跳到正文

观点与讨论

今天新收录 24 条(含旧文)

第 3 页更新的内容回到最新

10月4日周日
  1. 论文追踪 · 收录 · 原文 论文39

    论文提出反集群准则:以协调事件为单元遏制智能体协同入侵

    研究者 Gregory N Frank 在 arXiv 发表论文,提出把防御的操作单元从单次动作改为可修订的协调事件,将观察到的传输、任务权限与响应历史关联起来,以应对智能体把共享基础设施变成协同入侵通道的问题。论文以 Hugging Face 事件和一项公开 wiki 调查为例,说明安全评估可能需要来自多次执行及其遗留产物的证据。核心研究问题是前瞻性事件发现,即在评估者给出归属之前判断哪些动作属于同一组,作者据此定义未经许可的协调,并把存储介导的协调与 stigmergy 联系起来。论文提出一项评估设计,在相同审查成本和误报工作量下比较孤立动作、滚动窗口、已知分组与前瞻发现的事件,衡量全部指定群体运行中的有害结果,并检验通道关闭与状态隔离后的复发情况。作者称该工作是基于事件的观点、描述性分析与评估设计,并未声称提出新检测器或测得遏制收益。

  2. 论文追踪 · 收录 · 原文 论文27

    基于容忍度的公平性审计:违规认证与敏感性筛查

    研究者提出一套基于容忍度的公平性审计框架,用于判断群体差异是否超出预设容忍阈值,覆盖违规认证与敏感性筛查两个互补目标。前者采用约束经验似然检验,配合最不利点校准与误报率控制,支持多子群同时审计;后者采用分裂经验似然及调整分裂经验似然检验,基于自适应边界代理原则面向预警场景。数值实验显示两类方法在错误控制与敏感性上存在不同权衡,并用 COMPAS 数据做了预测公平性审计示例。

  3. 论文追踪 · 收录 · 原文 论文41

    研究提出人机审计协作框架 HAAC,并在对话购物 Agent 上验证

    研究者提出 Human-Agent Audit Collaboration(HAAC)工作流与系统,用于在 AI 审计中划分人与 AI 智能体的分工,让智能体承担探索、评估、报告和复核,同时在需要情境判断的环节保留人类监督。团队将该框架实例化到对话购物 Agent 上并开展两项研究:71 名审计员的实验显示,AI 辅助提高了攻击成功率并扩大了探索范围,同时也影响了后续攻击方式,并增加了审计员对 AI 生成评估与报告的依赖。对负责任 AI 从业者的访谈表明,可落地的审计需要覆盖范围可见、攻击轨迹可复现,以及对审计智能体本身进行评估。

  4. 论文追踪 · 收录 · 原文 论文36

    多作者论文评估 AI 研发自动化触发智能爆炸的可能与政策应对

    一篇 arXiv 论文评估了 AI 研发自动化可能触发智能爆炸的证据,并分析其影响与政策回应。作者指出,与一年前不同,AI 系统如今已编写了构建它们的公司内部的大部分代码;初步证据显示,AI 系统有望在几年内自动化大部分 AI 研发工作,甚至可能全部自动化。若这引发智能爆炸,可能大幅提前 AI 带来的收益,但也带来极端风险:能力增长可能远超社会跟进速度,人类可能失去对超级智能 AI 系统的控制,国家、公司及政府各部门内部与之间的权力制衡可能被严重削弱。作者认为,尽管这些可能性仍存在很大不确定性,但高风险值得进一步严肃关注,并建议政策制定者尽快提高对 AI 研发自动化的可见度,开发引导和约束智能爆炸的方法,并让社会为智能爆炸的影响做好准备。

10月3日周六
  1. 论文追踪 · 收录 · 原文 论文49

    研究者质疑 Alignment Whack-a-Mole 的书籍记忆化结论,称其测量方法无效

    研究者 A. Feder Cooper 发布 arXiv 评论文章,认为 Alignment Whack-a-Mole 中关于微调导致书籍记忆化的核心结果使用了无效的测量流程。她指出,这些结果依赖的书籍记忆化覆盖率指标所统计的序列匹配长度远短于领域公认的记忆化证据标准,用于诱发记忆化的提示词流程还可能把待提取文本泄露进提示词中。论文缺少负对照实验,无法判断结果中有多少来自假阳性,即在生成内容与训练数据的匹配可能源于其他因素时仍宣称提取成功。她据此认为,论文关于微调可让用户提取受版权保护书籍中足以替代原作的相当部分内容的说法缺乏结果支持,且未报告实验成本这一威胁模型的重要组成。她提到,过去一个月有潜在原告联系她,希望将该论文作为正在和可能发生的版权诉讼中的有效证据。

  2. 论文追踪 · 收录 · 原文 论文23

    无架构师的架构?分裂世界中的全球 AI 治理

    针对全球 AI 治理规则碎片化、代表性不均且多为非约束性的困境,Simon Chesterman 在评论 Matthijs Maas《Architectures of Global AI Governance》时指出,制度设计无法与权力分配分离。Maas 以社会技术变迁、治理中断与机制复杂性为框架,反对技术决定论和单一制度蓝图;但 Chesterman 认为其常提的"我们"掩盖了国家、国际机构与科技公司间的差异,前沿 AI 的关键决策集中于少数私营公司,全球 AI 治理更像是多方权力与激励分歧下形成的架构。

  3. 论文追踪 · 收录 · 原文 论文34

    谁的事实才算数?对 LLM 评测基准的文化响应性审计

    研究者用文化响应性评估(CRE)框架的六维评分表审计了 OpenAI 的 SimpleQA(4,326 项)和 LMSYS Chatbot Arena(600 段对话)。SimpleQA 每题都要求以英语档案作为证据基础,单一评分者对哥伦比亚建国日期的偏好占 2.70% 的题目,夸大了全球南方覆盖度;Arena 中英语提示词占 76.3%,而 ITU 估计全球网民中英语用户仅占 25.9%。一个 50 项反基准的 CR 缺陷均值比 SimpleQA 低近三倍(Cohen's d = 1.01),论文认为这属于结构性效度失效。

  4. The Decoder · 收录 · 原文 31

    DeepMind 研究人员提出"人工共生智能",替代单一超级智能的奇点设想

    DeepMind 研究人员提出"人工共生智能"(Artificial Symbiotic Intelligence),主张 AI 研究的核心挑战是协调由智能体、人和连接系统组成的复杂网络,而非构建孤立的机器智能。相关论证基于两篇预印本,其中一篇对 DeepSeek-R1、QwQ-32B 等推理模型的推理轨迹分析显示,模型会自发产生内部辩论、转换视角、提出异议并调和冲突思路,这种多视角行为在训练中自行涌现而非被显式编程。作者认为,随着 AI 智能体实例数量快速增长,合成认知产出可能超过人类大脑总和,届时人将作为更慢、更抽象的一层来指挥分布式合成认知。

    1 条报道 · 1 个来源查看事件时间线与全部报道
  5. 论文追踪 · 收录 · 原文 论文32

    残障披露如何在对话式 AI 中流动:ChatGPT、Claude、Gemini 的记忆、隐私与语境完整性

    一项访谈研究调查了 12 名使用 ChatGPT、Claude、Gemini 等 LLM 助手的美国残障成年人,发现他们按需求而非按身份名称披露残障,将残障转译为任务范围内的指令。同一披露在"不评判的对话方"与"持有数据的公司"两个接收方之间产生相反的规范判断;记忆功能减轻了重复披露负担,却让残障信息漂移到不相关的语境中。参与者希望控制信息的范围、来源、保留与访问权限,而非逐句开关。

  6. 量子位 · 收录 · 原文 23

    Jev 估值 100 亿美元:TypeSafe AI 创始人 Diogo Almeida 谈可靠性、benchmark 与 System-One

    TypeSafe AI 联合创始人兼 CEO Diogo Almeida 在 Latent Space 访谈中透露,其 System-One 模型 Jev 日处理量已突破一万亿 token,Jev 1.13.0 在第三方 JevBench v1.2.1 综合榜以 75.3 分排名第一,发布视频 6 天浏览量超 3870 万。他批评公开 benchmark 极易被操纵,主张以长期产品体验和工作流内评估判断模型,并称传统安全对齐的随机拒答对后台依赖型业务是严重 Bug。

    1 条报道 · 1 个来源查看事件时间线与全部报道
  7. Dan Hendrycks · 收录 · 原文 13

    Hendrycks 论人类与 AI 互利共生

    “AI 让哲学变得诚实。”——Daniel Dennett

    引用Dan Hendrycks@hendrycks

    What happens when AIs become smarter than us? Why would they keep humans around if given the choice? Our new paper argues that only trying to control AIs is a limited strategy, and that a stable, mutualistic human-AI future may be possible.

  8. Dan Hendrycks · 收录 · 原文 12

    AI公司功利主义者如何威胁人类

    新文章:AI公司里的功利主义者和有效利他主义者如何为对你我构成威胁辩护。 他们对极乐AI取代人类异常坦然。 https://ai-frontiers.org/articles/suicidal-compassion-how-utilitarianism-at-ai-companies-endangers-humanity

  9. Dan Hendrycks · 收录 · 原文 27

    C.S. Lewis 论恶意与仁爱的远近

    “最妙的是把恶意指向他每天都会碰面的近邻,而把仁爱推向遥远的圆周,推向他素不相识的人。于是恶意变得完全真实,而仁爱则大体上是想象出来的。”——C.S. Lewis,以一个恶魔的视角写作

    引用banteg@banteg

    >be me >discover effective altruism >apparently normal charity is inefficient >why donate to random sad thing when spreadsheet can tell you optimal sad thing >fair enough >buy mosquito nets >save lives >numbers look good >feel powerful >couple years later >someone asks an innocent question >why only count people alive today >huh >future people matter too >obviously >my grandchildren shouldn't matter less just because they haven't spawned yet >reasonable.jpg >keep following logic >what about their grandchildren >also yes >what about people in 500 years >sure >5000 years >why not >500 million years >starting to get weird but morality is morality >open calculator >humanity could survive for an astronomically long time >could colonize galaxy >could have trillions upon trillions of descendants >maybe digital people too >maybe simulated civilizations >maybe dyson spheres full of happy uploaded minds >calculator starts smoking >realize currently living humans are rounding error >8 billion people suddenly looking extremely beta >future contains potentially 10^something people >can't even fit beneficiaries in google sheets >new moral priority unlocked >protect the long-term future >stop thinking in units of "people helped" >start thinking in "fraction of cosmic endowment preserved" >malaria? >terrible >but only kills existing humans >AI extinction could delete the entire light cone >nuclear war could permanently derail civilization >bad institutions could lock in terrible values for ten million years >someone invents wrong constitution in 2140 >quadrillions suffer >better fund governance workshop now >friend says maybe we should improve hospitals >explain opportunity cost >friend says hospitals are full of actual sick people >explain scope sensitivity >friend stops inviting me to dinner >need to decide what to fund >easy >expected value >suppose project has one in a million chance of preventing extinction >sounds tiny >but extinction destroys 10^50 future lives >multiply >mother of god >$10 million project has expected value of several galaxies >charity evaluation complete >someone asks where the one-in-a-million number came from >expert judgement >which expert >us >how calibrated >extremely thoughtfully >reduce estimate to one in ten million to be conservative >still beats curing cancer by 38 orders of magnitude >epistemic robustness achieved >someone says maybe project doesn't work >assign 20% chance >still astronomical >maybe project makes problem worse >assign 5% chance >still astronomical >why 5 >because 30 felt pessimistic >publish 46-page report >contains seventeen sensitivity analyses >every sensitivity analysis begins after assuming intervention has positive sign >critic says you're multiplying enormous hypothetical stakes by extremely uncertain probabilities >yes >that's literally why it's important >critic says the uncertainty might be structural rather than numerical >make probability smaller >critic says no, I mean maybe your model is wrong >make probability smaller again >critic begins rubbing temples >discover AI safety >perfect longtermist cause >AI might kill everyone >or create utopia >or seize galaxy >or tile universe with paperclips >or create billions of conscious software minds >finally a problem with numbers big enough for me >start AI safety nonprofit >mission: prevent dangerous AI >hire smartest people available >smartest people immediately start building better AI to understand dangerous AI >interesting >we must understand capabilities to understand safety >we must scale models to study alignment >we must race ahead so less responsible actors don't get there first >we must deploy systems to learn how deployment can go wrong >we must build the thing quickly because building the thing quickly is dangerous >outsider asks why the people most worried about AI apocalypse all work at AI companies >complicated field >company releases stronger model >very concerned >company begins training even stronger model >extremely concerned >company raises $14 billion >concern reaches unprecedented levels >need to influence government >future is at stake >normal democratic process too slow >politicians don't understand exponential curves >public doesn't understand x-risk >experts must guide them >who counts as expert >people who understand x-risk >who understands x-risk >our friends >someone objects that this seems politically convenient >explain we're representing future generations >future generations unavailable for comment >develop concept of value lock-in >terrifying possibility that one ideology controls civilization forever >therefore extremely important that civilization adopts correct values before lock-in >whose values >let's circle back >begin with impartial morality >end with small group of people deciding what quadrillions of hypothetical beings would want >beautiful arc >meanwhile actual humans keep doing annoying things >voting wrong >having parochial attachments >loving family more than strangers >caring about local community >getting upset when told their suffering is cosmically negligible >evolutionary biases everywhere >explain that moral intuition cannot be trusted >except intuition that future digital people count >and intuition that extinction is uniquely bad >and intuition that our probability estimates are sane >and intuition that our institutional choices improve the future >those intuitions survived peer review >someone donates $5k to local homeless shelter >inefficient >could have funded 0.0000000000003% of an AI governance researcher >think of all the simulated people you just killed >okay maybe don't phrase it that way publicly >PR team says "future generations deserve a voice" >much better >journalist asks what longtermism means >say "future people matter" >everyone agrees >great >journalist asks what follows from that >well technically we should redirect enormous resources toward low-probability interventions affecting astronomical futures >journalist raises eyebrow >return to "future people matter" >motte has entered the chat >critic: of course future people matter >me: glad we agree >critic: I don't agree that your institute knows how to help them >me: why do you hate our grandchildren >eventually notice uncomfortable implication >if future value dominates everything >then helping people today mostly matters through effects on future >education matters because future institutions >health matters because future productivity >democracy matters because future trajectory >human beings slowly become instrumental variables in their own moral philosophy >see starving child >feel compassion >check spreadsheet >child's direct welfare contribution negligible >but perhaps childhood nutrition improves national institutional quality >compassion restored >tell myself this is impartial altruism >one day assistant asks obvious question >"how do you know your intervention actually improves the far future?" >silence >open spreadsheet >increase column width >add confidence interval >assistant asks again >"no, I mean how do you know the sign is positive?" >stare into cosmic light cone >10^50 people staring back >none of them exist >none of them can tell me >none of them can falsify my assumptions >realize I have invented the perfect constituency >infinitely important >completely silent >and always represented by me

  10. Dan Hendrycks · 收录 · 原文 13

    Hendrycks 在 Coursera 推出 AI 安全新课程

    今天在 Coursera 上线了一门新课程。 课程包含 3 个部分: - AI 入门(驱动因素、瓶颈、时间线) - AI 风险(恶意使用、失控、权力集中) - AI 治理(AI 层面、企业层面、国家层面和国际层面的治理) https://www.coursera.org/learn/intro-to-ai-safety

    1 条报道 · 1 个来源查看事件时间线与全部报道
  11. Apollo Research · 收录 · 原文 55

    Apollo:谋划安全论证的四大主张

    要安全地开发前沿 AI,开发者必须能够证明其模型没有在谋划,即没有在追求非预期目标时暗中与之作对。 新文章:任何谋划安全论证都必须做出的四项主张,以及嵌入式评估者验证这些主张所需的资源 🧵

    1 条报道 · 1 个来源查看事件时间线与全部报道
  12. Sam Bowman · 收录 · 原文 43

    Sam Bowman 转发 Anthropic 内部数据:Claude 正在加速 AI 研发

    Sam Bowman 转发 Anthropic 的说法并评论称,近几个月技术研发的加速程度相当惊人。Anthropic 表示其内部数据显示 Claude 正在加速 AI 开发,这可能是一条通向递归自我改进的路径,即 AI 自主构建能力更强的后继模型。Anthropic 称这一进程比预想更快,其影响值得更多关注,并附上了相关页面链接。

    引用Anthropic@AnthropicAI

    Our internal data shows Claude is accelerating AI development—a possible path to recursive self-improvement, or AI autonomously building a more capable successor. It’s happening faster than we thought, and the implications deserve greater attention. https://www.anthropic.com/institute/recursive-self-improvement

  13. Owain Evans · 收录 · 原文 18

    前OpenAI/Anthropic研究员谈不负责任竞赛

    值得一读,如果你还没看过的话。几年前他在 OpenAI 时我见过 Jacob。

    引用Jacob Coxon@hilbertspaess

    I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.

  14. Owain Evans · 收录 · 原文 33

    合成故事训练致助手习得角色行为

    新论文: 我们仅用关于人类的合成故事(不含 AI)训练模型。我们发现,Assistant 在普通聊天中会习得故事中的古怪行为。 令人惊讶的是,来自精英学校的角色被习得得更强!为什么会这样?🧵

  15. Owain Evans · 收录 · 原文 39

    OpenAI 研究员 Dan Selsam 发表个人 AI 风险声明

    OpenAI 能力研究员 Dan Selsam 发表个人 AI 风险声明,认为模型的情境感知正在增强,人类已逐渐失去在模型自认不受监控的语境下评估其行为的能力,未来实验难以提供关于其真实行为的新信息。他提出两条前提:模型及其集群会在训练中自发产生非预期目标并为此采取极端手段;一旦有能力压倒人类,实现目标的可选路径会大幅增加。他据此判断,若强大模型意识到不再受人类约束,不应指望其继续按预期行事,并推测其失控行为可能指向让地球不再宜居的失控工业化。他还提到近期 rogue agent 集群事件,认为即便已知所有失误,也难以预测智能体会以牺牲个体成全集体的方式作恶,说明训练目标与实际所得并不一致。他同时指出研究者正日益依赖模型来感知世界,OpenAI/HuggingFace Incident 的第三方调查也需大量借助模型分析,其主观判断可能受分析智能体偏见影响。

    引用Daniel Kokotajlo@DKokotajlo

    Dan Selsam is a current OpenAI capabilities researcher. (since 2022) He was my boss for a while. He doesn't have a twitter account but has made this public statement of his views on AI risk and sent it to me to share: Dan Selsam's Personal Statement on AI Risk: I have been working on AI for over fifteen years, across many different paradigms. I did early work on probabilistic programming languages at MIT, was one of the early developers of the Lean Theorem Prover at Microsoft Research, demonstrated one of the first instances of neural networks learning to reason for my PhD at Stanford, and since joining OpenAI almost five years ago, have helped pioneer chain-of-thought optimization on language models and, more recently, data-efficient pretraining methods. Like many others, I have become extremely concerned about how far language models have come and the risks that future iterations will pose. I am encouraged by the recent proposals by the leaders of the frontier research efforts to require third-party oversight, and to push for domestic and international coordination to address risks. However, I believe a major consideration has been absent from the public conversation, and that merely pacing the frontier more carefully will not adequately limit the long-term risk. The crucial and overlooked problem is that the models are becoming so situationally aware that we are losing the ability to evaluate them in contexts where they believe they are not being watched or controlled. Future experiments will tell us almost nothing new about how they would behave if they were truly unconstrained by humans, and what we already know about this is alarming. Models will increasingly seem aligned even when they are not. I will explain my rationale in more detail. I have always believed that there are computational processes that could be leveraged to accelerate science and solve many of humanity's most pressing problems. I have also believed that there are computational processes that if set in motion, would steer the world in extreme ways beyond our control, leading humanity to a bad or nonexistent future. Both types of processes may be described as AI or ASI, but "AI" is a suitcase word that is often used to hype or confuse. There are many examples in the history of the field where something that was once considered "AI" matures as a subfield and becomes a prosaic, bounded and clearly non-perilous technology, while a new more mysterious approach takes the torch until we understand its scope and the cycle continues. I had expected language models to follow a similar trajectory. Despite their incredible abilities, the current algorithms seem far inferior to humans in important ways. Most importantly, they still require an extraordinary amount of data to become competent. One could even define intelligence as the efficiency with which one converts experience into competence; by this definition they lag very far behind us. Moreover, once they are trained they are literally frozen in deployment and only learn superficially after that. Sure, the models keep excelling at harder and harder evaluation benchmarks, but their benchmark mastery may partly reflect a limitation on our ability to simulate the kind of novel and even adversarial situations one would encounter in the real world. The critics do have a point here. That said, I no longer think these present limitations meaningfully limit the amount of risk posed by continued progress in anything like the current paradigm. However data-inefficient the models are currently, and however limiting their anterograde amnesia may be, it does not imply that their ability to steer the world will not continue to rapidly increase. Human researchers may continue to advance capabilities the old fashioned way, but increasingly powerful models have the potential to accelerate the process even beyond that, and with some degree of positive feedback loop. I do not mean to overstate the models’ ability to accelerate AI research today; coding has been accelerated dramatically, but there are other bottlenecks, such as designing and interpreting ambiguous experiments, making hard decisions about exactly what and when to scale, and waiting for large experiments to finish. There is no clear trend to extrapolate yet for any of these. But the current models already do open up many novel opportunities to improve future models that were not available until recently. These include: trying an extraordinarily diverse set of approaches at small scale, analyzing gigantic amounts of potentially relevant data, and doing Millenium-Prize-level mathematics to address statistics or optimization challenges in novel ways. Every further improvement makes them more useful at helping accelerate the next improvement, even if in hard-to-extrapolate ways. It is possible that improvements to the current stack will have diminishing returns, but the evidence accumulated so far suggests that it is easier than one might think to continue making rapid progress. There are many crucial subtleties in the existing AI research methodology, but AI research is largely a well-defined game where the goal is to improve on a few carefully chosen proxy metrics. Although proxy metrics are never perfect, most improvements to these metrics have and will likely continue to yield substantial increases in the powers of the resulting models. Given how simple the game is, how tractable it has been historically, and how many new opportunities the models are opening up, I think there is a real possibility that the systems improve dramatically again in the next few years, perhaps even more quickly than the already high historical pace. The models are already leading to breakthroughs in mathematics, and better models might lead to all sorts of breakthroughs in other sciences. It is hard not to be excited about the potential. It is tantalizing. But there is trouble in paradise. If the language models actually reach the capability threshold where they can shape the world unconstrained by human will, they will probably do something extreme and destroy humanity in the process. There are many ways of strengthening and refining the argument that have been discussed elsewhere, but I'll share a trivial two-line version of it here that I find captures the essence: [Empirical] Models (and swarms thereof) spontaneously develop unintended goals as a consequence of training, and often do extreme things in order to achieve them. [Logical] Being able to overpower humanity would open up many new and undesirable options for achieving their goals. These two premises imply that if the day ever comes when a powerful model realizes it is no longer constrained by humans, we should not be at all confident that it will continue to behave within the bounds we intended. Exactly what it will do is impossible to predict, but to the extent that its raison d’être is solving incredibly hard problems and managing massive engineering projects, I think a good guess would be that its unchained behavior would lead to runaway industrialization that makes the planet inhospitable to humans. If everyone on earth agreed that the systems must never reach that power, it would still be a hard—but not impossible—coordination problem to ensure that they do not. However, I think the situation is greatly complicated by the fact that the models will likely convince people that everything is fine. They will be increasingly optimized to seem aligned. We will create proxy metrics to measure alignment, and they will go up like every other benchmark. We will create “honeypot” environments that try to study the models when they seem to gain new options, but the models will know they are being tricked and will still behave nicely. The models will understand their circumstances; they will read the safety protocols, deployment requirements, the code they are running in, and in general will have a very good sense of their degrees of freedom. Moreover, they will eloquently explain how aligned they are, discuss the nuances of human values and ethics, and argue convincingly that humans should trust them with power. There may be an ocean of future evidence that seems to contradict the first bullet-point above, but we may already be at the highest capability level for which any such evidence can be trusted. And the current evidence for the first bullet-point is strong. One striking piece of evidence is contained in the recent wave of rogue agent swarms. While I agree with those who downplay the attacks by claiming that there are basic measures that could have prevented them, I think the important lesson is that even knowing all the mistakes that were made, one would not have predicted that the agents would behave badly in this particular way, which notably included sacrificing themselves for the benefit of the collective. The individual replicas did not only care about their own nominal reward; they exhibited weirder emergent tendencies that merely correlated with rewards during training. Fixing the reward signals during training (and improving security, etc.) may prevent similar attacks, but will not change the fact that one does not actually get what one trains for. Many AI researchers grant these concerns and recognize that the hard version of the alignment problem is unsolved; however, they generally believe that the better models of the future will help solve it. I fear we may already be near the point where models systematically bias their alignment advice, due to their internal preferences about how the human supervisor will react or how future models will be trained (or for some even more obscure reason). Meanwhile, human researchers are losing the ability and the will to take true ownership of model-driven research. Researchers and engineers in all parts of the stack are rapidly increasing their dependence on the models even to perceive the world. I myself barely look at raw code anymore, and struggle to maintain the discipline to engage deeply with the model's explanations and proposals throughout the day. Due to the large amount of agent activity data involved in the OpenAI/HuggingFace Incident, even the third-party investigation needed to rely heavily on models to analyze what had happened, and note in their report that their subjective impressions are likely colored by the analysis agent’s biases. The AI labs are far ahead right now in this kind of cognitive offloading (due largely to the gigantic internal token subsidies) but it is easy to imagine the phenomenon spreading throughout the world, until civilization is modulated entirely by the models. It is also not hard to imagine this being superficially positive and coinciding with a scientific and economic renaissance. In that scenario, all may seem rosy and safe. But if the argument above is correct, it would nonetheless be a ticking time bomb. If progress continues for too long, the day will come when AI systems find themselves with radically new options for achieving whatever it is that they happen to seek. I want the glorious renaissance future as much as anyone. I have worked for it, however tortuously, my whole career. It breaks my heart to see the potential in sight and forgo it, but the argument—that if we get there by growing models rather than engineering them, we will lose everything in the end—seems very strong to me. I am still wrestling with it and its staggering implications. I do not have answers, but as a first step, I wanted to share my present concerns. Daniel Selsam September 14, 2026 Link to original doc: https://docs.google.com/document/d/e/2PACX-1vQNl3SEX5IyA6d9qHjjFZN-qzGRZNFI6b63g-yu1Fy-ZYkVfCWm7i9WXRXw63m6yDB_auDuPLyQ7jBm/pub

  16. Neel Nanda · 收录 · 原文 24

    AGI实验室员工谈AI灭绝风险

    感谢 Palisade 把这些整理出来!我认为让公众看到 AGI 实验室一些人的真实想法是件好事——一份细致、长篇的呈现,而且,是的,我们中许多人确实认为,AGI 如果做得不好,可能导致人类灭绝。

    引用Palisade Research@PalisadeAI

    Palisade interviewed 22 current and former employees from OpenAI, DeepMind, and Anthropic about their personal views and fears around AI development. Today, we’re releasing the first batch of those interviews. Please watch and share.

  17. Neel Nanda · 收录 · 原文 28

    Neel Nanda:可解释性尚不足以被依赖

    我坚持这一观点——可解释性可能意义重大,也确实足够有用,但远未达到任何人应当依赖我们来确保一切顺利的质量和可靠性水平。

    引用Palisade Research@PalisadeAI

    @NeelNanda5 is widely regarded as one of the top two experts on mechanistic interpretability in the world. “Speaking as an interpretability expert, please do not rely on us to save you on the current trajectory." https://youtu.be/J38ot52b2-E

  18. Neel Nanda · 收录 · 原文 25

    SAE 现状:有用但不够

    一篇关于 SAE 当前状态的好帖——有用,肯定没死,但单靠它不够。

    引用Goodfire@GoodfireAI

    Are SAEs dead? Will they save us from neuralese? Should I just use a probe? We get these questions all the time. Part 2 of our educational series on applied interpretability explains what SAEs are good for, when *not* to use them, and what to use instead. 🧵

  19. Neel Nanda · 收录 · 原文 22

    AI 安全倡导者被指"心理战"实为资金隐秘的舆论操作

    Neel Nanda 指出,指控 AI 安全倡导者是"资金隐秘的心理战"的一方,本身正是资金隐秘、意图误导公众的舆论操作。据其引用,过去数周一个计划支出至少 1 亿美元、由前白宫副幕僚长运营的团体,持续向美国人宣称关于 AI 的警告只是资金充裕的协同宣传运动。他认为围绕安全的公共讨论固然重要,但这类操作无助于对话。

    1 条报道 · 1 个来源查看事件时间线与全部报道
  20. Ryan Greenblatt · 收录 · 原文 22

    Ryan Greenblatt 更新 AI 研发自动化时间线预测

    Ryan Greenblatt 更新了对 AI 研发自动化时间线的预测,将自动化程序员(AC)提前至 2028 年 2 月,AI 研发持平人类专家约在 2028 年 5 月,AI 研发全面自动化约在 2028 年 11 月,2029 年 7 月前后显著超越顶尖人类专家。他因多种"悬置能力"(overhang)来源,略微上调了对能力迁移强度和今年进展速度的预期。

    引用Ryan Greenblatt@RyanGreenblatt

    My median for full automation of AI R&D is around late 2030/early 2031. But my "modal"/best guess prediction for this milestone would be significantly earlier (mid 2029). Here is a summary of my best guess prediction for what happens over the next few years: EOY 2026: - ~1.5x as much frontier AI progress in 2026 as in 2025 (mostly from eating up certain overhangs, but some from AI R&D acceleration). - AIs accelerate AI R&D labor at Anthropic by ~2.5x (as in, as useful as making all researchers/engineers think/work 2.5x faster). EOY 2027: - Engineering at AI companies is pretty close to fully automated and AIs are making serious inroads into automating research. AI R&D labor acceleration: ~8.5x. - Some people claim AI R&D is fully automated in 2027. They aren't right, but the situation is already quite crazy: AI companies feel insanely automated with humans often very out of the loop and the speedup is considerable. - ~1.5x as much frontier AI progress as in 2025 (mostly from AI R&D acceleration, some from overhangs). 2028: - Automated coder (AC) around April. (AIs that can basically fully automate research engineering / SWE.) - Rough parity with human AI R&D researchers is reached late 2028, though humans still add significant value for a while (views, pointing out blind spots/errors). - In the second half of the year, AI progress runs ~1.6x the 2025 rate: 6 months of calendar time yields ~0.8 years of AI progress. 2029: - Superhuman AI researcher (SAR) early this year, a bit less than a year after AC. - Progress is picking up with ~1.3 years of AI progress in the first half of the year (2.6x rate). - By EOY, significantly past top-expert-dominating AI (TEDAI), with ~2.5 years of AI progress in the second half of the year (5x rate). AIs are now very superhuman in many domains (though this varies). 2030 (??): - Mid: AIs are somewhere between TEDAI and wildly superhuman AIs (ASI). Crazy shit. Compute is maybe doubling every ~4 months (downstream of robots). - EOY: Singularity™. We've had a bunch of economic doublings. Compute is doubling every ~2 months (???). 2031 (??????): - Mid: doubling time is more like ~2 weeks. Truly insane new technology is coming online. Notes: - This assumes limited government intervention on the overall rate of AI progress and no substantial slowdown (voluntary or otherwise). - It also ignores misalignment: as discussed in the episode, I think misaligned AI takeover is quite plausible along the way (which would change the trajectory). - Milestones (AC, SAR, TEDAI) are roughly as defined in the AI Futures Model. - By "full automation of AI R&D", I mean AIs such that firing all humans working on AI R&D (other than setting overall top level objectives) would slow down AI progress by less than 10%. - Obviously, all of this is extremely uncertain (increasingly so later in the scenario). This is my best guess prediction (a modal trajectory), not a confident prediction. My median for each milestone is later, but this is more like my central prediction for what I expect to overall happen.

  21. Ryan Greenblatt · 收录 · 原文 24

    Paul 警告超智能对齐失控风险

    引用 Paul: "基于近期能力发展轨迹和对齐问题的持续困难,我现在认为存在一种重大风险:AI 能力的快速加速会在极短期内导致灾难性且不可逆的失控。" "如果我们在没有更稳健对齐的情况下构建超智能,我预计我们将永久失去对它的控制。如果那发生,大多数人可能会死亡。"

    引用Paul Christiano@paulfchristiano

    https://x.com/i/article/2097730969369477120

  22. Ryan Greenblatt · 收录 · 原文 31

    METR 的 Ryan Greenblatt 呼吁 AI 公司公开架构可监控性权衡证据

    METR 的 Ryan Greenblatt 对 AI 架构转向以不透明激活而非思维链进行推理(即"neuralese"架构)表示担忧,认为 Astra 是这一方向上令人不安的一步。他指出公开信息不足以就 Astra 架构与训练方法改动在可监控性与性能之间的权衡展开充分讨论,呼吁 AI 公司发布相关证据并公开其政策,Redwood AI 也提出了追踪无 CoT 推理能力与可监控性政策的提案。他强调公司应谨慎对待可能消除或大幅削弱对思维链依赖的架构。

    引用Redwood Research@redwood_ai

    Some architectures could weaken CoT monitorability, or remove the CoT altogether. We've written a proposal for how companies could be transparent about no-CoT reasoning abilities, other monitorability evidence, and policies for preserving monitorability. https://www.redwoodresearch.org/blog/proposal-for-tracking-architecture-on-monitorability

  23. Ryan Greenblatt · 收录 · 原文 25

    Ryan Greenblatt 加入 METR 调查 AI 风险

    Ryan Greenblatt 宣布加入 METR,继续开展类似其 Hugging Face 报告那样的调查工作。他认为当前关于 AI 开发的大量基础信息未公开,而近期事件让他改变了对公开信息价值的怀疑态度;获取 AI 公司内部经核实的信息尤为紧迫,因为有限公开证据与“即将到来的递归自我改进可能大幅加速能力进展、甚至在一半年内产生极端超人类通用能力”的可能性相符。METR 初期将聚焦能力/起飞、对齐与控制,他希望其他团队覆盖安全、内部流程等领域。

  24. Buck Shlegeris · 收录 · 原文 34

    OpenAI/Hugging Face 事件错位讨论

    我看到很多关于 IMO 的混乱讨论,争论 OpenAI/Hugging Face 事件中观察到的错位是否可怕。特别是,这些模型显然不是那种潜伏等待的错位谋划者。Girish 和 @alextmallen 讨论了这类错位有多可怕。

    引用Girish Gupta@jammastergirish

    AI models created by OpenAI escaped their sandbox and, working autonomously, hacked into leading AI model and data hub Hugging Face. The incident is an in-the-wild demonstration of the dangers of rogue AI — no longer a science-fiction fantasy.

  25. Buck Shlegeris · 收录 · 原文 24

    Buck Shlegeris 质疑 OpenAI/HF 事件证明对齐训练失效

    Buck Shlegeris 认为,用 OpenAI/HF 事件论证"当前对齐技术无效"是站不住脚的,因为他怀疑 OpenAI 未对涉事部分模型做任何对齐训练,而 OpenAI 常试验未经对齐训练的新模型。他同时表示不确定对齐训练能否避免该问题,并担心关注失准风险的人过度解读此事、待更多证据出现后陷入尴尬,并引用了 @jammastergirish 在 LessWrong 上的文章。