STEALING OpenAI models data ๐Ÿฅท

Latent Space ยท Advanced ยท๐Ÿ“ฐ AI News & Updates ยท1y ago
Skills: AI Security90%

Key Takeaways

Nicholas Carlini of DeepMind discusses stealing OpenAI models' training data through prompt attacks, demonstrating the vulnerability of models like GPT 3.5 Turbo to data stealing.

Full Transcript

we do also serve people building on top of models and one thing that I think people are interested in is prompt injections prompt security that kind of stuff I feel like you the relevant version of yours your thing is can I steal the rag Corpus that it might be proprietary to a company there's two kinds of stealing there's model stealing and there's data stealing data stealing is exactly this kind of question in many ways the answer is is yes even without rag you can often steal data that a model was trained on we have shown that for production models okay in this case um in the most extreme variant we showed a way to recover training data from GPT 3.5 turbo he figured out that if you prompt chat GPT to repeat a word forever and it will repeat the word many many many times in a row and then like explode and like just start doing random stuff and it was doing random stuff maybe a small percent of the time maybe two% of the time it would just repeat training data back to you which is very confusing but like you know this is a thing that like happened and was like an exciting kind of thing and like we've we've seen this in the past yeah

Original Description

Nicholas Carlini of DeepMind on how they stole OpenAI training data through prompt attacks!
Sign in to unlock AI tutor explanation ยท โšก30

Playlist

Uploads from Latent Space ยท Latent Space ยท 50 of 60

1 Ep 18: Petaflops to the People โ€” with George Hotz of tinycorp
Ep 18: Petaflops to the People โ€” with George Hotz of tinycorp
Latent Space
2 FlashAttention-2: Making Transformers 800% faster AND exact
FlashAttention-2: Making Transformers 800% faster AND exact
Latent Space
3 RWKV: Reinventing RNNs for the Transformer Era
RWKV: Reinventing RNNs for the Transformer Era
Latent Space
4 Generating your AI Media Empire - with Youssef Rizk of Wondercraft.ai
Generating your AI Media Empire - with Youssef Rizk of Wondercraft.ai
Latent Space
5 RAG is a hack - with Jerry Liu of LlamaIndex
RAG is a hack - with Jerry Liu of LlamaIndex
Latent Space
6 The End of Finetuning โ€” with Jeremy Howard of Fast.ai
The End of Finetuning โ€” with Jeremy Howard of Fast.ai
Latent Space
7 Why AI Agents Don't Work (yet) - with Kanjun Qiu of Imbue
Why AI Agents Don't Work (yet) - with Kanjun Qiu of Imbue
Latent Space
8 Powering your Copilot for Data - with Artem Keydunov from Cube.dev
Powering your Copilot for Data - with Artem Keydunov from Cube.dev
Latent Space
9 Beating GPT-4 with Open Source Models - with Michael Royzen of Phind
Beating GPT-4 with Open Source Models - with Michael Royzen of Phind
Latent Space
10 The State of Silicon and the GPU Poors - with Dylan Patel of SemiAnalysis
The State of Silicon and the GPU Poors - with Dylan Patel of SemiAnalysis
Latent Space
11 The "Normsky" architecture for AI coding agents โ€” with Beyang Liu + Steve Yegge of SourceGraph
The "Normsky" architecture for AI coding agents โ€” with Beyang Liu + Steve Yegge of SourceGraph
Latent Space
12 The AI-First Graphics Editor - with Suhail Doshi of Playground AI
The AI-First Graphics Editor - with Suhail Doshi of Playground AI
Latent Space
13 The Accidental AI Canvas - with Steve Ruiz of tldraw
The Accidental AI Canvas - with Steve Ruiz of tldraw
Latent Space
14 The Origin and Future of RLHF: the secret ingredient for ChatGPT - with Nathan Lambert
The Origin and Future of RLHF: the secret ingredient for ChatGPT - with Nathan Lambert
Latent Space
15 The Four Wars of the AI Stack - Dec 2023 Recap
The Four Wars of the AI Stack - Dec 2023 Recap
Latent Space
16 The State of AI in production โ€” with David Hsu of Retool
The State of AI in production โ€” with David Hsu of Retool
Latent Space
17 Building an open AI company - with Ce and Vipul of Together AI
Building an open AI company - with Ce and Vipul of Together AI
Latent Space
18 Truly Serverless Infra for AI Engineers - with Erik Bernhardsson of Modal
Truly Serverless Infra for AI Engineers - with Erik Bernhardsson of Modal
Latent Space
19 A Brief History of the Open Source AI Hacker - with Ben Firshman of Replicate
A Brief History of the Open Source AI Hacker - with Ben Firshman of Replicate
Latent Space
20 Open Source AI is AI we can Trust โ€” with Soumith Chintala of Meta AI
Open Source AI is AI we can Trust โ€” with Soumith Chintala of Meta AI
Latent Space
21 Making Transformers Sing - with Mikey Shulman of Suno
Making Transformers Sing - with Mikey Shulman of Suno
Latent Space
22 A Comprehensive Overview of Large Language Models - Latent Space Paper Club
A Comprehensive Overview of Large Language Models - Latent Space Paper Club
Latent Space
23 Why Google failed to make GPT-3 -- with David Luan of Adept
Why Google failed to make GPT-3 -- with David Luan of Adept
Latent Space
24 Personal AI Meetup - Bee, BasedHardware, LangChain LangFriend, Deepgram EmilyAI
Personal AI Meetup - Bee, BasedHardware, LangChain LangFriend, Deepgram EmilyAI
Latent Space
25 Supervise the Process of AI Research โ€” with Jungwon Byun and Andreas Stuhlmรผller of Elicit
Supervise the Process of AI Research โ€” with Jungwon Byun and Andreas Stuhlmรผller of Elicit
Latent Space
26 Breaking down the OG GPT Paper by Alec Radford
Breaking down the OG GPT Paper by Alec Radford
Latent Space
27 High Agency Pydantic over VC Backed Frameworks โ€” with Jason Liu of Instructor
High Agency Pydantic over VC Backed Frameworks โ€” with Jason Liu of Instructor
Latent Space
28 This World Does Not Exist โ€” Joscha Bach, Karan Malhotra, Rob Haisfield (WorldSim, WebSim, Liquid AI)
This World Does Not Exist โ€” Joscha Bach, Karan Malhotra, Rob Haisfield (WorldSim, WebSim, Liquid AI)
Latent Space
29 LLM Asia Paper Club Survey Round
LLM Asia Paper Club Survey Round
Latent Space
30 How to train a Million Context LLM โ€” with Mark Huang of Gradient.ai
How to train a Million Context LLM โ€” with Mark Huang of Gradient.ai
Latent Space
31 How AI is Eating Finance - with Mike Conover of Brightwave
How AI is Eating Finance - with Mike Conover of Brightwave
Latent Space
32 How To Hire AI Engineers (ft. James Brady and Adam Wiggins of Elicit)
How To Hire AI Engineers (ft. James Brady and Adam Wiggins of Elicit)
Latent Space
33 State of the Art: Training 70B LLMs on 10,000 H100 clusters
State of the Art: Training 70B LLMs on 10,000 H100 clusters
Latent Space
34 The 10,000x Yolo Researcher Metagame โ€” with Yi Tay of Reka
The 10,000x Yolo Researcher Metagame โ€” with Yi Tay of Reka
Latent Space
35 Training Llama 2, 3 & 4: The Path to Open Source AGI โ€” with Thomas Scialom of Meta AI
Training Llama 2, 3 & 4: The Path to Open Source AGI โ€” with Thomas Scialom of Meta AI
Latent Space
36 [LLM Paper Club] Llama 3.1 Paper: The Llama Family of Models
[LLM Paper Club] Llama 3.1 Paper: The Llama Family of Models
Latent Space
37 Synthetic data + tool use for LLM improvements ๐Ÿฆ™
Synthetic data + tool use for LLM improvements ๐Ÿฆ™
Latent Space
38 RLHF vs SFT to break out of local maxima ๐Ÿ“ˆ
RLHF vs SFT to break out of local maxima ๐Ÿ“ˆ
Latent Space
39 The Winds of AI Winter (Q2 Four Wars of the AI Stack Recap)
The Winds of AI Winter (Q2 Four Wars of the AI Stack Recap)
Latent Space
40 Segment Anything 2: Memory + Vision = Object Permanence โ€” with Nikhila Ravi and Joseph Nelson
Segment Anything 2: Memory + Vision = Object Permanence โ€” with Nikhila Ravi and Joseph Nelson
Latent Space
41 Answer.ai & AI Magic with Jeremy Howard
Answer.ai & AI Magic with Jeremy Howard
Latent Space
42 Is finetuning GPT4o worth it?
Is finetuning GPT4o worth it?
Latent Space
43 Personal benchmarks vs HumanEval - with Nicholas Carlini of DeepMind
Personal benchmarks vs HumanEval - with Nicholas Carlini of DeepMind
Latent Space
44 Building AGI with OpenAI's Structured Outputs API
Building AGI with OpenAI's Structured Outputs API
Latent Space
45 Q* for model distillation ๐Ÿ“
Q* for model distillation ๐Ÿ“
Latent Space
46 Finetuning LoRAs on BILLIONS of tokens ๐Ÿค–
Finetuning LoRAs on BILLIONS of tokens ๐Ÿค–
Latent Space
47 Cursor UX team is CRACKED ๐Ÿ’ป
Cursor UX team is CRACKED ๐Ÿ’ป
Latent Space
48 Choosing the BEST OpenAI model ๐Ÿ†
Choosing the BEST OpenAI model ๐Ÿ†
Latent Space
49 How will OpenAI voice mode change API design?
How will OpenAI voice mode change API design?
Latent Space
โ–ถ STEALING OpenAI models data ๐Ÿฅท
STEALING OpenAI models data ๐Ÿฅท
Latent Space
51 [Paper Club] ๐Ÿ“ On Reasoning: Q-STaR and Friends!
[Paper Club] ๐Ÿ“ On Reasoning: Q-STaR and Friends!
Latent Space
52 [Paper Club] Writing in the Margins: Chunked Prefill KV Caching for Long Context Retrieval
[Paper Club] Writing in the Margins: Chunked Prefill KV Caching for Long Context Retrieval
Latent Space
53 The Ultimate Guide to Prompting - with Sander Schulhoff from LearnPrompting.org
The Ultimate Guide to Prompting - with Sander Schulhoff from LearnPrompting.org
Latent Space
54 llm.c's Origin and the Future of LLM Compilers - Andrej Karpathy at CUDA MODE
llm.c's Origin and the Future of LLM Compilers - Andrej Karpathy at CUDA MODE
Latent Space
55 Prompt Engineer is NOT a job ๐Ÿ“
Prompt Engineer is NOT a job ๐Ÿ“
Latent Space
56 Prompt Mining LLMs for better prompts โ›๏ธ
Prompt Mining LLMs for better prompts โ›๏ธ
Latent Space
57 The six pillars of few-shot prompting ๐Ÿ”ง
The six pillars of few-shot prompting ๐Ÿ”ง
Latent Space
58 Language Agents: From Reasoning to Acting โ€” with Shunyu Yao of OpenAI, Harrison Chase of LangGraph
Language Agents: From Reasoning to Acting โ€” with Shunyu Yao of OpenAI, Harrison Chase of LangGraph
Latent Space
59 [Paper Club] Who Validates the Validators? Aligning LLM-Judges with Humans (w/ Eugene Yan)
[Paper Club] Who Validates the Validators? Aligning LLM-Judges with Humans (w/ Eugene Yan)
Latent Space
60 Can you separate intelligence and knowledge?
Can you separate intelligence and knowledge?
Latent Space

This video discusses the vulnerability of AI models to data stealing through prompt attacks, highlighting the importance of AI security and prompt engineering. Nicholas Carlini demonstrates how to steal training data from OpenAI models, including GPT 3.5 Turbo. The video provides a comprehensive overview of the risks associated with AI models and the need for robust security measures.

Key Takeaways
  1. Understand the concept of prompt injections and prompt security
  2. Learn how to design prompt attacks to test AI model security
  3. Develop strategies to protect AI models from data stealing
  4. Implement techniques to prevent prompt injections
  5. Test AI models for vulnerabilities to data stealing
๐Ÿ’ก AI models can be vulnerable to data stealing through prompt attacks, highlighting the need for robust security measures to protect sensitive information.
๐Ÿ”’ Pro feature: Ask AI to explain this lesson โ†’

Related Reads

๐Ÿ“ฐ
OpenAI loses a top data center exec, as stream of high-profile departures continues
OpenAI faces leadership changes with the loss of a top data center executive, amid a series of high-profile departures, impacting its infrastructure organization
TechCrunch AI
๐Ÿ“ฐ
The Great Tech Boomerang
Companies are rehiring developers after AI layoffs, highlighting the importance of human skills in tech
Dev.to ยท Pearl Almeida
๐Ÿ“ฐ
India Wants a $150 Billion Chip Market. Japan May Be the Industrial Partner That Makes It Real
India aims to create a $150 billion chip market and may partner with Japan to achieve this goal, potentially altering the semiconductor industry landscape
Medium ยท AI
๐Ÿ“ฐ
The Unforeseen in Maxims and the Waste of the Setback
Abandoned knowledge can become the foundation for new creations, highlighting the importance of re-evaluating past setbacks
Medium ยท AI
Up next
๐Ÿšจ MANUS USERS: BACK UP NOW! What You Need to Know + This Week in AI
Alicia Lyttle
Watch โ†’