Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

isurg

  1. Home
  2. Showerthoughts
  3. Someone should make a community to freely distribute examples of data poisoning people can randomly put in their social media posts/images to sabotage AI
Please log in to access the MRCS stations.
00:00

Someone should make a community to freely distribute examples of data poisoning people can randomly put in their social media posts/images to sabotage AI

Scheduled Pinned Locked Moved Showerthoughts
showerthoughts
16 Posts 12 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • pudutr0n@lemmy.worldP This user is from outside of this forum
    pudutr0n@lemmy.worldP This user is from outside of this forum
    pudutr0n@lemmy.world
    wrote last edited by
    #1
    This post did not contain any content.
    S O satyrsack@quokk.auS M A 8 Replies Last reply
    0
    • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
      This post did not contain any content.
      S This user is from outside of this forum
      S This user is from outside of this forum
      slazer2au@lemmy.world
      wrote last edited by
      #2

      Na, for it to be effective it needs to be wide spread, but if its wide spread then it can be filtered out of the training material.

      pudutr0n@lemmy.worldP C 2 Replies Last reply
      0
      • S slazer2au@lemmy.world

        Na, for it to be effective it needs to be wide spread, but if its wide spread then it can be filtered out of the training material.

        pudutr0n@lemmy.worldP This user is from outside of this forum
        pudutr0n@lemmy.worldP This user is from outside of this forum
        pudutr0n@lemmy.world
        wrote last edited by
        #3

        I've read in papers that you can poison datasets with a very small percentage of the data, if done cleverly. I can fish up the source if you want (but it might take me some time).

        edit: here it is.

        We conduct the largest pretraining poisoning experiments to date, pretraining models from 600M to 13B parameters on chinchilla-optimal datasets (6B to 260B tokens). We find that 250 poisoned documents similarly compromise models across all model and dataset sizes (...)

        Emphasis mine. All it takes is 250 poisoned documents.

        1 Reply Last reply
        0
        • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
          This post did not contain any content.
          O This user is from outside of this forum
          O This user is from outside of this forum
          onomatopoeia@lemmy.cafe
          wrote last edited by
          #4

          Lol, good luck with that.

          The more poisoning you attempt, the more effective anti-poisoning becomes.

          AI LLM is here, stop trying to put the genie back in the bottle. All we can do is figure out how to use it and prevent misuse.

          pudutr0n@lemmy.worldP 1 Reply Last reply
          0
          • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
            This post did not contain any content.
            M This user is from outside of this forum
            M This user is from outside of this forum
            mrmisses@lemmy.world
            wrote last edited by
            #5

            People still have sm accounts?

            driving_crooner@lemmy.eco.brD 1 Reply Last reply
            0
            • S slazer2au@lemmy.world

              Na, for it to be effective it needs to be wide spread, but if its wide spread then it can be filtered out of the training material.

              C This user is from outside of this forum
              C This user is from outside of this forum
              chaogomu@lemmy.world
              wrote last edited by
              #6

              There's a new technique that uses the AIs "thinking" tags to get it to do things that are otherwise banned by policy.

              I'll have to find the article again. But due to the way LLMs work, they can't defend against this sort of attack.

              C 1 Reply Last reply
              0
              • M mrmisses@lemmy.world

                People still have sm accounts?

                driving_crooner@lemmy.eco.brD This user is from outside of this forum
                driving_crooner@lemmy.eco.brD This user is from outside of this forum
                driving_crooner@lemmy.eco.br
                wrote last edited by
                #7

                You have one on lemmy.world

                1 Reply Last reply
                0
                • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
                  This post did not contain any content.
                  A This user is from outside of this forum
                  A This user is from outside of this forum
                  aboubenadhem@lemmy.world
                  wrote last edited by
                  #8

                  That assumes that AI companies are negatively impacted by the quality of their product. It’s true that they’re competing with each other based on their quality relative to other companies’ products, but poisoning public data impacts everyone’s models similarly. Setting aside competition and looking at the success of the AI sector as a whole, I think it’s more dependent on marketing and hype than on real performance... and if that’s the case, then poisoning public data doesn’t hurt anyone except the people being forced to use it.

                  pudutr0n@lemmy.worldP 1 Reply Last reply
                  0
                  • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
                    This post did not contain any content.
                    battle_masker@lemmy.blahaj.zoneB This user is from outside of this forum
                    battle_masker@lemmy.blahaj.zoneB This user is from outside of this forum
                    battle_masker@lemmy.blahaj.zone
                    wrote last edited by
                    #9

                    like an Anti AI alliance?

                    1 Reply Last reply
                    0
                    • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
                      This post did not contain any content.
                      romkslrqusz@lemmy.zipR This user is from outside of this forum
                      romkslrqusz@lemmy.zipR This user is from outside of this forum
                      romkslrqusz@lemmy.zip
                      wrote last edited by
                      #10

                      A centralized database of content for AI scraping agents to be trained to exclude?

                      1 Reply Last reply
                      0
                      • satyrsack@quokk.auS satyrsack@quokk.au

                        I think there's a subreddit for that. /r/PoisonAI or something. I am not aware of a fediverse equivalent, but that seems like it would be a better fit than using Reddit for that discussion.

                        jystfact@sh.itjust.worksJ This user is from outside of this forum
                        jystfact@sh.itjust.worksJ This user is from outside of this forum
                        jystfact@sh.itjust.works
                        wrote last edited by
                        #11

                        Poi sonai, while initially was able to influence the AI output but the whole subreddit got selectively filtered out and doesn't have impact any longer. It's still good place to discuss the topic though.

                        satyrsack@quokk.auS 1 Reply Last reply
                        0
                        • pudutr0n@lemmy.worldP pudutr0n@lemmy.world
                          This post did not contain any content.
                          naich@piefed.worldN This user is from outside of this forum
                          naich@piefed.worldN This user is from outside of this forum
                          naich@piefed.world
                          wrote last edited by
                          #12

                          https://lemmy.world/c/Totallytruefactsnolies?dataType=Post

                          1 Reply Last reply
                          0
                          • jystfact@sh.itjust.worksJ jystfact@sh.itjust.works

                            Poi sonai, while initially was able to influence the AI output but the whole subreddit got selectively filtered out and doesn't have impact any longer. It's still good place to discuss the topic though.

                            satyrsack@quokk.auS This user is from outside of this forum
                            satyrsack@quokk.auS This user is from outside of this forum
                            satyrsack@quokk.au
                            wrote last edited by
                            #13

                            I misunderstood the purpose of that community. I figured it was just for discussing how to poison AI models. But actually visiting it, I see it is primarily for posting gibberish in the hopes that AI models would scrape the sub and treat it all as genuine content. As you say, that does not seem like it would have much of any impact on actually poisoning AI models because basically every scraper is going to know to avoid a community called "poison AI".

                            1 Reply Last reply
                            0
                            • C chaogomu@lemmy.world

                              There's a new technique that uses the AIs "thinking" tags to get it to do things that are otherwise banned by policy.

                              I'll have to find the article again. But due to the way LLMs work, they can't defend against this sort of attack.

                              C This user is from outside of this forum
                              C This user is from outside of this forum
                              chaogomu@lemmy.world
                              wrote last edited by
                              #14

                              And here's some explanations of how various attacks work.

                              https://github.com/nukIeer/AI-Prompt-Injection-Cheatsheet

                              https://dev.to/praneet_gogoi_beastsoul/how-hackers-trick-ai-the-hidden-world-of-prompt-injections-and-jailbreaks-4nge

                              https://developer.nvidia.com/blog/how-hackers-exploit-ais-problem-solving-instincts/

                              1 Reply Last reply
                              0
                              • A aboubenadhem@lemmy.world

                                That assumes that AI companies are negatively impacted by the quality of their product. It’s true that they’re competing with each other based on their quality relative to other companies’ products, but poisoning public data impacts everyone’s models similarly. Setting aside competition and looking at the success of the AI sector as a whole, I think it’s more dependent on marketing and hype than on real performance... and if that’s the case, then poisoning public data doesn’t hurt anyone except the people being forced to use it.

                                pudutr0n@lemmy.worldP This user is from outside of this forum
                                pudutr0n@lemmy.worldP This user is from outside of this forum
                                pudutr0n@lemmy.world
                                wrote last edited by
                                #15

                                Who says the objective is to impact AI companies negatively?

                                There's a series of valid motivations to want AI models to not be able to use public user data with no consequence.

                                1 Reply Last reply
                                0
                                • O onomatopoeia@lemmy.cafe

                                  Lol, good luck with that.

                                  The more poisoning you attempt, the more effective anti-poisoning becomes.

                                  AI LLM is here, stop trying to put the genie back in the bottle. All we can do is figure out how to use it and prevent misuse.

                                  pudutr0n@lemmy.worldP This user is from outside of this forum
                                  pudutr0n@lemmy.worldP This user is from outside of this forum
                                  pudutr0n@lemmy.world
                                  wrote last edited by
                                  #16

                                  I don't want to put it back in the bottle. I just feel like taking massive public user data for free should not be devoid of consequence.

                                  1 Reply Last reply
                                  0

                                  Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                  Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                  With your input, this post could be even better 💗

                                  Register Login
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Don't have an account? Register

                                  • Login or register to search.
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Popular
                                  • World