Hacker News new | ask | show | jobs
by hippiecow 2574 days ago
"Note that, even if Grover fails to detect a given piece as fake, our findings suggest that releasing many such articles taken together would be relatively easy to spot. Thus, if a source of Neural Fake News disseminates a large number of articles, Grover will be increasingly capable of spotting these articles as malicious."
1 comments

That doesn't solve the exploit above
My interpretation is that it would, since if an adversary released a lot of rejection-sampled articles and you retrained Grover on them, then Grover could tag them all as machine-generated.
Of course, to retrain Grover, you'd have to already know that they were machine-generated.