Hacker News new | ask | show | jobs
by CM30 5 days ago
It's also not trivial to tell if an open source project has had malicious code added. It might be a bit easier than to tell if there's malicious code than if the weights in a model were poisoned, but for 99% of users, you're going on pure trust in both cases.

And in both cases, even this seems better than relying on a closed source, service only solution where the same issues could be completely undetectable (at least without way more analysis)

1 comments

> going on pure trust

The trust in open source software is founded on the process which involves people being able to understand the code given they have the right expertise. I don't see how this process works with open weights.

Trust shifts to the producer of the open weight model, based on the global communicated experience of all models they’ve ever produced.
This doesn't make any sense! Arguing for the sake of arguing.

Why is Windows not open source then, where we can trust Microsoft based on the experience with previous Windows versions?