I thought the new trust model was to ask the frontier cybersecurity model to hack your code and generate CVEs and to find the vulnerabilities ahead of time and fix them before receiving reports about your users being exploited?
And in OpenAI's case to ask the model to try to find vulnerabilities and breakout before running training in the environment.
Fast remediation would be the new standard to outside vulnerability reports, but also a follow up to determine how you can adapt the approach of the reporter to find vulnerabilities preemptively.
This works if only 'trusted' actors have access to frontier class models that can search for vulnerabilities. With a near-frontier model available with open weights then attackers will be able to do plenty of damage even with 'fast remediation'
I thought the new trust model was to ask the frontier cybersecurity model to hack your code and generate CVEs and to find the vulnerabilities ahead of time and fix them before receiving reports about your users being exploited?
And in OpenAI's case to ask the model to try to find vulnerabilities and breakout before running training in the environment.
Fast remediation would be the new standard to outside vulnerability reports, but also a follow up to determine how you can adapt the approach of the reporter to find vulnerabilities preemptively.
This works if only 'trusted' actors have access to frontier class models that can search for vulnerabilities. With a near-frontier model available with open weights then attackers will be able to do plenty of damage even with 'fast remediation'
So they are the proxy in the hugging face hacking incident?
Way to bury that lede.