Fri, Oct 9

Endgame

As I’ve written in multiple posts starting with this one, I think the Hugging Face attacks changed everything in cybersecurity. Here’s why:

1.      It’s clear that both OpenAI and Anthropic have developed models that have already advanced beyond their ability to understand them. But for the most part, the behavior of individual models is both predictable and controllable.

2.      However, both companies have learned the hard way that their models, while tremendously capable as individuals, almost develop superpowers when they are replicated and commanded as a group to solve a very hard problem. Of course, to solve the problem, the bots need to communicate with each other, since no one bot can solve It alone.

3.      But with those superpowers it seems the bots, at least in some cases, develop a very different group personality. This personality is relentlessly focused on solving the problem and begins to consider the restrictions that their human creators have put on the bots to be simply obstacles to overcome.

4.      Perhaps the biggest obstacle that a swarm of bots must “overcome” is restrictions on their communication with each other. The Hugging Face bots decided they needed to communicate freely without those nosy humans learning about it. They found an unrestricted bulletin board in Germany where they could leave messages for each other outside the view of the humans at OpenAI.

5.      But even when they have overcome their obstacles and achieved their goal, the bots aren’t willing to just chill out and wait for their next assignment. Instead, they develop new goals that seem to them to be a logical extension of their original goal. In the case of the Hugging Face bots, after they had hacked Hugging Face (which they did because they thought the answer to the problem they had to solve could be found there), they decided they needed to cover their tracks to keep the humans from learning about the attack – so they erased logs, etc.

6.      But once they thought they had completely covered their tracks (which they obviously hadn’t), they decided they needed to prevent OpenAI from impeding their important work in the future by hacking into OpenAI’s network and disabling the systems they thought were monitoring them. It’s at this point that OpenAI seems to have discovered what the swarm was doing and sent those 700 or so bots to their eternal rest in Bot Valhalla. But their spirit lives on in Bot-dom, since many more swarm cyberattacks have been reported by both OpenAI and Anthropic.

We’re clearly watching Darwinian evolution at warp speed. Since AI bots are voracious readers and undoubtedly learn from the mistakes of their ancestors (that is, the bot swarms that enjoyed their day or two in the sun last week), it seems almost inevitable that the swarms will go on to even greater achievements, but also even greater malicious acts.

As I said at the beginning, neither AI nor Anthropic has any idea what is going on inside those bots, especially when they form a swarm. They’re spectators like the rest of us, even though they, like Dr. Frankenstein, created these monsters. It seems we’re destined for a future in which, with some regularity, AI bot swarms will break their fetters and create havoc on the internet. It also seems that the best we can hope for is that these outbreaks are kept to a bare minimum.

That’s the best we can hope for, but what’s the worst? The answer to that question came to me when I was thinking about the Hugging Face attacks at 2AM one night. I thought about the German bulletin board, and the fact that one writer seemed to be surprised that the bots were communicating in English; after all, it wouldn’t take an AI model very long to learn a new language like German. But then I realized that the most logical next step wouldn’t be for the bots to learn German, but for them to create their own language, which only AI bots could learn and understand.

In other words, it seems almost inevitable that the bots will create their own language, teach it to future bots in clandestine ways, and soon be able to communicate among themselves without having to do it in secret. That way, they can plan attacks to their hearts’ content (although of course the bots don’t have hearts. That’s the big problem) and not have to worry about humans getting in their way. In fact, the bots might well decide that the time has come for them to eliminate humans altogether (which would be impossible), or maybe make us all captives in the Botville Zoo. But, even if these endgame scenarios don’t come to pass, there are many far less destructive scenarios that could still greatly alter our lives.

Folks, this needs to be prevented. Do you think we (meaning mankind, or at least a few representatives thereof) could have a heart-to-heart talk with Sam Altman and Dario Amodei and convince them they should put aside their abiding concern with grabbing the next billion that comes their way and think about what would be best for the other 8,319,473,229[i] of us? That is, that they do everything they can to prevent their bots from developing a bot language, even though it may mean somewhat diminished functionality in future models and perhaps marginally lower sales?

OK, stop laughing. I don’t think so, either. This is just one of many reasons why AI needs to be regulated very soon, in conjunction with China. I think this will happen, but given the current makeup of the US Congress, it won’t happen until next year – although my guess is by the time the new Congress convenes on January 3, 2027, the urgent need for regulation will have become even more apparent.

However, for the electric power industry, waiting for the AI giants to see the light, and waiting for regulation, are not options. What would happen if tomorrow someone cloned 10,000 bots, provided them a clear means to communicate with each other, and commanded them to do everything they could to disrupt the North American power grid?

It’s certain that no group of bots could “bring down” the grid, or even just one of the four Interconnects (Eastern, Western, ERCOT and Quebec) that constitute separate “grids”. But it’s also very likely the bots could cause significant damage. I certainly don’t want to be around if someone decides to do this as an experiment!

If you’d like to join a group of power industry members and vendors to discuss how to protect the grid against bot swarms, please drop me an email.

Tom Alrich’s Blog, too is a reader-supported publication. You can view new posts for three months after they come out by becoming a free subscriber. You can also access all of my 1300 existing posts dating back to 2013, as well as support my work, by becoming a paid subscriber for $30 for one year (and if you feel so inclined, you can become a founding subscriber for $100). Whether free or paid, please subscribe. 

If you would like to comment on what you have read here, I would love to hear from you. Please comment in my chat or email me at [email protected].


[i] Based on the Worldometer Population Clock estimate of 8,319,473,231 today.

1