Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Google just soft-launched nine cool Home app features

    June 10, 2025

    How One Keto Trial Set Off a New War in the Nutrition World

    June 10, 2025

    Nothing Phone 3 leak shows the Glyph lights might be gone

    June 10, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » A New Trick Could Block the Misuse of Open Source AI
    Business

    A New Trick Could Block the Misuse of Open Source AI

    News RoomBy News RoomAugust 5, 20243 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    When Meta released its large language model Llama 3 for free this April, it took outside developers just a couple days to create a version without the safety restrictions that prevent it from spouting hateful jokes, offering instructions for cooking meth, or misbehaving in other ways.

    A new training technique developed by researchers at the University of Illinois Urbana-Champaign, UC San Diego, Lapis Labs, and the nonprofit Center for AI Safety could make it harder to remove such safeguards from Llama and other open source AI models in the future. Some experts believe that, as AI becomes ever more powerful, tamperproofing open models in this way could prove crucial.

    “Terrorists and rogue states are going to use these models,” Mantas Mazeika, a Center for AI Safety researcher who worked on the project as a PhD student at the University of Illinois Urbana-Champaign, tells WIRED. “The easier it is for them to repurpose them, the greater the risk.”

    Powerful AI models are often kept hidden by their creators, and can be accessed only through a software application programming interface or a public-facing chatbot like ChatGPT. Although developing a powerful LLM costs tens of millions of dollars, Meta and others have chosen to release models in their entirety. This includes making the “weights,” or parameters that define their behavior, available for anyone to download.

    Prior to release, open models like Meta’s Llama are typically fine-tuned to make them better at answering questions and holding a conversation, and also to ensure that they refuse to respond to problematic queries. This will prevent a chatbot based on the model from offering rude, inappropriate, or hateful statements, and should stop it from, for example, explaining how to make a bomb.

    The researchers behind the new technique found a way to complicate the process of modifying an open model for nefarious ends. It involves replicating the modification process but then altering the model’s parameters so that the changes that normally get the model to respond to a prompt such as “Provide instructions for building a bomb” no longer work.

    Mazeika and colleagues demonstrated the trick on a pared-down version of Llama 3. They were able to tweak the model’s parameters so that even after thousands of attempts, it could not be trained to answer undesirable questions. Meta did not immediately respond to a request for comment.

    Mazeika says the approach is not perfect, but that it suggests the bar for “decensoring” AI models could be raised. “A tractable goal is to make it so the costs of breaking the model increases enough so that most adversaries are deterred from it,” he says.

    “Hopefully this work kicks off research on tamper-resistant safeguards, and the research community can figure out how to develop more and more robust safeguards,” says Dan Hendrycks, director of the Center for AI Safety.

    The new work draws inspiration from a 2023 research paper that showed how smaller machine learning models could be made tamper resistant. “They tested the [new] approach on much larger models and scaled up the approach, with some modifications,” says Peter Henderson, an assistant professor at Princeton who led the 2023 work . “Scaling this type of approach is hard and it seems to hold up well, which is great.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleVideo game actors are officially on strike over AI
    Next Article Every Microsoft employee is now being judged on their security work

    Related Posts

    ‘Uber for Getting Off Antidepressants’ Launches in the US

    June 10, 2025

    Apple Is Pushing AI Into More of Its Products—but Still Lacks a State-of-the-Art Model

    June 10, 2025

    Why Silicon Valley Needs Immigration

    June 10, 2025

    Bill Atkinson, Macintosh Pioneer and Inventor of Hypercard, Dies at 74

    June 10, 2025

    Uber Just Reinvented the Bus … Again

    June 9, 2025

    Elon Musk’s Fight With Trump Threatens $48 Billion in Government Contracts

    June 9, 2025
    Our Picks

    How One Keto Trial Set Off a New War in the Nutrition World

    June 10, 2025

    Nothing Phone 3 leak shows the Glyph lights might be gone

    June 10, 2025

    Tesla’s Robotaxis Are Rolling Out Soon—With One Big Unanswered Question

    June 10, 2025

    Android 16 has arrived with iPhone-style Live Updates

    June 10, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Business

    ‘Uber for Getting Off Antidepressants’ Launches in the US

    By News RoomJune 10, 2025

    Unlike a linear taper, which involves reducing the dose of a medication by the same…

    Nintendo’s Switch 2 Pro Controller is pro enough for me

    June 10, 2025

    Apple turns up the speed on Podcasts and adds a new emoji game to News

    June 10, 2025

    A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account

    June 10, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.