> Apple alleges that Liu ran a simulation in March using the circuit schematic file in LTspice, an electrical engineering tool. In messages from around that time, Liu said his AI “agent” learned to run LTspice and review the results.
"I didn't steal it, I fed it to an agent who then fed it back to me".
> Apple argues that when trade secret information is fed into an AI agent or model that learns from it, that learning “may create irreversible and continually propagating uses of the trade secret.
Has anyone seen Pandora? I want to have a look inside that box she's been carrying around...it's time we start suing the pants off this "generative" stuff...
- Mr. Liu not only downloaded a confidential Apple circuit schematic but also used it in his work at OpenAI;
- Far from his unauthorized access to Apple’s third-party cloud storage being unknown to him, Mr. Liu and others at OpenAI were well-aware of that access;
- Mr. Liu, upon learning of Apple’s internal investigation of him, sent instructions for destroying evidence to an OpenAI colleague who confirmed she would comply; and
- Mr. Liu used a tool in his work at OpenAI that has the same name as an internal Apple engineering application used for Apple development work.
Good lord. Smart people doing the dumbest things with their work equipment.
I have a former coworker who was the VP of Finance at my company. He suddenly got fired out of the blue. The company was in the midst of trying to find a buyer (this was announced) so this was extra surprising. Turns out, he knew a lot of bad news about the company, and they caught him looking for a job. They fired him because he was too much of a liability.
How did they catch him? He was putting resumes and cover letters on OneDrive. "Yeah, in retrospect, that's one of the dumber things I've ever done," he said to me later.
> Apple argues that when trade secret information is fed into an AI agent or model that learns from it, that learning “may create irreversible and continually propagating uses of the trade secret.”
This is somewhat of a high impact argument to test. I wonder if the case will eventually get to working this point out.
There's already some precedent when dealing with humans reverse engineering systems. We use "cleanroom" approaches where the ones doing the reverse engineering are segregated from those doing the later design and development work. Instead of producing a design document based on the thing being studied, the reverse engineers produce a specification from which a new design, untainted by knowledge of the original design, is produced.
People using ML to try and reverse-engineer and create a "clean" version of things will likely need to use a similar approach. You can't ask one LLM to take in a circuit design as input and produce a specification and design within the same context. The resulting design will be at least partially informed by knowledge of the original design. The way to do this safely (potentially still with suits happening, but safer at least) will be to have one execution to produce a specification, and a second fresh execution taking the specification to produce a design. At least then you know your LLM was not aware of the original design.
Of course, LLM agents "cheat", so you'll also want to be careful to ensure a clean environment if you're using an agent that does not provide access to the original design material.
If the LLM designs the circuit, it is clear "contamination" if the tool calls which wrote the RTL / Verilog are also in the same context window as the specification design.
If a windows DLL, distributed without a license that says anything regarding, is it a "clean room implementation" if there is some nonzero chance the source code was leaked into the weights at pre-train time? I guess there should be some sort of method for subpoenaing frontier labs to ask "can you grep for this code in the training set for this model", but that might not be practical or feasible.
> If the LLM designs the circuit, it is clear "contamination" if the tool calls which wrote the RTL / Verilog are also in the same context window as the specification design.
You can't ensure it properly segregates its knowledge so it's a legal risk. If you believe your LLM can generate a design from a spec without knowledge of the original, why would you take that unnecessary risk? A lot of the behavior in this area is meant to avoid the appearance of impropriety, because the appearance of impropriety forces you to defend and demonstrate there was none.
If you isolate the two behaviors (reverse engineer design to spec; convert spec to new design) then you have a legal defense. You can claim that any coincidentally too similar design elements are a consequence of standard design patterns or something, not a consequence of inherent knowledge of the original design.
This is why we separate the people into distinct roles, there's no reason not to do the same (or expect the same) with machines. If you don't want the legal cover, of course, by all means take the risk and enjoy a trillion dollar company taking you to court.
> Additionally, Apple learned about Liu’s use of the schematic because he used it on a Mac mini which later synced via iCloud to the MacBook he took from Apple. Apple now also wants access to that Mac mini.
I'm very curious about the privacy implications of this. I know that anything I do and store on my company's laptop can be tracked, but I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information.
The files syncing to the company laptop's disk is a layer of nuance that makes this situation tricky to evaluate.
> I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information
I don't think this is true, this would still be unauthorized access on your employer's end and would be considered illegal. They're not allowed to pose as you to access your services iirc.
You shouldn't obviously still sign out (or never sign in in the first place) of course!
Reminds me of the story of an ex-Coca-Cola employee who offered to sell the secret recipe to Pepsi. Pepsi immediately let Coca-Cola know and it was handled. Not a good look for OpenAI. They come off as desperate and unprofessional.
Funny to imagine that food scientists at these companies must have cracked these recipes decades ago, and the secrecy might now only serve as a loyalty test for the uninitiated in the food and beverage guild.
That's because pepsi already had coca-cola's secret recipe. I'm sure if they didn't have it already they would have been more than happy to at least have some knowledge before reporting it, but not like they didn't have the talent, money or technology to reverse engineer it at least a decade ago at that point.
No, it's because Pepsi isn't trying to be Coke, they're trying to be better than Coke. So having the recipe is kind of moot.
Even if they were to take the recipe and publish it for all to see, you would still need all of the other machinery that is Coca-Cola to make Coca-Cola.
And then you have issues of quality. Coca-Cola has certain standards, it's not a guarantee that everyone else will have those same standards. Like, people buy the expensive brand of milk despite all milk being the same. It's one ingredient. With quality standards given by the government. There is really no room for interpretation.
Is this an AI response? coca-cola was replicated by one guy and confirmed in blind taste test by several other people, no magical machinery needed to make it once you know the ingredients.
What about quality? That has nothing to do with it.
Of course they're trying to be the better coke, that's why they tried making coke with the same color with more sugar and made the flavors stronger.
Not really OpenAI but today's society. I say this started with the "just do it and ask for forgiveness later" attitude that started maybe 20 or 30 years ago.
At one time most people had respect, even people at the top, now many people just do what they want. Plus most of the time they get away with it.
is what the entire LLM industry is based on. They swallowed up all of society’s copyrighted texts without really asking for permission from anyone. This is just par for the course for them it seems unfortunately.
> Peer pressure and community sanctions of bad actors will result in the changes we need.
It's been demonstrated over centuries that this is unreliable. We end up needing a third party (commonly governments) to step in and establish rules and referee behavior. We wouldn't have an EPA, FCC, SEC, or many other organizations and laws if private actors could successfully police themselves.
Private actors are inevitably part of groups. Those groups need to hold the individual members accountable. That obviously doesn't work any more in SV among wealth-obsessed tech-bros. It still works in other parts of the economy though.
Happened at a (large) company I worked for in the past. A devops guy stole the DB ahead of going to work with a rival, he was caught and the rival of course wanted nothing to do with it. I'm not sure of his fate but it couldn't have been much fun.
A mature organization does not want the liability and if contacted by previous employer with evidence of these kinds of allegations, immediately gives said employees the boot.
Happens occasionally at big corporations, even the bloodsucking vampire. Best to distance yourself from such employees - lest they will do to you what they have done to others.
The difference is, relative to OpenAi they have standards and morals.
One of the things I always told kids who came into these big trading firms is the owner(s) is/are a billionaire, and likely came up from one of the trading floors or something adjacent. They are not the “forgiving” types when it comes to shit like this, and they have infinitely more resources than you.
So maybe don’t try to steal code, or trade concepts.
Hasn’t stopped some people I know from trying…
(For clarification I am not ex-CitSec and do not know this poor SOB, but he serves as the perfect poster child for “Don’t do that”)
> Apple argues that when trade secret information is fed into an AI agent or model that learns from it, that learning "may create irreversible and continually propagating uses of the trade secret."
Yes. Yes, please make this argument, Apple. Some fascinating other conclusions follow from this.
"I didn't steal it, I fed it to an agent who then fed it back to me".
> Apple argues that when trade secret information is fed into an AI agent or model that learns from it, that learning “may create irreversible and continually propagating uses of the trade secret.
Ok I'm hooked
<gets out popcorn>
- Mr. Liu not only downloaded a confidential Apple circuit schematic but also used it in his work at OpenAI;
- Far from his unauthorized access to Apple’s third-party cloud storage being unknown to him, Mr. Liu and others at OpenAI were well-aware of that access;
- Mr. Liu, upon learning of Apple’s internal investigation of him, sent instructions for destroying evidence to an OpenAI colleague who confirmed she would comply; and
- Mr. Liu used a tool in his work at OpenAI that has the same name as an internal Apple engineering application used for Apple development work.
I have a former coworker who was the VP of Finance at my company. He suddenly got fired out of the blue. The company was in the midst of trying to find a buyer (this was announced) so this was extra surprising. Turns out, he knew a lot of bad news about the company, and they caught him looking for a job. They fired him because he was too much of a liability.
How did they catch him? He was putting resumes and cover letters on OneDrive. "Yeah, in retrospect, that's one of the dumber things I've ever done," he said to me later.
This is somewhat of a high impact argument to test. I wonder if the case will eventually get to working this point out.
People using ML to try and reverse-engineer and create a "clean" version of things will likely need to use a similar approach. You can't ask one LLM to take in a circuit design as input and produce a specification and design within the same context. The resulting design will be at least partially informed by knowledge of the original design. The way to do this safely (potentially still with suits happening, but safer at least) will be to have one execution to produce a specification, and a second fresh execution taking the specification to produce a design. At least then you know your LLM was not aware of the original design.
Of course, LLM agents "cheat", so you'll also want to be careful to ensure a clean environment if you're using an agent that does not provide access to the original design material.
If the LLM designs the circuit, it is clear "contamination" if the tool calls which wrote the RTL / Verilog are also in the same context window as the specification design.
If a windows DLL, distributed without a license that says anything regarding, is it a "clean room implementation" if there is some nonzero chance the source code was leaked into the weights at pre-train time? I guess there should be some sort of method for subpoenaing frontier labs to ask "can you grep for this code in the training set for this model", but that might not be practical or feasible.
You can't ensure it properly segregates its knowledge so it's a legal risk. If you believe your LLM can generate a design from a spec without knowledge of the original, why would you take that unnecessary risk? A lot of the behavior in this area is meant to avoid the appearance of impropriety, because the appearance of impropriety forces you to defend and demonstrate there was none.
If you isolate the two behaviors (reverse engineer design to spec; convert spec to new design) then you have a legal defense. You can claim that any coincidentally too similar design elements are a consequence of standard design patterns or something, not a consequence of inherent knowledge of the original design.
This is why we separate the people into distinct roles, there's no reason not to do the same (or expect the same) with machines. If you don't want the legal cover, of course, by all means take the risk and enjoy a trillion dollar company taking you to court.
I'm very curious about the privacy implications of this. I know that anything I do and store on my company's laptop can be tracked, but I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information.
The files syncing to the company laptop's disk is a layer of nuance that makes this situation tricky to evaluate.
Never, ever, ever sign into personal mail/messaging on work machines. Even the appearance of having done so just sets up for bad things.
This was kinda iffy 20 years ago, now its crazy to do. We all have phones now, there's no good reason to do this.
I don't think this is true, this would still be unauthorized access on your employer's end and would be considered illegal. They're not allowed to pose as you to access your services iirc.
You shouldn't obviously still sign out (or never sign in in the first place) of course!
Even if they were to take the recipe and publish it for all to see, you would still need all of the other machinery that is Coca-Cola to make Coca-Cola.
And then you have issues of quality. Coca-Cola has certain standards, it's not a guarantee that everyone else will have those same standards. Like, people buy the expensive brand of milk despite all milk being the same. It's one ingredient. With quality standards given by the government. There is really no room for interpretation.
What about quality? That has nothing to do with it.
Of course they're trying to be the better coke, that's why they tried making coke with the same color with more sugar and made the flavors stronger.
At one time most people had respect, even people at the top, now many people just do what they want. Plus most of the time they get away with it.
"just do it and ask for forgiveness later"
is what the entire LLM industry is based on. They swallowed up all of society’s copyrighted texts without really asking for permission from anyone. This is just par for the course for them it seems unfortunately.
IP theft can really pay off.
It's been demonstrated over centuries that this is unreliable. We end up needing a third party (commonly governments) to step in and establish rules and referee behavior. We wouldn't have an EPA, FCC, SEC, or many other organizations and laws if private actors could successfully police themselves.
The key difference here seems to be that OpenAI very much wants something to do with it.
The difference is, relative to OpenAi they have standards and morals.
https://www.businessinsider.com/yihao-ben-pu-citadel-2011-11
So maybe don’t try to steal code, or trade concepts.
Hasn’t stopped some people I know from trying…
(For clarification I am not ex-CitSec and do not know this poor SOB, but he serves as the perfect poster child for “Don’t do that”)
Yes. Yes, please make this argument, Apple. Some fascinating other conclusions follow from this.