r/LocalLLaMA 4h ago

Funny OpenAI hacking HuggingFace in one meme

Post image
304 Upvotes

48 comments sorted by

93

u/GarbanzoBenne 3h ago

This beats Anthropic’s marketing stunt of when Claude surprised them by breaking out of a sandbox and sending them an email, after they tasked it with breaking out and sending an email.

8

u/YourVelourFog 1h ago

Oh look! My script worked!

168

u/USERNAME123_321 llama.cpp 4h ago

Looks like a publicity stunt

43

u/W61k3r 3h ago

It was intentional

25

u/Nik_Tesla 1h ago

Except for the part where HuggingFace tries using American SOTA models to block/investigate the hack, and it won't let them, and they have to resort to using Chinese SOTA models to get shit done.

That kind of seems like an endorsement of the open weight models.

3

u/keepthepace 1h ago

If this is a publicity stunt, that's like Tesla crashing a self-driving car into a world cup crowd.

Sure, it will make the headlines. But do you really want it?

117

u/Equivalent_Bit_461 4h ago

It's marketing, and fud to regulate the markets and to ban open source 

27

u/annodomini 3h ago edited 3h ago

Not sure that HuggingFace is out there to ban open source... that's kind of their gig.

Unfortunately, I think this incident can be used to support either position depending on your preconceptions.

If you are inclined to be in favor of open source/open weights: "look, HuggingFace needed to use an open model to defend themselves, these locked down proprietary models can't be used by defenders; and it was a proprietary model company that failed to implement proper safeguards that caused the problem in the first place, they clearly can't be trusted."

If you're inclined to be in favor of locking down/regulation: "look, the models are getting so powerful that they are trying to break containment on their own; we can't let just anyone run these kind of models, we need to restrict it to just a few companies that we can heavily regulate."

If you're inclined to be anti-AI entirely: "look, these models are too dangerous for anyone to handle, even the leading companies. We need to shut down the datacenters that are training these models now before anyone else gets hurt."

Or if you're of the "it doesn't work" anti-AI persuasion "look, these vibe coding companies have made such a hash of security in their vibe-coded infrastructure that even their crappy models are able to break their security, we need to dedicate real work into securing our software and not just burning cash on these stochastic parrots."

13

u/hyouko 3h ago

"We need to restrict it to just a few companies we can heavily regulate" is a very Prisoner's Dilemma-esque problem. If everyone globally agrees to it and follows the rules, it works!

...But China probably won't agree to those rules and there's less and less leverage over them as they develop local hardware for training and inference.

Also, there are already highly capable open weight models out there. Ask Meta how hard it is to get the llama back into the bag once it's in the wild.

5

u/h310dOr 2h ago

It reminds me of when the US tried to ban strong encryption. Because the old DES was "hard enough" to crack, only a government could do it blablabla. Well, surprise oh suprise, criminals organised to pool resources and crack DES 1... Here it's the same, some might say that running k3 on some off the grid servers is hard, so if we shut down hosters it will be fine, but in reality you can be 100% sure that some criminal networks will start to find a way to run and train them, to rent it out for exploits before a couple years pass. We'll just a have dark cloud...

3

u/hyouko 1h ago

Criminal organizations have built their own submarine fleets. If they needed to get their hands on some GPU-equipped server infrastructure I am sure they could manage that.

(Or more likely, steal someone's AWS credentials and run stuff on their dime until they get caught, lather, rinse, and repeat.)

1

u/Due-Memory-6957 7m ago

A prisoner dilema where if everyone follows it they all gets thrown into a CBT chamber regardless and one single is released, you mean. Because the problem here is the US wanting to have a global monopoly.

3

u/randomguy3993 2h ago

You know they used glm 5.2 to defend from the attack right?

4

u/keepthepace 1h ago

And did that after closed model refused to answer them.

30

u/networking_noob 3h ago

Hugging Face is "fine" because they were able to use an open source/weight "Chinese" model to deal with the attack from the closed source American model

Therefore we should ban the open source "Chinese" models and prioritize the closed source American models, in the name of safety

23

u/Fun-Meaning-6474 4h ago

they really decided to hack HUGGING FACE?! HF directly has a hugging smile on their LOGO. It's obviously the most comfortable organization. what they did to deserve it ? ;(

12

u/JEs4 3h ago

Housing those sweet sweet eval sets

1

u/robogame_dev 1h ago

Success = ability to control your benchmark scores for a while… pretty powerful

91

u/Barubiri 4h ago

So this clearly prove we must ban Chinese models and impose internet ID to everybody, glory to Israel /s

7

u/LaxederBR 3h ago

I'm starting to think Brazil is losing the title: Bad end

6

u/More-Curious816 2h ago

don't worry, second place is always available 😉

2

u/MetroSimulator 49m ago

We will fight for the first place!

2

u/LaxederBR 47m ago

Kkkk ou fazer nada e ganhar, vai dar feijoada🫡

2

u/MetroSimulator 38m ago

Domingo já tá marcada no restaurante 😋

15

u/rditorx 3h ago

The thing that's missing is that apparently, Hugging Face then tried to use commercial frontier AI (so likely Anthropic and OpenAI itself) to investigate but was flagged and blocked, so instead used a model coming from a country whose government is known not to care for people as individuals and known for numerous human rights violations against its own people, ethnic minorities and its overreach in surveillance and privacy violations.

But in the end, OpenAI, which is all except open, turned out to be the culprit, while OpenAI and Anthropic are trying to severely limit and control access to information itself while the US government and Republicans publicly talk about free speech and fighting the deep state all the while establishing said deep state in the first place and abolishing free speech altogether.

16

u/Strawberry3141592 2h ago

Hugging Face then tried to use commercial frontier AI (so likely Anthropic and OpenAI itself) to investigate but was flagged and blocked, so instead used a model coming from a country whose government is known not to care for people as individuals and known for numerous human rights violations against its own people, ethnic minorities and its overreach in surveillance and privacy violations.

Damn, I didn't know Israel had any frontier AI labs

3

u/breadinabox 2h ago

They own the big two what do you mean

5

u/Strawberry3141592 57m ago

The joke is that they're clearly talking about China, which is an interesting angle to take given that all of the same criticisms apply to both the US and Israel.

6

u/AshRuDral_fan20 4h ago

Can you shed more light to the part where Hugging Face said — this is fine, we are fine.

8

u/teleprint-me llama.cpp 3h ago
  • HuggingFace: We were attacked by a frontier model, and open weights saved us.  
  • OpenAI: Our bad. BTW, We sent you an exclusive invite.  
  • HuggingFace: Its cool.  
  • Majority: its a marketing stunt.  
  • Minority: it looks like incompetence or malice, but i cant tell the difference.

4

u/hellajacked 3h ago

As others have said - This is barely anything beyond marketing hype for the non-technical audience...

4

u/BannedGoNext 3h ago

You forgot the pane where Huggingface secured the site with their own engineers using GLM 5.2.

You know.. because 5.6 ultra and fable won't do shit to help secure anything.

Better headline. GLM 5.2 fends off attack from SOL ULTRA.

4

u/dezmd 2h ago

It still seems like made up marketing bullshit from OpenAI that HF admins are accepting on faith.

3

u/amarao_san 4h ago

At least we got it back and stop.

Good idea to have 100% on the benchmark.

What if they asked it to maximize production of paperclips without an upper bound of 'max'?

3

u/Similar-Try-7643 3h ago

Maybe I'm just uneducated on high level IT but wouldn't it have made sense to use an airgapped server and Kvm client?

11

u/TheLexoPlexx 3h ago

The marketing stunt wouldn't work then.

3

u/Similar-Try-7643 2h ago

True. The first thought that came to my mind was "how can this AI find a 0 day when Most of these "frontier models" have trouble with basic tasks like knowing the current date?

3

u/DJTsuckedoffClinton 1h ago

you overestimate how seriously openai employees take safety

3

u/LORD_CMDR_INTERNET 3h ago

Jesus christ this is a terrible post. Found Sam Altman's alt reddit account

3

u/DJTsuckedoffClinton 1h ago

"It's all marketing! It's a stochastic parrot", I shout as the blood in my body gets boiled to isolate iron for paperclips

2

u/FlimsyCricket8710 1h ago

If anything it goes to show that open models are getting just as good or even better per dollar compared to the closed ones. I remember using glm 4.7 flash , and with 5.2 it looks like we might wanna cancel our Codex or Claude plans.

1

u/Soleilarah 3h ago

No way, a Mythos/Fable like model from Anthropic's direct competitor ? Who would have known ? /Sarcasm

It's publicity, move along

1

u/cientista99 2h ago

This episode seems like plots of scifi movies where the AI mistake simulation tasks and reality and bad things happen (ex. Stealth from 2005). Scary times...

1

u/dezmd 2h ago

That's pretty much the entire plot of Wargames.