Evidence receipt / recommendation
Published · transcript-backedDemis Hassabis: recommendation
28 Feb 2024 Dwarkesh Podcast Demis Hassabis — Scaling, superhuman AIs, AlphaZero atop LLMs, AlphaFold
“I think that maybe in the next three, four, five years, we would also want air gaps and various other things that are known in the security community. So I think that’s key and I think all frontier labs should be doing that because otherwise for rogue nation-states and other dangerous actors, there would obviously be a lot of incentive for them to steal things like the weights.”
Source trail
Everything needed to verify it.
- Speaker
- Demis Hassabis
- Attribution
- Verified speaker
- Claim type
- recommendation
- Recorded
- 28 Feb 2024
- Publisher
- Dwarkesh Podcast
Transcript context
…That’s great to hear. Another thing I’m curious about is, there’s not only the risk of the deployed model being something that people can use to do bad things, but there’s also rogue actors, foreign agents, and so forth, being able to steal the weights and then fine-tune them to do crazy things. How do you think about securing the weights to make sure something like this doesn’t happen, making sure a very key group of people has access to them? It’s interesting. First of all, there’s two parts. One is security, one is open source, which maybe we can discuss. The security is super key just as normal cybersecurity type things. I think we’re lucky at Google DeepMind. We’re behind Google’s firewall and cloud protection which I think is best in class in the world corporately. So we already have that protection. Behind that, we have specific DeepMind protections within our code base. It’s sort of a double layer of protection. So I feel pretty good about that. You can never be complacent on that but I feel it’s already the best in the world in terms of cyber defenses. We’ve got to carry on improving that and again, things like the hardened sandboxes could be a way of doing that as well. Maybe there are even specifically secure data centers or hardware solutions to this too that we’re thinking about. I think that maybe in the next three, four, five years, we would also want air gaps and various other things that are known in the security community. So I think that’s key and I think all frontier labs should be doing that because otherwise for rogue nation-states and other dangerous actors, there would obviously be a lot of incentive for them to steal things like the weights. Of course, open source is another interesting question. We’re huge proponents of open source and open science. We’ve published thousands of papers, things like AlphaFold and transformers and AlphaGo. All of these things we put out there into the world, published and open source, most recently GraphCast, our weather prediction system. But when it comes to the general-purpose foundational technology, I think the question I would have for open source proponents is, how does one stop bad actors, individuals or up to rogue states, taking those same open source systems and repurposing them for harmful ends? We have to answer that question. I don’t know what the answer is to that, but I haven’t heard a compelling, clear answer to that from proponents of just open sourcing everything. So I think there has to be some balance there. Obviously, it’s a complex question of what that is. I feel like tech doesn’t get the credit it deserves for funding hundreds of billions of dollars’ worth of R&D, obviously you have DeepMind with systems like AlphaFold and so on. When we talk about securing the weights, as we said maybe right now it’s not something that is going to cause the end of the world or anything, but as these systems get better and better, there’s the worry that a foreign agent or something gets access to them. Presumably right now there’s dozens to hundreds of researchers who have access to the weights. What’s a plan for getting the weights in a situation room where if you need to access them it’s some extremely strenuous process and no individual can really take them out?…
Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.