If they believe open weight models are inherently unsafe but are forced to release weights, then if they really believe their own safety arguments, they would need to stop development.
Ya bro it's totally not possible to defeat a detection system that, in its own marketing on contrived, game-able benchmarks that they created, claims only a 99.6% true negative rate.
As stated, it's work product. Not a toy "adversarial prompt," so I won't be posting it here.
And as stated, even Pangram's own marketing material claims at least a 0.4% false negative rate on their own contrived corpus. A one in 250 event is hardly even rare.
You seem quite defensive about Pangram, and it shows up in a few of your comments. Is there a reason for that? If it's extending to outright denial of Pangram's own stated error rates... sheesh... very weird indeed (unless they're paying you, obviously).
What I said is that every time Pangram has said 100% AI, it is 100% something I don't want to read. I don't particularly care if it was written by humans or LLMs.
Every time I've asked for evidence from someone who claims something like you do there always seems to be a reason it can't be posted. So it makes one suspicious.
Is there no way you can modify your prompt to be shareable?
> I never found a piece of text that pangram claims is 100% AI that to me seems like purely human written text.
That's another claim you made, which is quite silly. You've never found something that Pangram marks as 0% human and which you deem to be 100% human? Huge gulf.
And no, not really. It's copy from fundraising materials. Removing the identifiable portions of it would remove virtually everything, which is perhaps why Pangram didn't flag it?
I said it wasn't something I wanted to read. Humans are capable of writing things I don't want to read. Which at this point is starting to include your comments.
I did and it's true, but I amended my statement at the top of this thread, which you've ignored.
What I wrote is true (it is a claim about my experience), so I'm not sure what you're attacking.
I amended my statement to avoid a discussion about the provenance which is not what I actually care about. What I care about is if I want to read it. Humans could theoretically write something in AI voice and if they did, I wouldn't want to read it.
I have not seen any examples of human text in LLM style that clearly predate 2023. If you can supply one, that would be incredible evidence.
If you're able to supply a prompt which generates text that fools pangram and is not like one sentence long or a list of names or something, but actual prose I want to read, then I will concede.
Oh, well sure, but I don't care about your preferences for what you'd like to read. You can use a Ouija board to decide whether something is worth reading for all I care, just don't use it to accuse other people of plagiarism or dishonesty.
Duh.
If your statement was "my super special dowsing rods tell me what I want to read with 100% accuracy" I'd say "cool." But that wasn't your claim.
> If you're able to supply a prompt which generates text that fools pangram and is not like one sentence long or a list of names or something, but actual prose I want to read, then I will concede.
This is an even more conservative claim than the one you just made! Sheesh.
I don't know if putting a disclaimer at the very end of the blog, that you also disclaim, should be considered "very clear".
"Here is, for those that have read this far, the acknowledgements that used to be in the formal paper but we decided to remove it, mostly because the paper has been reworked and rewritten so many times by us."
> I never found a piece of text that pangram claims is 100% AI that to me seems like purely human written text.
Is that the level of sensitivity we're looking for? More than literally 0%? Do you know how crazy it'd be to achieve that, even if they were trying to?
I have 1000s of reddit and hacker news comments from before 2023, and lots of long form writing too. But as you point out, those are all in the training set, and in pangram's "definitely human" training set too.
The ones that sound like LLMs tend to be the ones that were well researched and spent more time on, not the off the cuff stuff, which is most of what I write. So it would take me a while to find something like that.
But you're welcome to dive into my reddit and HN history, or all my blog posts on the wayback machine if you want to look for one. :)
How would your scheme work? You use RSA to encrypt the entire thing? Or you use it to get a key for a block cipher and then use that?
I feel like either way, you'd need the key to be different for every CD, otherwise you could just share the shared key. But if the encryption of every CD is different, why not just share the block cipher key directly? They can have a list of CDs and the associated key(s).
What additional security or functionality does an RSA like step add here?
No. That cracking group would have known a priori the phone call was a pretense, because id was very unlikely to press distinct CDs. So they could focus on conventional cracking techniques.
Maybe have n versions of the CD (maybe 16, or 32), so there are n decryption keys. When the buyer recites the code over the phone, the program run by the salesperson can identify which key is used based on the number.
The hacker groups would be a little frustrated trying to find all of the different CDs.
The setup costs for a pressed CD are substantial - manufacturing many different designs would have been much more expensive, and would have only slowed down crackers marginally. It's unlikely that this would have recovered enough sales to be worth it.
A reminder that CD-ROMs are pressed from glass masters, not burned like CD-Rs. I wonder if anyone has tried something like this with burned discs, though.
The multisession standard actually afforded the possibility of CD-PROM; a hybrid disc with a pressed read-only session followed by a writable section. It was only used for Kodak Picture CD (not the same as Photo CD) to hold software in the pressed session. It also apparently standardized a magneto-optical hybrid that never made it to market.
Hmm, it could work then if they’ve pressed most of the game data first and then recorded the encrypted part for each disk. But I guess the tooling for such setup would still be too expensive.
With CD-Rs it was already possible in the mid '90s, if we're talking mass production. CD-Rs are a little more expensive to produce, but not much more so. A slight concern is that readers of the time might not have been able to read the discs, because CD-Rs are not quite as reflective as CD-ROMs.
You would need some sort of hardware serial number system for PCs and a whole security infrastructure to verify that the serial number being used for the unlock wasn't faked. Then you could do per-PC unlocks. I'm not aware of anything like that being widespread back in the Quake days, though these days every computing device you own probably has a unique ID burned into ROM somewhere.