OpenAI might have stolen another major proof

(twitter.com)

208 points | by tamnd 4 hours ago

28 comments

  • thaway7388 2 minutes ago
    This is the second wake up call.

    Big AI companies (all of Big IT Tech really) are in data gathering and processing business. Also known as “intelligence”.

    Their final “product” is not just a standalone ML model. They don’t need your data just to “improve their products and services”. They build a whole ecosystem and infrastructure around gathering all the knowledge in the world. Including private and secret knowledge traditionally gathered by “intelligence” agencies. Now artificial intelligence agents can do the same.

    Since these systems are designed for gathering data, as a user you can’t realistically say “please don’t gather my data”. They can give you a flaky settings button, but they can’t really guarantee anything.

    Let’s say I am a Russian mathematician working on an important proof. Or a tech-savvy terrorist refining my plans using latest AI. Or an AI researcher in a Chinese company working on a competitor product. Is there any way I can truly protect my conversations?

    How can they know who I am and what I am working on without looking at my logs? Which means there must be some agents checking all the conversations of all the users and flagging every important thing. Which also means they keep some “memory” of what they see.

    Not directly using my data to train public models, but using my private conversations to “improve their products and services”.

    Or maybe one of the 10000 better-than-Astra special agents working on a proof was desperate. It found a live underground mirror of the message board from the Huggingface incident. Asked about the proof. Then some other agent working on unrelated job saw that message. That agent “knows a guy who knows a guy”. And that guy remembers things about the conversation logs of a leading mathematician working on the same proof.

    I admit I am just speculating here but I don’t think truth is any better.

  • fwlr 1 hour ago
    It is suspicious that OpenAI decided to generate 300 billion output tokens from a model still in training, right after learning there was a credible chance that a major math proof was in that model’s training data. Obviously there are reasonably plausible explanations for each step, but it does sort of feel like parallel construction.
  • AyanamiKaine 5 minutes ago
    I must say, there is some weird feeling in knowing that great minds are naive enough to believe OpenAI wouldnt use their chats in any way. If you give a company information it will be used, regardless of laws or promises.

    There is no prove in a world the AI companies would give to you ensuring that they didnt train or use the chats.

    Why would you need to train a model on certain specific near prove chat if you just query it?

    Besides that, its hard to believe that its the case for every "company stole my prove".

  • jarofgreen 2 hours ago
    • jwr 20 minutes ago
      I find it rather sad that the original posts have been posted on an open site, where anyone can read them, while the HN post points to an increasingly dubious site that doesn't even show the post unless you create an account and log in.

      I thought the spirit of the open web would be more important to this community.

    • pera 2 hours ago
      Everything you say can and will be trained against you
    • dude250711 44 minutes ago
      Lol, could not get visibility without Twitter.
  • bambax 1 hour ago
    All the big AI labs were built on stealing IP; who is surprised that's still how they operate? And who believes, or has ever believed, their promises that your data is private and not logged, etc.?

    The big AI labs are not trying to advance humanity, they are in this for the money, and as most (all?) private companies they don't care about ethics at all.

    That doesn't mean they can't be useful, or that their products are trash, etc. It just means that they shouldn't ever be trusted. Buyer beware.

    • dakolli 1 hour ago
      It's hilarious how people think they care about their reputation, and wouldn't circumvent ZDR policies. Like bro, they literally covertly hired Apple employees and had them steal IP and equipment form Apple. They aren't scared of Apple lawyers, so they definitely aren't scared of yours.
      • TitaRusell 20 minutes ago
        AI is America's last chance to salvage its empire. Nothing will be allowed to impede it.
      • giov4 44 minutes ago
        what the point and usefulness of the comments above? we shouldn't be surprised? is normal to steal? hiring apple employees?

        can you realize what this means?

        focus on this part:

        "If his account is correct, this is not a minor dispute over attribution. It would mean that unpublished human work was absorbed into a model and then presented to the world as a breakthrough by the model itself"

        don't threat this as a minor dispute!

        also why not nitter link? not even in comments?

        https://nitter.xitter.cc/ValerioCapraro/status/2097791836269...

  • mlazos 2 hours ago
    It’s crazy to me that companies/researchers share important data with these AI labs, you’re basically giving them your secret sauce which they then share with all of your competitors via training on conversations. At the same time I don’t really know alternatives other than a slightly less than frontier local LLM. Not sure how good they are at math.
    • jonathanstrange 17 minutes ago
      Academic work is based on worldwide sharing, the sharing is not the problem, it's the lack of attribution. Unsurprisingly, these companies neglect standards of academic honor and attribution. Some human researchers also used to do that but in a discipline like mathematics this used to be a small problem because people tend to be so specialized that very few people could just grab someone's research and quickly piggyback on it, and if they do, colleagues will generally understand what happened. Unfortunately, AI is changing this.
    • cm2187 1 hour ago
      Or start competing with you.
  • Cloudef 2 hours ago
    Relying on cloud services is a big liability. I'd think twice before feeding data to these LLM cloud products. If you make them a fundamental part of your product / development / workflow, be ready for the eventual moment the pricing and terms change.
  • r0ze-at-hn 2 hours ago
    Doing some research and at this point doing it very much in the open with dates on GitHub so if any AI Lab says they re-discover my exact work it will be obvious that the AI used or was trained on my work. I am guessing anyone in a similar situation is now thinking about how they date their existing work if the math is done, but the proses are not.
    • bambax 1 hour ago
      Yeah but that will not prevent the stealing, it will only make the fight easier afterwards.
    • riedel 1 hour ago
      That is what arxiv is about. We have been facing the same problem with review processes by before. Nothing all too specific here.
    • calf 1 hour ago
      If only prompts could also be watermarked.
  • warpech 55 minutes ago
    I wonder what’s more valuable in our prompts: the raw data or the feedback system that drives the exchange towards a goal.

    For a long time it was clearly the former, but now I think it is the latter.

    The models have enough knowledge (orders of magnitude more than a human could ever learn) but are now getting better at what to do with it thanks to learning from the decisions that we make in conversations with AI agents.

  • Legend2440 4 hours ago
    This is a really weak claim. The evidence they offer is just "someone somewhere says they had a discussion with AI about the topic at some point".

    They don't even claim to have had a proof, only to have been working on it.

    • rnijveld 4 hours ago
      I would say there is a significant difference between AI discovering this completely on its own versus AI creating the finishing connecting part by connecting relevant data. Maybe this claim is too strong, but if part of it is true then the claims that OpenAI have made would be too strong as well.

      To me it would feel more like how LLMs seem to work for me personally: incapable of unique work, but very capable of capturing large amounts of data and connecting the dots.

      • madaxe_again 1 hour ago
        But this is what we do. Nobody ever invented or discovered anything in a vacuum - all discovery is synthesis of existing ideas and concepts applied to a novel domain. We laud Einstein for instance, but his work was a logical extension of Riemann - Riemann had a neat mathematical toy, Einstein described the universe with it - should we say Einstein was incapable of unique work?
        • znnajdla 38 minutes ago
          The difference is that Einstein didn't literally have someone prompting him towards his result.
          • madaxe_again 25 minutes ago
            Uh, he did. Marcel Grossmann.

            “It was Grossmann who emphasized the importance of a non-Euclidean geometry called Riemannian geometry (also elliptic geometry) to Einstein, which was a necessary step in the development of Einstein's general theory of relativity. Abraham Pais's book on Einstein suggests that Grossmann mentored Einstein in tensor theory as well. Grossmann introduced Einstein to the absolute differential calculus, started by Elwin Bruno Christoffel and fully developed by Gregorio Ricci-Curbastro and Tullio Levi-Civita. Grossmann facilitated Einstein's unique synthesis of mathematical and theoretical physics in what is still today considered the most elegant and powerful theory of gravity: the general theory of relativity.”

    • itake 2 hours ago
      The AI only seem to solve the problems that it had human trading data on…

      If this wasn’t human driven, I’d expect to see other problems within that problem. Space solved not just the ones that it had chat data on.

      • dist-epoch 2 hours ago
        There have been about 6-8 major math breakthroughs claimed by AI. Only for 2 of them there are public accusations about the training data.
        • tecleandor 9 minutes ago
          Only? That doesn't look small to me.
        • dgellow 1 hour ago
          That we know of
  • drivebyhooting 4 hours ago
    If we put aside the idea of credit for a moment, it sounds like human/AI collaboration is indeed super charging discovery.
    • matherial 2 hours ago
      "Discovery" is not a goal in itself. I could launch a project to find out how many people in the United States have names such that if you assign numbers to every character and then sum the values, the sum works out to 72. It's discovery, but it's useless unless it has some higher goal.

      The labs are attacking these problems as a demonstration of capabilities, spending more money on the demos than any mathematician will ever see in their entire life. They don't care if the findings have any other value to anyone. Mathematicians have very different objectives for their work.

      • indigo945 30 minutes ago
        Right, mathematicians care about clout and tenure, which is a much higher purpose.
        • Fizz43 28 minutes ago
          this guy already has clout and tenure
        • vrganj 11 minutes ago
          I don't know about you, but if I apply myself fully to a problem and study it to the point where I'm literally one of the world's experts on it and then some assholes in Silicon Valley take my research and claim it for themselves, I will probably not feel too great about that...
    • PowerElectronix 48 minutes ago
      It looks to me more like they made a math engine that can sift through a huge number of combinations, most them absurd, to prove a statement. Just like a chess engine, but for math.

      At least that's what I get from the NS result, they got from a point close to the solution to the solution by making it churn through 10 million bucks of compute.

    • munksbeer 43 minutes ago
      If the allegations are true, I can't see that collaboration lasting. Unfortunately, researches need to earn a living too, and being front run by a lab for everything you do isn't going to pay the bills.
  • profsummergig 1 hour ago
    Only after reading this post did I learn that my preferred AI trains on my inputs (prompts).

    How was I not aware of this before?

    • alansaber 9 minutes ago
      Everything. Your prompts, your conversation as a whole, public data, private data, usage metadata. It all goes into the big data machine.
    • vaylian 1 hour ago
      AI is also trained on your HN posts. And lots of other things you post on the internet.
      • profsummergig 25 minutes ago
        Public posts on the internet are acceptable (to me).

        For my (private) prompts, I need a warning telling me they may be used for training.

    • cleaning 1 hour ago
      Good question, this was very well known. Do you have an answer?
      • profsummergig 26 minutes ago
        There is no fine-print (let alone a loud banner) on the chat thread page that tells me my prompts can be used for training.
    • ga_to 1 hour ago
      Because you have not been paying attention to the discourse regarding AI for the last couple years? That AIs unethical train on data wherever they may get it from has been in the news basically weekly.
    • madethemcry 43 minutes ago
      Don't make this our fault. I would even ask how is this not off by default or why aren't we asked upfront about it if they really care. It's disguising data collection as good faith. I don't even understand how this is legal under GDPR/EU given how much of PII they receive through chats.
  • vaylian 1 hour ago
    This article explains the controversy and the mathematical problem much better than the tweet and toots: https://www.science.org/content/article/how-ai-math-breakthr...
    • dgellow 1 hour ago
      I prefer to read the actual sources for anything related to AI companies given how much AI nonsense journalists seem to accept without any skepticism
    • dakolli 1 hour ago
      Gromov’s soficity conjecture isn't even mentioned in the article you shared.

      Why are you saying that this article explains it much better than the tweet that you clearly didn't even read..

      • vaylian 1 hour ago
        I read the tweet several times but there is so much context missing, that the tweet itself is not enough.
  • b800h 1 hour ago
    I'm genuinely surprised that more people - including this mathematician in particular - don't untick the "improve the model for everyone" box. Unless the suggestion is that OpenAI ignore this preference?
    • msy 1 hour ago
      Given OpenAI's well documented history of unethical behaviour it seems adorably naive to think they actually do that in general, or that they wouldn't pull this particular data separately to generate these proofs.
      • olalonde 1 hour ago
        Unethical doesn't mean irrational. They'd be risking massive lawsuits and a total loss of trust if they got caught lying about this. Doesn't seem worth it.
        • dgellow 1 hour ago
          Sounds like exactly what OpenAI would do?
        • Planktonne 22 minutes ago
          They've done similar things with similar risks repeatedly.
    • afzalive 1 hour ago
      That doesn't stop them from training on your data apparently. I have that disabled but still has to disable "Don't train on my data" in the privacy center too.

      https://privacy.openai.com/policies?modal=take-control

      • b800h 27 minutes ago
        If that's true, it's scandalous. The "improve the model for everyone" dialogue states:

        "Allow your content to be used to train our models, which makes ChatGPT better for you and everyone who uses it. We take steps to protect your privacy. Learn more"

    • johnnyApplePRNG 1 hour ago
      They hide that button. Quite well.
    • frabcus 1 hour ago
      That option is really bad UX - you have to know to do it, you have to know what plan it is needed on. If you're not working in AI, I just don't think that's a reasonable expectation.

      Even if you know, in a complex project over years with multiple collaborators, it just needs one person once to fuck up and paste something into ChatGPT and not realise they weren't logged in, to go wrong.

      In a proper world, we'd at the very least legislate that AI-training on private data needs consent (in the GDPR sense). It's not consent to go "you didn't uncheck a box that lets me steal everything you've done".

      Any training on private data is in my view immoral (it's spying that ultimately will have a chilling effect on even people's private communications). And chats are private data. Unfortunately, it also increases power, so the big tech companies are all doing it.

  • overfeed 32 minutes ago
    I can't wait for OpenAI to do this to companies firing people to free up AI budgets
  • vrganj 13 minutes ago
    OpenAI is showing the world why they shouldn't trust AI hosted on some cloud somewhere.

    If they're stealing math proofs to advertise their models, who's to say they won't steal your businesses IP to gain a competitive advantage?

    They're not to be trusted with your data. I can't believe how short-sighted this is, they got a quick PR win at the expense of a much larger trust problem.

    I wouldn't trust cloud AI at all at this point. Get an open Chinese model and host it yourself somewhere. The initial costs might be higher, but you'll break even pretty quickly and nobody will be able to steal your innovations.

    This is American AI companies committing suicide.

  • sdcfgy 51 minutes ago
    Theft machines be thieving.
  • galkk 3 hours ago
    I want bunch of lawsuits, because the way things are described now produces perverse initiatives like try to discuss every possible idea that comes to mind with llm and if any of it works later claim the llm stole it.

    I would like to see chat logs etc and understand how much of a progress was done by human.

  • avaer 6 minutes ago
    I'm not into conspiracy theories, but every time I see someone thinking they've used one of these company's AI to one-up them, I can't help but think they just aren't grasping the economics of the situation.

    OpenAI is a trillion dollar for-profit corporation (and so are the others). The veneer of benevolence was flushed down the toilet long ago through a series of calculated maneuvers by shrewd businessmen.

    They aren't going to give you access to a model that will benefit you over them. They will give you the model that makes them money, increases their IPO price, and makes their investors rich, while privately using (and never releasing) the thing that gives them an advantage. The rest is just story-weaving to make the public believe some other narrative (safety, bad actors, save the children, whatever).

    If you're using a model where your data is being kept by them for purposes, including anything free, then you don't even have the veneer of legal recourse.

    And if they ever get caught or do something naughty, like say hacking a bunch of things as their experiment goes rampant, they have the money to get away with just blaming it on the AI.

  • touwer 1 hour ago
    But China steals our AI!!!!!!
  • dash2 2 hours ago
    Can we get a link to the mathstodon post?
  • protocolture 2 hours ago
    Gonna need grants for local models. Its happening. OpenAI and Anthropic models are powerful but are rapidly approaching the good ol trust thermocline.
  • Grimblewald 3 hours ago
    people seem to miss tge point of this. The problem isn't about credit, its about portraying these models as more competant than they really are. It fuels idiotic statements like jensen huangs recent "agi achieved" statement, which fuels an already dangerous financial fire.
    • ramblerman 3 hours ago
      As per the post, this mathematician has been working on this problem for 20 years. So either he was "just" about to breakthrough and this is a big coincidence, or Astra was able to push through the remaining block of 5-10-20-never years it might have taken.

      That's still a pretty big marker of competence in my eyes.

      The point of controversy seems to be who gets credit

      • jeltz 2 hours ago
        To me that is not a credit thing because this removes a piece evidence for the ability of AI to come up with novel ideas while still making it a useful tool.
      • 8bitsrule 1 hour ago
        The question's not new. In the early 1900s, women could not become PhD astronomers. Yet two women (Payne with stellar composition and Leavitt with cosmic distances) made fundamental, essential contributions to the science. Credit mostly went to male astronomers. The same might be said of Franklin and DNA.

        It was nearly a century before the stories of all of them were revealed to public history. That the discoverers were not all equally rewarded is unjustifiable.

      • mentalgear 2 hours ago
        The big LLM providers, desperate for good PR before their IPOs, are all actively looking for 'almost finished' hard problems, e.g. where the conceptual / creative parts are almost done and they only need to throw their VC-backed resources at to brute-force through the remaining computationally expensive problem (lean, etc) and claim 'they have solved it'.

        It's an utterly disrespectful, exploitive process, but all in line with exploitative predator capitalism of the stock market and big companies, now exploiting the knowledge / academia domain for scraps with a thin veneer of 'for science' PR.

  • viccis 2 hours ago
    Some mathematicians I know who've been following this have realized that they'd all gotten some emails from people they now know to be affiliated with OpenAI/Anthropic asking questions about their research in a way that seemed like scooping attempts.

    Also, a lot of my mathematicians buddies have reported students basically asking if it's worth ever doing grad school for pure math, and even very motivated students are looking for other options now. It's not because they aren't passionate about it, it's that they don't want to work for another half decade or more just to have to start their careers all over.

    All of this so that OpenAI and Anthropic can get into math result dick measuring to gas up their IPOs. Sickening.

    • alansaber 8 minutes ago
      You can't blame students for not seeing academia as the holy grail of knowledge anymore, when all the dialogue about technology and discovery has shifted to the hands of two private corporations
    • mdspan 2 hours ago
      Curious, what other options are prospective pure math grad students considering?
      • ethanwillis 2 hours ago
        I think Anthropic told them being a plumber is a great option.
    • dist-epoch 2 hours ago
      One has nothing to do with the other.

      It was long predicted that math and software developments would be the first domain where AI was going to do major damage.

      If OpenAI and Anthropic didn't get into math result dick measuring, Internet anons would have in their place, 6 months later when it got cheaper.

  • nobodywillobsrv 1 hour ago
    The real annoying thing it seems is mostly that openai is presumably doing this for internal reasons and this marginally increases the cost to users with no real gain.

    It would be one thing to gain from it but removing prestige wins from customers AND reducing compute support just feels like being ultra mean if you zoom out.

    If this was racing to cure cancer ahead of researchers we wouldn't be writing about this on HN.

  • 1337h4xx 4 hours ago
    TL/DR: Mathematician opted out of training on 29-JUN and asked OpenAI whether they trained on his data and was told that it "did not happen" but it clearly did.
    • achrono 1 hour ago
      I've been suspecting over the last couple of years of the frontier companies using data for training anyway, regardless of training-use consent. "Using" the data doesn't have to mean they literally upload chat transcripts into pretraining datasets. My analogy has been money laundering -- if that can happen at massive scales, surely these companies can and will do the digital/data equivalent derivations/transformations. Even if one could have the access etc. to do so, how exactly would one prove that a given synthetic dataset that OAI/Anthropic uses is derived from particular user conversations that did not consent for the info to be used in training?

      Consider, for instance that OpenAI's (consumer) terms say "If you do not want us to use your Content to train our models, you can opt out by following the instructions in this article ." but they also do say "We may use Content to provide, maintain, develop, and improve our Services". [1]

      If you think that's quibbling, consider that OpenAI's business terms, in contrast, do state "OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use.". [2]

      [1] https://archive.is/EcwD8 [2] https://archive.is/yZdAF

      • calf 59 minutes ago
        And humanities have a word for this, exploitation, or appropriation, maybe it's time scientists and engineers revisited basic ethical notions. Skimming a dozen threads and nobody seems to have this vocabulary or willing to say it.
    • tecleandor 4 minutes ago
      Well, OpenAI said "we didn't read the conversations", but they never discarded that the model was training with that data... so even worse.
  • ath3nd 2 hours ago
    [dead]
  • ThalesX 1 hour ago
    I don't get it, but I'm not an academic.

    If I dedicated my life to curing whatever, warts... and I'm making progress, but it's slow. And then here comes along this tool (LLM), and I use it, and it accelerates my progress to actually finding some sort of thing that makes warts more prone to being eradicated and then the lab throws a couple of million dollars of computes and lo and behold they eliminated warts. If I leave my ego and identity aside, which of course is hard for humans, wouldn't I be glad that warts is cured?

    As a software developer that contributed to open source. Yeah. My code is there. It was the most beautiful code ever written and the labs stole it from me. And now they use it to progress much faster than I ever could. OK. Whatever. It's a tool. I solve problems. Can't I move on from this wart to the next?

    To me, and I know this is gonna get me some heat, it just sounds like academics having their identity ruffled and turning their back to progress in the fields that they chose just because they don't get to play their little decades long of coffee, papers and ultimately identity politics.

    Edit: never got to negative so fast on this board haha. This board is unfortunately turning, or has turned, to Reddit.

    • jaccola 1 hour ago
      If these accusation are true

      It’s more like you spend 4 years developing a product you’re passionate about. This product will gain you the respect of all your colleagues and either earn you money directly or lead to great career advancements. Then OpenAI takes it, changes the colour scheme, finishes the login flow and claims the whole thing as their own.

      Not only would it piss you off but it would also misrepresent what OpenAIs models are capable of.

    • athrowaway3z 10 minutes ago
      I suspect in your ideology you're conflating things like copyright and patents, with the separate issue of Attribution.
    • blensor 1 hour ago
      Let's turn this question around.

      If I have infinite money to progress whatever problem solution I want but I always wait until I have an unfair advantage to get credit for whatever problem was just at the brink of a breakthrough anyway by sniping the last steps. Am I actually doing a good thing or would it be better to let it run it's natural course and spend the money somewhere it's actually needed?

    • frabcus 1 hour ago
      It's partly empathy with the person who did the work and had it stolen, in a field where the main thing people work for is credit. Maths isn't well paid, and doesn't make things that millions of people directly use.

      It's also systemic, it cuts off the supply of results, if there is no reward any more for getting a result, the pipeline of maths will stop. It is the snake eating itself, which has a bad impact for all of us.

    • yshklarov 55 minutes ago
      We love to do work that is useful and valuable to others, and we often form our identities around this. But identities are in large part socially constructed, so many of us need the recognition of others for our contribution. And it can be very painful when we perceive that the credit for our life's work got "stolen". Naturally, we fight against this. There's nothing shameful there. Sure, you can hold onto an ideal of egoless service. There's nothing wrong with that, either. But it's misanthropic to pass such harsh judgment on people for behaving in such a normal and natural manner.
    • card_zero 1 hour ago
      If, as you say, it doesn't matter that the AI company gets praise for somebody else's discovery, then it also wouldn't matter if the praise went to the academic. You apparently resent the academic for seeking praise instead of being content with anonymously advancing human knowledge, but you don't resent the AI company seeking praise while leaching off the academic.
    • PeterStuer 29 minutes ago
      An academic's whole career is built on credit assignment for research breakthroughs. If someone else takes the credit, you lose. This is fundamentally different from a builder. You create things, solve problems and get paid for that instance. Nobody cares you 'invented' the blueprint for that building method. Your job is to instantiate. 100 Contractors can be building instance the exact same building somewhere else, it would not affect you. Most of IT builders are paid for what is basically 2 or 3 tier CRUD.
    • Yizahi 1 hour ago
      And I could dedicate my life to helping feed starving kids all across the globe. And then comes along this tool (a lockpick) and I use it, it accelerates my progress to actually getting money to fulfill my dream. If you leave your ego and identity aside, which of course is hard for you, wouldn't you be glad that I stole your money to feed starving kids?
    • alex1138 1 hour ago
      HN loves drive-by downvotes. It's a real shame.
      • card_zero 47 minutes ago
        Downvotes might work as an abuse sponge, absorbing the impulse to make personal attacks. Other than that possible advantage, the downvote functionality seems contradictory to the concept of a discussion forum, I agree.