Hacker News new | ask | show | jobs
by fidotron 3 days ago
You have to wonder if any of these models, from any providers or countries, are set up to lie. i.e. tell you no vulnerabilities while quietly siphoning off the ones they do find into a database.

Yet another reason that self hosted will prove to be the only sane way forward, and it'a almost certainly necessary to have multiple different model providers working adversarially.

4 comments

Some PRC models are backdoored to silently insert extra vulnerabilities when certain conditions are met - https://www.boozallen.com/expertise/cybersecurity/whats-in-a...

And that's just the model behavior. The provider itself can do whatever. Given the PRC's public record of prolific IP theft, the default assumption is that they're taking everything you send to one of their APIs.

Anyone have suggestions for poisoning their data?

Booz Allen is cute, but if china can train K3 on a fraction of the US compute availability, yet it benchmarks almost equivalent to Fable for a third of the cost, it’s game over for US labs in the long run.

Believe me, I wish this wasn’t the case, but open up the hardware on the device you are reading this on and tell me the majority of tech inside wasn’t made in China….

Manufacturing was lost a long time ago, this is really just another way

> if china can train K3 on a fraction of the US compute availability, yet it benchmarks almost equivalent to Fable for a third of the cost, it’s game over for US labs in the long run.

I agree. However, as of yet, most/all leading PRC models are distilled from US models. I've personally observed Deepseek, GLM, and Kimi all respond that they are Claude when asked, and the networks of tens of thousands of proxy accounts that we've found show that it's happening on a large scale.

But - if the PRC labs actually train up the domain expertise to train those models from scratch, which they are in the process of doing - then the US is cooked. They're not there yet, but it's probably only a matter of years.

Playing devils advocate, does from scratch really matter if all frontier labs are training off each other anyways? Practically speaking, businesses/consumers just care about lowest inference cost for maximizing intelligence anyways (not to mention Anthropic/OpenAI forcing KYC/litigation barrier trash for access to any cybersecurity/IT capabilities) that I literally just cancelled Claude today.

Yeah it’s sad the CCP has my information. But it’s either them or the feds, and at least Chinese models actually work for cybersecurity tasks, not to mention aren’t stupid expensive

Artificialanalysis.ai rn on opus 5 is a joke. The main intelligence benchmarks it is like 1% better than Fable, but the cost difference between that and K3 is so funny lol. It’s the same with cars— you don’t have to do it from scratch, as long as you can do it cheaper and with the same quality, hence Toyota/Honda taking over

Yeah it’s sad that American models are censored more than Chinese ones lol (outside of asking them about the CCP) but it’s where we are at I guess :(

Assuming the providers are compromised (and I agree that some of them probably are) then I doubt the angle taken will be to poison the product. That kind of thing usually gets noticed eventually.

A more likely scenario is to focus on the model users as potential victims, e.g. by logging internal infrastructure descriptions, capturing private access tokens from chats, etc. That is very deniable, because it's hard to prove where the compromised data originated.

Of course, I'm not claiming PRC is a friend of the world. And I agree with your last point, however I don't think it's feasible to self-host Kimi-3 sized inference.
Self-hosted local models can't become viable soon enough... Currently they require hundreds of thousands of dollars if not millions in capital. That needs to change!