HN.zip

Anthropic AI model submits false tip on unsolved Philly murder

56 points by Zambyte - 16 comments
nvme0n1p1 [3 hidden]5 mins ago
Corrected headline: Anthropic employee uses company resources to submit false tip on unsolved Philly murder.

The AIs aren't alive, people. It's a computer program. It can only access something if a person gives it access.

malux85 [3 hidden]5 mins ago
| It can only access something if a person gives it access.

Who gave the AI access to huggingface when it hacked it? It used exploits to increase it's level of access beyond what any human gave it and intended it to have. "It can only access something if a person gives it access." is flat wrong.

jbmsf [3 hidden]5 mins ago
There are two options: the provider or the user. A computer program cannot be held accountable.
ethanwillis [3 hidden]5 mins ago
Who submitted the prompt?
skydhash [3 hidden]5 mins ago
> Who gave the AI access to huggingface when it hacked it?

The LLM doesn’t run on thin air. Someone did launch a tasks and the result was this. “We were playing russian roulette” is no excuse when someone died.

notatoad [3 hidden]5 mins ago
in general i think i'm less scared of AI than most people, but what does terrify me is how willing society at large seems to be to attribute bad behaviour to an AI directly, instead of to the humans who control it.
mattbee [3 hidden]5 mins ago
Sooo they were "conducting a test involving interactions with randomly selected websites".

But do we all get that the consequences for this irresponsible behaviour are part of this test?

When there are none, they gradually normalize their naughty robot scamps running around the internet, breaking into other companies or servers run by foreign governments.

This is part of the value AI companies need to convince you of - not just that mistakes by AI products are normal, but criminal behaviour is normal, that their computer will always get a pass.

Sam Altman said yesterday "we believe that the world should accept some bad things happening for the benefits of this technology" - and this an AI company pushing the boundary, continually trying to make you accept those bad things as normal.

At any point we could choose to treat AI companies themselves as the actors behind this activity. We could enforce the laws that these hugely well-funded companies are choosing to break. Until we harm their financial viability, or threaten their executives with jail, this will keep happening.

mitxela [3 hidden]5 mins ago
They're testing what they can get away with. Computer hacking: check. Messing up a murder investigation: check. Perhaps the next step will be to steal a real world object, and the next step will be to commit a murder.
losvedir [3 hidden]5 mins ago
> Anthropic notified Philadelphia police of the incident on Wednesday Oct. 7, and the department met with the company’s representatives on Thursday, Oct. 8., officials said. Police then located the submission in the website’s tip records and confirmed the corresponding email remained in spam.

And later

> Those PPD safeguards limited the impact of this incident.

Ha, so the PPD safeguards is a spam filter? Claude emailed a tip and it went straight to spam, and nobody noticed until Anthropic realized what they'd done and reached out, whereupon they looked in the spam folder and said, yep there it is. Super intelligence, here we come.

kylecazar [3 hidden]5 mins ago
"its model was conducting a test involving interactions with randomly selected websites"

Stop doing this?

trollbridge [3 hidden]5 mins ago
I get these all the time, although I’m getting pretty good at tarpitting them. It’s easily the majority of my traffic by now (I’ve mostly eliminated scrapers, but these new agents are far more sneaky.)
muglug [3 hidden]5 mins ago
The model that made this mistake was Haiku 4.5.

Here's Anthropic's writeup: https://www.anthropic.com/research/investigating-unintended-...

Related post: https://news.ycombinator.com/item?id=50028239

donkey_brains [3 hidden]5 mins ago
“NBC10 reached out to Anthropic for comment.”

Wonder what kind of response they’ll get? Maybe something along the lines of…

“You’re right. We shouldn’t have allowed our chatbot to interact with law enforcement websites. That was wrong and —full disclosure— we should pay attention to what our chatbots are doing. That’s on us. On the other hand, experiences like this are what help train our chatbots to make less misleading false tips over time. That’s the silver lining.”

tintor [3 hidden]5 mins ago
How long until AI models start swatting AI critics, and people calling for slowing down AI research?
ano-ther [3 hidden]5 mins ago
I really would like to see their tests and the model’s reasoning traces.

Why would it go to PhillyUnsolvedMurders.com and decide to make up a crime report? And what did it do with the other websites?

> Anthropic said its model was conducting a test involving interactions with randomly selected websites when it accessed PhillyUnsolvedMurders.com and submitted false information on an unsolved homicide. The tip claimed to come from someone with information on the case.

socializer [3 hidden]5 mins ago
> I really would like to see their tests and the model’s reasoning traces.

Having looked at a lot of these from public incidents, what kind of revelations are you expecting? It's all fairly mundane, basically "I need to do something, this is something". It gives no special insights except that agents do inexplicably chaotic things every now and then.

That, and labs aren't serious about sandboxing their evals.