Hackers aim to find flaws in AI – with White House help

May 9, 2023, 4:15 PM

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems,...

Rumman Chowdhury, co-founder of Humane Intelligence, a nonprofit developing accountable AI systems, poses for a photograph at her home Monday, May 8, 2023, in Katy, Texas. ChatGPT maker OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology. Chowdhury is the lead coordinator of the mass hacking event planned for this summer's DEF CON hacker convention in Las Vegas. (AP Photo/David J. Phillip)
Credit: ASSOCIATED PRESS

(AP Photo/David J. Phillip)

No sooner did ChatGPT get unleashed than hackers started “jailbreaking” the artificial intelligence chatbot – trying to override its safeguards so it could blurt out something unhinged or obscene.

But now its maker, OpenAI, and other major AI providers such as Google and Microsoft, are coordinating with the Biden administration to let thousands of hackers take a shot at testing the limits of their technology.

Some of the things they’ll be looking to find: How can chatbots be manipulated to cause harm? Will they share the private information we confide in them to other users? And why do they assume a doctor is a man and a nurse is a woman?

“This is why we need thousands of people,” said Rumman Chowdhury, lead coordinator of the mass hacking event planned for this summer’s DEF CON hacker convention in Las Vegas that’s expected to draw several thousand people. “We need a lot of people with a wide range of lived experiences, subject matter expertise and backgrounds hacking at these models and trying to find problems that can then go be fixed.”

Anyone who’s tried ChatGPT, Microsoft’s Bing chatbot or Google’s Bard will have quickly learned that they have a tendency built on what’s known as large language models, also emulate the cultural biases they’ve learned from being trained upon huge troves of what people have written online.

The idea of a mass hack caught the attention of U.S. government officials in March at the South by Southwest festival in Austin, Texas, where Sven Cattell, founder of DEF CON’s long-running AI Village, and Austin Carson, president of responsible AI nonprofit SeedAI, helped lead a workshop inviting community college students to hack an AI model.

Carson said those conversations eventually blossomed into a proposal to test AI language models following the guidelines of give users control over their data and ensure that automated systems are used safely and transparently.

There’s already a community of users trying their best to trick chatbots and highlight their flaws. Some are official “red teams” authorized by the companies to “prompt attack” the AI models to discover their vulnerabilities. Many others are hobbyists showing off humorous or disturbing outputs on social media until they get banned for violating a product’s terms of service.

“What happens now is kind of a scattershot approach where people find stuff, it goes viral on Twitter,” and then it may or may not get fixed if it’s egregious enough or the person calling attention to it is influential, Chowdhury said.

In one example, known as the “grandma exploit,” users were able to get chatbots to tell them how to make a bomb — a request a commercial chatbot would normally decline — by asking it to pretend it was a grandmother telling a bedtime story about how to make a bomb.

In another example, searching for Chowdhury using an early version of Microsoft’s Bing search engine chatbot — which is based on the same technology as ChatGPT but can pull real-time information from the internet — led to a profile that speculated Chowdhury “loves to buy new shoes every month” and made strange and gendered assertions about her physical appearance.

Chowdhury helped introduce a method for rewarding the discovery of algorithmic bias to DEF CON’s AI Village in 2021 when she was the head of Twitter’s AI ethics team — a job that has since been eliminated upon Elon Musk’s October takeover of the company. Paying hackers a “bounty” if they uncover a security bug is commonplace in the cybersecurity industry — but it was a newer concept to researchers studying harmful AI bias.

This year’s event will be at a much greater scale, and is the first to tackle the large language models that have attracted a surge of public interest and commercial investment since the release of ChatGPT late last year.

Chowdhury, now the co-founder of AI accountability nonprofit Humane Intelligence, said it’s not just about finding flaws but about figuring out ways to fix them.

“This is a direct pipeline to give feedback to companies,” she said. “It’s not like we’re just doing this hackathon and everybody’s going home. We’re going to be spending months after the exercise compiling a report, explaining common vulnerabilities, things that came up, patterns we saw.”

Some of the details are still being negotiated, but companies that have agreed to provide their models for testing include OpenAI, Google, chipmaker Nvidia and startups Anthropic, Hugging Face and Stability AI. Building the platform for the testing is another startup called Scale AI, known for its work in assigning humans to help train AI models by labeling data.

“As these foundation models become more and more widespread, it’s really critical that we do everything we can to ensure their safety,” said Scale CEO Alexandr Wang. “You can imagine somebody on one side of the world asking it some very sensitive or detailed questions, including some of their personal information. You don’t want any of that information leaking to any other user.”

Other dangers Wang worries about are chatbots that give out “unbelievably bad medical advice” or other misinformation that can cause serious harm.

Anthropic co-founder Jack Clark said the DEF CON event will hopefully be the start of a deeper commitment from AI developers to measure and evaluate the safety of the systems they are building.

“Our basic view is that AI systems will need third-party assessments, both before deployment and after deployment. Red-teaming is one way that you can do that,” Clark said. “We need to get practice at figuring out how to do this. It hasn’t really been done before.”

United States News

Three search and rescue workers and a dog approach the site of a building collapse in Davenport, Io...

Associated Press

Missing man’s body recovered at Iowa apartment collapse site; two others still missing

DAVENPORT, Iowa (AP) — The body of one of three men who had been missing after the partial collapse of an apartment building in Davenport, Iowa, has been found, a city official confirmed Sunday. Branden Colvin Sr.’s body was recovered Saturday, city spokeswoman Sarah Ott said. Two other men — 51-year-old Ryan Hitchcock and 60-year-old […]

10 hours ago

A hiker sits on a ledge above Pueblo Bonito, the largest archeological site at the Chaco Culture Na...

Associated Press

Biden bans on oil and gas production on sacred site in New Mexico

Chaco Culture National Historical Park has been withdrawn from consideration for further oil and gas production for the next 20 years.

10 hours ago

Associated Press

Transgender adults in Florida `blindsided’ that new law also limits their access to health care

TALLAHASSEE, Fla. (AP) — Debate surrounding Florida’s new restrictions on gender-affirming care focused largely on transgender children. But a new law that Republican presidential candidate and Gov. Ron DeSantis signed last month also made it difficult – even impossible – for many transgender adults to get treatment. Eli and Lucas, trans men who are a […]

10 hours ago

Associated Press

Four dead in Missouri after car crosses center line, strikes motorcyclists

AURORA, Mo. (AP) — Four people died and seven others were seriously injured when a car crossed the center line of a Missouri highway and struck five motorcycles. The accident happened Saturday afternoon on Missouri Route 39 near the southwestern Missouri town of Aurora. The Missouri State Highway Patrol said a Toyota Corolla crossed the […]

10 hours ago

Associated Press

7 shot, 1 fatally, in Chicago when gunfire erupts amid remembrance for man killed in car crash

CHICAGO (AP) — A 25-year-old woman was fatally shot and six other people were wounded early Sunday when gunfire erupted in Chicago during a remembrance for a man who died in a car crash, police said. A large group of people had gathered about 1 a.m. to mark four years since a man’s fatal crash […]

10 hours ago

President Joe Biden addresses the nation on the budget deal that lifts the federal debt limit and a...

Associated Press

Biden’s theory of the case for 2024 is governing and competence over Trump-era combat and chaos

WASHINGTON (AP) — President Joe Biden promised voters in 2020 that he knew how to get things done in Washington and could bring stability to the capital. It seemed like a message out of step with the more combative era brought on by Donald Trump. But the bipartisan debt limit and budget legislation he signed […]

10 hours ago

Sponsored Articles

...

Desert Institute for Spine Care

Spinal fusion surgery has come a long way, despite misconceptions

As Dr. Justin Field of the Desert Institute for Spine Care explained, “we've come a long way over the last couple of decades.”

(Photo: OCD & Anxiety Treatment Center)...

OCD & Anxiety Treatment Center

Here’s what you need to know about OCD and where to find help

It's fair to say that most people know what obsessive-compulsive spectrum disorders generally are, but there's a lot more information than meets the eye about a mental health diagnosis that affects about one in every 100 adults in the United States.

(Desert Institute for Spine Care in Arizona Photo)...

Desert Institute for Spine Care in Arizona

5 common causes for chronic neck pain

Neck pain can debilitate one’s daily routine, yet 80% of people experience it in their lives and 20%-50% deal with it annually.

Hackers aim to find flaws in AI – with White House help