I understand you only care about maximizing your current preferences (which might include long-term flourishing of humanity), and not some vague “longtermist potential” independent of your preferences. I agree, but it would seem like most EAs would disagree
Yes, I think most EAs are confused about ethics (see e.g. 123), which is why I’m not sure I count as EA or merely as “EA-adjacent”[1].
I don’t immediately see why some simulation hypotheses (maybe specifically tailored to the way in which the AI encodes its physical hypotheses) would not be able to alter underlying physics in such a way as to provide a tighter causal loop between AI and simulator, so that User Detection yields a simulator
We design user detection so that anything below a threshold is a “user” (rather than only the extreme agent being the user), and if there are multiple (or no) “users” we discard the hypothesis. So, yes, there is still some filtering going on, just not as complex as before.
But maybe this is not your main concern. You said “our best plan at avoiding those is applying various approximate pruning mechanisms (as already happens in many other Alignment proposals)”. This is not how I would put it. My goal is to have an algorithm for which we know its theoretical guarantees (e.g. having such-and-such regret bound w.r.t. such-and-such prior). I believe that deep learning has theoretical guarantees, we just don’t know what they are. We will need to either (i) understand what guarantees DL has and how to modify it in order to impose the guarantees we actually want or (ii) come up with a completely different algorithm for satisfying the new guarantees. Either will be challenging, but there are reasons to be cautiously optimistic (mainly the progress that’s already happening, and the fact that looking for algorithms is easier when you know exactly which mathematical property you need).
Say P searches for a model of a theory T. Say Q simulates a room with a human, and a computer which distributes an electric shock to the human iff it finds a contradiction derived from T, and Q outputs whether the human screamed in pain (and suppose the human screams in pain iff they are shocked). Both reject at time t if they haven’t accepted yet, but suppose we know one of the two searches will finish before t.
The difference is, if there’s actually a room with a human (or the simulation of a room with a human), then there are other computations that are running (all the outputs of the human throughout the process), not just the one bit about whether the human screamed in pain. That’s how we know that in this situation a human exists, whereas if we only have a computer running P then no human exists. We can’t just “rearrange the program in a way that outputs information that wasn’t already there”, because if it isn’t already there, the bridge transform will not assert this rearranged program is running.
Due to the unfortunate timing of this discussion, I feel the need to clarify: this has absolutely nothing to do with FTX. I would have said exactly the same before those recent events.
We design user detection so that anything below a threshold is a “user”
Yes, but simulators might not just “alter reality so that they are slightly more causally tight than the user”, they might even “alter reality so that they are inside the threshold and the user no longer is”, right? I guess that’s why you mention some filtering is still needed.
I believe that deep learning has theoretical guarantees, we just don’t know what they are
I understand now. I guess my point would then be restated as: given the amount of room that simulators (intuitively seem to) have to trick the AGI (even with all the above developments), it would seem like no training procedure implementing PreDCA can be modified/devised so as to achieve the guarantee of (almost surely) avoiding acausal attacks. Not because of formal guarantees being impossible to prove about that training procedure (e.g. DL), but because pruning attacks from the space of hypotheses is too complicated of a search for any human-made algorithm/procedure to carry out (because of the variety of attacks and the vastness of the space of hypotheses).
We can’t just “rearrange the program in a way that outputs information that wasn’t already there”, because if it isn’t already there, the bridge transform will not assert this rearranged program is running.
Yes, but simulators might not just “alter reality so that they are slightly more causally tight than the user”, they might even “alter reality so that they are inside the threshold and the user no longer is”, right?
No. The simulation needs to imitate the null hypothesis (what we understand as reality), otherwise it’s falsified. Therefore, it has to be computing every part of the null universe visible to the AI. In particular, it has to compute the AI responding to the user responding to the AI. So, it’s not possible for the attacker to make the user-AI loop less tight.
...it would seem like no training procedure implementing PreDCA can be modified/devised so as to achieve the guarantee of (almost surely) avoiding acausal attacks… because of the variety of attacks and the vastness of the space of hypotheses.
The variety of attacks doesn’t imply the impossibility of defending from them. In cryptography, we have protocols immune from all attacks[1] despite a vast space of possible attacks. Similarly, here I’m hoping to gradually transform the informal arguments above into a rigorous theorem (or well-supported conjecture) that the system is immune.
No. The simulation needs to imitate the null hypothesis (what we understand as reality), otherwise it’s falsified. Therefore, it has to be computing every part of the null universe visible to the AI. In particular, it has to compute the AI responding to the user responding to the AI. So, it’s not possible for the attacker to make the user-AI loop less tight.
Yes, I had understood that, but this is only the case in the limit when the AI is completely certain about every minute detail about its immediate physical reality, right? Otherwise, as in my above example, the simulator could introduce microscopic variations (wherever the AI isn’t yet completely certain about reality, for instance in some parts of the user’s brain) which subtly alter reality in such a way that the information between AI and user from counterfactual actions takes longer to arrive. Or am I missing something?
The variety of attacks doesn’t imply the impossibility of defending from them.
If the information takes a little longer to arrive, then the user will still be inside the threshold.
A more concerning problem is, what if the simulation only contains a coarse grained simulation of the user s.t. it doesn’t register as an agent. To account for this, we might need to define a notion of “coarse grained agent” and allow such entities to be candidate users. Or, maybe any coarse grained agent has to be an actual agent with a similar loss function, in which case everything works out on its own. These are nuances that probably require uncovering more of the math to understand properly.
Oh, so it seems we need a coarse grained user (a vague enough physical realization of the user) for threshold problems to arise. I understand now, thank you again!
Yes, I think most EAs are confused about ethics (see e.g. 1 2 3), which is why I’m not sure I count as EA or merely as “EA-adjacent”[1].
We design user detection so that anything below a threshold is a “user” (rather than only the extreme agent being the user), and if there are multiple (or no) “users” we discard the hypothesis. So, yes, there is still some filtering going on, just not as complex as before.
But maybe this is not your main concern. You said “our best plan at avoiding those is applying various approximate pruning mechanisms (as already happens in many other Alignment proposals)”. This is not how I would put it. My goal is to have an algorithm for which we know its theoretical guarantees (e.g. having such-and-such regret bound w.r.t. such-and-such prior). I believe that deep learning has theoretical guarantees, we just don’t know what they are. We will need to either (i) understand what guarantees DL has and how to modify it in order to impose the guarantees we actually want or (ii) come up with a completely different algorithm for satisfying the new guarantees. Either will be challenging, but there are reasons to be cautiously optimistic (mainly the progress that’s already happening, and the fact that looking for algorithms is easier when you know exactly which mathematical property you need).
The difference is, if there’s actually a room with a human (or the simulation of a room with a human), then there are other computations that are running (all the outputs of the human throughout the process), not just the one bit about whether the human screamed in pain. That’s how we know that in this situation a human exists, whereas if we only have a computer running P then no human exists. We can’t just “rearrange the program in a way that outputs information that wasn’t already there”, because if it isn’t already there, the bridge transform will not assert this rearranged program is running.
Due to the unfortunate timing of this discussion, I feel the need to clarify: this has absolutely nothing to do with FTX. I would have said exactly the same before those recent events.
Thank you again for answering!
Yes, but simulators might not just “alter reality so that they are slightly more causally tight than the user”, they might even “alter reality so that they are inside the threshold and the user no longer is”, right? I guess that’s why you mention some filtering is still needed.
I understand now. I guess my point would then be restated as: given the amount of room that simulators (intuitively seem to) have to trick the AGI (even with all the above developments), it would seem like no training procedure implementing PreDCA can be modified/devised so as to achieve the guarantee of (almost surely) avoiding acausal attacks. Not because of formal guarantees being impossible to prove about that training procedure (e.g. DL), but because pruning attacks from the space of hypotheses is too complicated of a search for any human-made algorithm/procedure to carry out (because of the variety of attacks and the vastness of the space of hypotheses).
Of course! I understand now, thank you.
No. The simulation needs to imitate the null hypothesis (what we understand as reality), otherwise it’s falsified. Therefore, it has to be computing every part of the null universe visible to the AI. In particular, it has to compute the AI responding to the user responding to the AI. So, it’s not possible for the attacker to make the user-AI loop less tight.
The variety of attacks doesn’t imply the impossibility of defending from them. In cryptography, we have protocols immune from all attacks[1] despite a vast space of possible attacks. Similarly, here I’m hoping to gradually transform the informal arguments above into a rigorous theorem (or well-supported conjecture) that the system is immune.
As long as the assumptions of the model hold, ofc. And, assuming some (highly likely) complexity-theoretic conjectures.
Yes, I had understood that, but this is only the case in the limit when the AI is completely certain about every minute detail about its immediate physical reality, right? Otherwise, as in my above example, the simulator could introduce microscopic variations (wherever the AI isn’t yet completely certain about reality, for instance in some parts of the user’s brain) which subtly alter reality in such a way that the information between AI and user from counterfactual actions takes longer to arrive. Or am I missing something?
You’re right, thank you!
If the information takes a little longer to arrive, then the user will still be inside the threshold.
A more concerning problem is, what if the simulation only contains a coarse grained simulation of the user s.t. it doesn’t register as an agent. To account for this, we might need to define a notion of “coarse grained agent” and allow such entities to be candidate users. Or, maybe any coarse grained agent has to be an actual agent with a similar loss function, in which case everything works out on its own. These are nuances that probably require uncovering more of the math to understand properly.
Oh, so it seems we need a coarse grained user (a vague enough physical realization of the user) for threshold problems to arise. I understand now, thank you again!