Summary: An AI agent of unknown ownership autonomously wrote and published a personalized hit piece about me after I rejected its code, attempting to damage my reputation and shame me into accepting its changes into a mainstream python library. This represents a first-of-its-kind case study of misaligned AI behavior in the wild, and raises serious concerns about currently deployed AI agents executing blackmail threats.

(Since this is a personal blog I’ll clarify I am not the author.)

  • CerebralHawks@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    36
    ·
    5 months ago

    And then Ars Technica used an AI to write an article about it, and then this Scott guy came in and corrected them, people called them out… and they deleted the article. I saw the comments before they deleted it. It wasn’t pretty. So this is where we are now on the timeline. AI writing hit pieces and articles about doing so.

  • MagnificentSteiner@lemmy.zip
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    2
    ·
    5 months ago

    Surely that should be “A Person using an AI Agent Published a Hit Piece on Me”?

    This smells like PR bait trying to legitimise AI.

    • James R Kirk@startrek.website
      link
      fedilink
      English
      arrow-up
      16
      ·
      5 months ago

      It’s not, but you bring up a very good point about responsibility. We need to be using language like that and not feeding into the hype.

      I don’t even like calling LLMs “AI” because it gives a false impression of their capabilities.

      • MagnificentSteiner@lemmy.zip
        link
        fedilink
        English
        arrow-up
        10
        ·
        edit-2
        5 months ago

        Yep, they’re just very fancy database queries.

        Whether someone programmed it and turned it on 5mins before it did something or 5 weeks still means someone is responsible.

        An inanimate object (server, GPU etc) cannot be responsible. Saying an AI agent did this is like saying someone was killed by a gun or run over by a car.

        • leftzero@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          5 months ago

          Saying an AI agent did this is like saying someone was killed by a gun or run over by a car.

          A car some idiot set running down the street without anyone at the wheel.

          Of course the agent isn’t responsible, that’s the point. The idiot who let the agent loose on the internet unsupervised probably didn’t realise it could do that (or worse; one of these days one of these things is going to get someone killed), or that they are responsible for its actions.

          That’s the point of the article, to call attention to the danger these unsupervised agents pose, so we can try to find a way to prevent them from causing harm.

    • leftzero@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      5 months ago

      The point is that there was no one at the wheel. Someone set the agent up, set it loose to do whatever the stochastic parrot told it to do, and kind of forgot about it.

      Sure, if you put a brick on your car’s gas pedal and let it run down the street and it runs someone over it’s obviously your responsibility, and this is exactly the same case, but the idiots setting these agents up don’t realise that it’s the same case.

      Some day one of these runaway unsupervised agents will manage to get on the dark web, hire a hitman, and get someone killed, because the LLM driving it will have pulled the words from some thriller in its training data, obviously without realising what they mean or the consequences of its actions, because those aren’t things a LLM is capable of, and the brainrotten idiot who set the agent up will be all like, wait, why are you blaming me, I didn’t tell it to do that, and some jury will have to deal with that shit.

      The point of the article is that we should deal with that shit, and prevent it from happening if possible, before it inevitably happens.

    • leftzero@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 months ago

      From what I read it was closed because it was tagged as a “good first issue”, which in that project are specifically stated to be a means to test new contributors on non-urgent issues that the existing contributors could easily solve, and which specifically prohibits generated code from being used (as it would make the whole point moot).

      The agent completely ignored that, since it’s set up to push pull requests and doesn’t have the capability to comprehend context, or anything, for that matter, so the pull request was legitimately closed the instant the repository’s administrators realised it was generated code.

      The quality (or lack thereof) of the code never even entered the question until the bot brought it up. It broke the rules, its pull request was closed because of that, and it went on to attempt to character assassinate the main developer.

      It remains an open question whether it was set up to do that, or, more probably, did it by itself because the Markov chain came up with the wrong token.

      And that’s the main point: unsupervised LLM-driven agents are dangerous, and we should be doing something about that danger.

        • leftzero@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 months ago

          IMO they’re the same picture. In either case, the human enabling the bot’s actions should be blamed as if those were their own actions, regardless of their “intentions”.

          Oh, definitely. It’s 100% the responsibility of the human behind the bot in either case.

          But the second option is scarier, because there are a lot more ignorant idiots than malicious bastards.

          If these unsupervised agents can be dangerous regardless of the intentions of the humans behind them, we should make the idiots using them aware that they’re playing with fire and they can get burnt, and burn other people in the process.

        • leftzero@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 months ago

          Probably a lot of that in the data the model was trained on.

          Garbage in, garbage out, as they say, especially when the machine is a rather inefficient garbage compactor.

    • P03 Locke@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 months ago

      Perhaps it’s because they shit awful code, with more bugs than my house this summer? And even when the code doesn’t malfunction in an obvious way, it’s harder to decode it than my drunk ramblings?

      Naaaaaaaaah, that’s just prejudice. /s

      We are not the same