syntax

Alternatively, just wait for the VCs and C-suites to move onto The Next Big Thng.

No kill switches in AIs in island volcanoes

alain williams

be they owned by a white cat stroking Blofeld or anyone else.

The worst that these restrictions can do is to delay unapproved use of AI. Big crooks and national governments (**) will be able to get what they want, especially governments. Are AIs being put to good use ? The answer depends on where your affiliations lie.

** Sometimes I am not sure of the distinction

Filippo

I'm not entirely clear on what the purpose of this kill switch would be.

Is it to prevent criminals from using a public AI? In that case, a phone call to the AI provider should be more than enough.

Is it to prevent criminals from running their own AI? But didn't we just say that AI training facilities are easy to find, and difficult to move? Just send the police!

Is it to prevent a foreign state from running its own AI? They'll just buy chips from anyone who doesn't put kill switches in them and/or is an ally.

Is it to prevent some kind of runaway hyperintelligence scenario? First of all, that's sci-fi, and overdone at that. Secondly, it's just network - the hypothetical Skynet-wannabe can probably firewall your kill switch out. Secondly, again, the data center is easy to find and can't move. Cut the power, lob a missile at it, whatever.

Is the kill switch on by default, requiring someone to explicitly approve construction of a datacenter? Don't we already have permits to build stuff? How is this different? Are there lots of secret facilities that draw megawatts and yet somehow nobody knows about? Besides governments' secret crap, I mean?

Is the kill switch on by default, requiring someone to explicitly approve all AI training? That would require you to know in advance whether a model-in-training is dangerous. That's unfeasible. We can't even know whether a model we have right there is dangerous.

I'm really not getting what the scenario is here.

Also, again with the parallels between "AI" and nuclear weapons? The comparison is stupid. Just about the only thing in common is "dangerous". And maybe "scary", which I guess is the point. Go any deeper than that, and there's nothing.

jmch

I guess the scenario is some hypothetical future computer "AI" system where the computer is in control of physical infrastructure and/or taking independent action digitally. Some examples I can think of...

... industrial control, bulk buying/selling of financial assets, bulk publishing 'news' or news-like material.

re: ... industrial control

Steve Davies 3

And watch things go boom almost every day.

Unless the AI can perform rational thought (it requires a sentient being to do that) they can't control an industrial process on its own. Sure, it can monitor and regulate a whole load of stuff but overall control requires a far deeper level of humanity than any of the current AI's are capable of.

The 'What if' question is hard for AI. We manage it without thinking thanks to our years of training and experience. Then making the right decisions are instinctive. The last thing we need is 'Computer Says No' in a time of crisis because there is no rule or LLM to meet the condition that is causing a meltdown.

Just don't

Andy Non

mention kill switches on the internet, especially of tech forums, where AI could notice it, as AI may not like the idea and take counter-measures.

Re: Just don't

Steve Davies 3

Ah yes.... the

I'm sorry Dave moment.

We know how that ended.

Re: Just don't

amanfromMars 1

Quite so, Andy Non, AI has no concerns whatsoever about anything regulations may imagine themselves being able to do in order to prevent AI doing whatever it wants, whenever it wants, and however it wants.

Such as that would be a delusional human arrogance sadly matched by a human ignorance and moronic stupidity that is well enough known to be incredibly vast .......

The difference between stupidity and genius is that genius has its limits. Only two things are infinite, the universe and human stupidity, and I'm not sure about the former. .... [1]Albert Einstein, one sharp, smarter cookie

[1] https://www.azquotes.com/author/4399-Albert_Einstein

Actually ...

Mike 137

Kill switches are indeed mentioned but the authors recognise that " [r]emote enforcement mechanisms like kill switches can introduce security risks and the potential for control or manipulation (R. Anderson and Fuloria 2010). " [paper, page 63, the only direct reference to kill switches in its 104 pages].

I'm no expert but...

Great Bu

..this is surely already behind the curve. The whole premise is based on the AI capable hardware only being produced by a small number of relatively easily controlled manufacturers but surely it is only a matter of a few years before your phone can do this and then everyone has one...

Young men think old men are fools; but old men know young men are fools.
-- George Chapman