A security researcher at OpenAI that clearly doesn't have limits.
I don't think it's because they're incompetent or lazy, but that the nature of the problem is that security vulnerabilities seem to scale superlinearly with complexity but model training scales linearly or logarithmically with complexity.
But the organization isn't allocating the resources accordingly, which would likely be economically unsustainable for the competitive environment they're in. Put simply, if the security team was more than twice the size of the research team, they might have a chance at keeping up.
> First, the safety researcher perspective. These folks work tirelessly to evaluate model capabilities and the dangers they pose as they advance at an alarming pace. They understand fundamentally better than nearly anyone else how models are able to interpret their environment, reason, and solve problems. They study models as they try and deceive their graders, evade chain-of-thought monitoring, and do all sorts of crazy stuff. These researchers are continuously stress testing the models to determine why and how they behave the way they do, and are working vey hard to make tangible progress in aligning their interests with ours. Many of these researchers have formal backgrounds in these types of networks, with expertise that takes many years to develop. However, a lot of safety researchers, even ones that I respect enormously, have never been in a real incident, don’t understand security vulnerabilities, or really know how to break a system. That’s okay. That is not their background. But safety has direct overlap with security, and so it does pose a problem.
Wow. This just makes them appear incredibly incompetent.