upvote
It's not "legit", it's pointless scaremongering about entirely speculative future dynamics. Current LLMs can't "build" anything novel in this broad space. What if future AIs make it a lot easier for researchers to defend against plausible bioweapons? That's also reasonably possible, and would be a reason to deploy bio-capable AIs more broadly (with meaningful safeguards of course. But these are comparatively cheap because worthwhile bio research is resource-intensive already). At the very least, it'd be nice to have an AI model that doesn't immediately refuse to answer questions about junior-high Biology class.
reply
So a terrorist can't use a local llm to help grow anthrax? That is not farfetched at all.

AI democratized the knowledge needed to build bioweapons. Like how with a 3d printer anyone can build a gun with no expertise.

reply
> AI democratized the knowledge needed to build bioweapons. Like how with a 3d printer anyone can build a gun with no expertise.

Building simple guns out of pipes never was hard. Jury is still out if it is more or less work than getting a 3d printer working.

reply
Also it kind of infantalizes terrorists as if not having an LLM access or 3d printer is what stopping their attacks. Like okay I ask LLM to help me create a dirty nuclear bomb but the moment i start taking steps to do that, law enforcement will already be tracking me.

Most people saying LLMs can make terrorism easy have never given doing terroism a serious thought imo.

reply
The raw materials to make bioweapons are easily purchased on line with no pre-emptive tracing. It's absurd to discount the expertise factor in being a bottleneck, which LLMs have evaporated.
reply
> It's absurd to discount the expertise factor in being a bottleneck, which LLMs have evaporated.

Mmm. Especially in this arena, LLM assistance is like The Anarchist's Cookbook. A quarter of the time following the instructions will seriously injure you... and if you know enough to identify which instructions are the hazardous ones, you know enough to not need the assistance.

reply
That may be true (and I hope it is). But it's not a limitation that will remain indefinitely.
reply
> But it's not a limitation that will remain indefinitely.

The Sun is going to fail in somewhere between many hundreds of millions and a few billion years. This will either turn the surface of the earth into slag, freeze it, or both. Either way, all life on the planet is doomed. This fact is not a reason to fail to switch from hydrocarbon-burning electricity generators to photovoltaic, fission, wind, hydroelectric, and geothermal electricity generators. Extinction events that will happen in the extremely distant future shouldn't prevent us from doing the things that are smart to do in the medium- and long-term.

But, -to bring things to the present day- companies that are solidly on track to hit their promised growth targets don't come out and publicly say "We're working on WMDs. [0] We are incapable of safely working on these WMDs. We refuse to stop working on these WMDs. However, if you lawmakers make special laws and regulations just for us and include us in the process, we'll be quite happy to submit the stop work order to our employees!". That's a statement you only make if there's no way in hell you're going to keep your promises and you're willing to risk jail time and annihilation of your companies for a shot at being able to con Congress into giving you an ironclad excuse to fail to keep your promises.

Given enough time and focused effort, we will end up with widely-available automated librarians that are very good. We're not there yet, and -based on current events- are absolutely not going to get there in the near future.

[0] Anything with a 10% chance of destroying all humanity is a WMD.

reply
> The Sun is going to fail in somewhere between many hundreds of millions and a few billion years.

Cool, what does a process that's about 9 orders of magnitude slower than AI development have to tell us about AI risks?

reply
Sure, that's why we keep seeing so many bioweapon attacks in recent times, because AI + Amazon can end the world.
reply
It's strange how quick people are willing to dismiss concerns with horrible reasoning as long as it suits their biases. Perhaps a little intellectual honesty is called for considering the stakes? There are many plausible reasons why we haven't seen AI fuel bio-terror attacks yet. None of which implies it's unlikely or implausible in principle.
reply
But hasn't bio attacks already been possible before AI, what has changed? Maybe the barrier to entry lowered, but one could argue the availability of info has not been the bottleneck for as long as the internet has existed.

The threat is ofc real, but AI won't magically "do the thing" still, it's not code that's the bottleneck AFAIK? Correct me where I'm wrong.

reply
Synthesizing complex information from a range of technical sources enough to build bioweapons is cognitively impenetrable for the vast majority of people. The ability of AI to synthesize this information into a step-by-step recipe to follow is a step change in accessibility.

There's an opportunity cost to terrorism just like with any time sink. The effort to build up knowledge enough to produce some weaponized pathogen will be compared to just doing traditional terrorism. For some low capability terror cell, its easy to see how the cost/benefit analysis has been in favor of traditional terrorism up to now. The kinds of terror acts that take years of sustained effort to execute are rare. But as the barriers to entry to bioterrorism fall away and become widely accessible we may see the cost/benefit shift.

reply
It turns out that LLMs, especially local LLMs, tend to hallucinate a lot when thinking about anything that's overtly fiddly or technical. This is even more the case when they're in a domain that isn't a natural part of their training data. If you have to "jailbreak" the model to get it to talk, you're so wildly out of the expected distribution that you'd be crazy to trust anything it says. It's basically making up stuff as it goes along. These are foundational issues with how the models are created, not something that a bad actor can just hack around.

(The biggest real safety issue in this kind of space is actually that the model might actively goad some unsuspecting victim into doing something incredibly dumb and dangerous to themselves as much as possibly others.

IIRC, there were reports of something vaguely similar happening IRL but involving casual mischief, not any kind of extreme attacks. And because nobody else seems to have managed to elicit the same actively goading verbiage from the model, it's implicitly suspected that the person involved was the one who introduced the problematic scenarios to begin with.)

reply
This take belongs in 2024. It has been falsified multiple times but it never seems to go away.
reply
Are you thinking about model capabilities in coding and math starting late 2025 or so? Those were intentionally boosted via automated RLVR, and there's nothing even loosely comparable to that in applied biology work, let alone in the speculative "helping a bad actor do something crazy" domain that the AI safety folks are worried about. You can't extrapolate from one to the other.

The implied concerns from sensible safety advocates are also about someone jailbreaking the latest proprietary AI frontier model for something like this (which is why their current guardrails are so extreme), not about toy local models.

reply
I actually agree with you. Verifiable domains will have better performance.

But there’s nothing specially bad about LLMs that don’t allow it to work outside of its training set. It’s just that biology has to verify itself in physical realm and it’s a bit slower.

So yeah, I also don’t think some bad actor will find the secret to manufacturing a bio weapon using LLMs. But maybe these people think it’s possible. I’m skeptical but I’m going to also listen to the people who know it best.

reply
> But maybe these people think it’s possible. I’m skeptical but I’m going to also listen to the people who know it best.

The problem is that in order for the scaremongering to make any kind of sense and for "stop frontier AI immediately" to be the right response (which is what the "AI safety" folks seem to be pushing for), you don't just need this to be possible in the abstract at some undetermined point in the future. You also need to argue that it will not be helpful for white-hat biosafety researchers (there will hopefully be several orders of magnitude more white-hat biosafety folks than attackers, with orders of magnitude more resources available) to red-team that exact scenario several months or even years in advance using their trusted access to unreleased super-smart AI, and thereby devise appropriate defenses with that same AI's help. That, if anything, is the most implausible part about this entire scenario.

reply
>You also need to argue that it will not be helpful for white-hat biosafety researchers (there will hopefully be several orders of magnitude more white-hat biosafety folks than attackers, with orders of magnitude more resources available) to red-team that exact scenario several months or even years in advance

Sigh.

Attackers only need to win once. Defense needs to work every time.

A single wide scale attack affecting around 100k people or more will have your neighbors stomping on your face telling you to shut up, and to lock this shit down.

It's insane how you can watch a technology get better and better and better and come up idea that everything will remain the same. We are currently in the middle of development of the most powerful weapons on earth and you don't want to think about it because it's uncomfortable.

reply
It only sounds legit to people who don't understand biology and haven't done advanced laboratory work. Sort of like Michael Crichton novels: superficially plausible but not grounded in any real science.
reply
I see no actual argument here.
reply
You haven't made any argument either, so I suppose we're even.
reply
I'm always suspicious of people who claim expertise/special knowledge but aren't quick to offer it and instead engage in petty back-and-forths. Instead of trying to win this debate in the narrow sense, why not just make the best argument you can in support of your position? If authority has any value, it is because it gives you specialized knowledge that lets you judge the likelihood of speculative scenarios better than laymen. If you can't communicate that knowledge and the argument that leads to your conclusion, your supposed expertise just isn't worth much in this context.
reply
My argument was that it is reasonable to be concerned that human terrorists might use AI to assist with building bioweapons.
reply
That's merely an assertion unsupported by any reliable evidence, not an actual argument. In short you're just making shit up.
reply
Well that's the nature of trying to prevent a thing that hasn't happened yet right? What would be reliable evidence except that terrorists already used AI to help build a bioweapon? I'm sure before 9/11 talking about terrorists using commercial airplanes as makeshift missiles seemed like scaremongering too.

I see zero technical reasons why it could not be done, so being concerned about prevention seems pretty reasonable. I'm not saying AI uses robotic arms to build a bioweapon unassisted or something, just that it dramatically empowers bad actors enough to make them capable of things they previously were not.

reply
The last few years have shown me something about human behavior.

Before the thing happens: "This will never happen, it can't happen, you're making it up, stop being a scaremonger".

10 minute after the thing happens: "Of course, this always happened and it's always been this way and we just have to live with it".

We are quickly adaptable, but that may be risky if we snuggle up with death.

reply
What an incredible illustration of human intelligence failing to generalize out of distribution.
reply
It's quite hard to measure until a wet lab gets behind the filter access to benchmark it.

But if you extrapolate from the ability it has in fields that aren't too strictly filtered, it looks pretty scary.

There are arguments against doing that but at first glance it seems like we just don't really know, and we likely won't: if governments decide they're interested in AI gain of function capabilities they won't be broadcasting that or allowing public benchmarks.

reply
> But if you extrapolate from the ability it has in fields that aren't too strictly filtered, it looks pretty scary.

The closest unfiltered analogy to something as complex as chemistry or biology is most likely the softer fields like philosophy, the humanities and the softer end of the social sciences. Most practitioners and scholars in these fields would agree that AI is not nearly as compelling there as it might be in e.g. math, and that's putting it mildly and charitably.

Even coding shows the divide pretty well: AI writes code that manages to work (i.e. achieve its self-assessed functional goals) but the stuff is so unmaintainable that it ultimately poisons the AI's own context leading to mode collapse. This makes complete sense because maintainability is a soft objective that's especially hard to automatically optimize for in the short term, as part of a RL training run. The math folks themselves, too, now faced with a very real threat to their field from purportedly "hostile misaligned AIs", immediately zeroed in on education and exposition as something that LLMs are terrible at; with their abilities in systemizing and theory-building also being very much in question.

reply
terrorists can also use annas archive, scihub and equipment they order on Alibaba to build bioweapons and I don't see him losing his mind over those

if you're trying to build a bioweapon shockingly enough the bottleneck is... the laboratory work. What on earth is 'legit' about stringing words together that sound scary, you can't just iterate 'ai bioweapon cyber' in a sentence over and over as if that adds up to actual evidence for an increased risk of any threat. well tbf you can technically because apparently it freaks a lot of podcast listeners out

reply
As a thought experiment imagine you have a biochemical PhD expert on the phone with you giving you step by step instructions on how to grow some dangerous biotoxin, giving you feedback in real time and helping you troubleshoot. Would you be more successful with this expert than you'd be on your own?

Now imagine anyone can call that expert for free at any time.

Maybe the AI isn't quite there with biology knowledge yet (doubtful), but it is a matter of time.

How is that not a real risk?

reply
> As a thought experiment imagine you have a biochemical PhD expert on the phone with you giving you step by step instructions on how to grow some dangerous biotoxin, giving you feedback in real time and helping you troubleshoot. Would you be more successful with this expert than you'd be on your own?

I think there is some difference of degree, but not of kind. A determined terrorist can relatively easily find many ways to kill people en masse today, no AI needed. The bottleneck is usually the actual physical execution in the real world, not theoretical knowledge.

reply
>The bottleneck is usually the actual physical execution in the real world, not theoretical knowledge.

And the interest or willpower too. People fall into a kind of reductive Good vs Evil mode of thinking, with "terrorists" being of course a kind of shadowy mass of pure evil lurking in the darkness. But actual real life terrorists are people too and I'd wager few of them are actually interested in trying to end humanity.

reply
The only terrorists who wanted to end the world were Aum Shinrikyo as far as I remember. Everyone else is fighting for a cause that benefits their people - some good like kicking out colonial oppression, some evil like fascism or Islamism, some of them in between like various ethnic conflicts.

Even the religious extremists don't really want to take over the world and destroy everyone who doesn't convert. That's just a way to gain support from a conservative nation. A lot of them are motivated by revenge for wars that destroyed their country and want to make sure it never happens again.

Their methods are wrong no doubt, and not very effective, but the reasons they do it are good. And a person like that will never release a deadly bio weapon. We should worry more about incel mass shooter types who believe everyone is evil.

reply
Exactly. I am more worried about a Beavis-and-Butthead lone wolf incel type making something that kills a thousand people and then scale that up across 4chan or whatever. Not human extinction but still very bad.
reply
The issue with the direction of technology is it tends to make things that were once very hard to impossible. This is why there are bumper stickers mocking Libertarians by saying things like "legalize recreational plutonium".

If we are not careful and suddenly release tools with far more capabilities than we expect you go from "smart" people being able to do it, to some angsty teenager being able to pull it off in their bedroom.

The current issue with AI is we are squirting out new models faster than we can complete long term testing on them. We'll find new model capabilities long after they've been in the field. Just assuming safety is how you catch cancer from your food dye, or how you change the atmosphere around you and start burning down your planet. Now just imagine that involving intelligence and doing with a few percent of the worlds GDP to make it happen.

reply
not an expert but because i assume you need the physical resources to do it in the first place?
reply
you don't even need to make it a thought experiment, we have real world cases of this. Anthrax cultivation is easy enough that a first year biology student can do it, but it's in practice so dangerous and difficult to aerosolize without the correct equipment that nobody does it. The information to easily produce many bioweapons is online, the internet and instant global communication already democratized knowledge, why are terrorists still driving trucks into crowds?

Plans for 3d printed weapons are publicly available, same argument was made then, if everyone can download a blueprint for a gun, are we all going to get gunned down? Hasn't happened. There's two errors in this Bill Gates argument. One is thinking terrorists don't already have PhDs, secondly overrating intelligence because that's the only thing they're good at, and when they think of terrorists they just think of their own inflated egos, but turned evil. Which isn't how real terrorists operate

reply
Synthesizing complex information from a range of textbooks enough to build bioweapons is cognitively impenetrable for the vast majority of people. Having the AI synthesize this information into a step-by-step recipe to follow is within the capabilities of most motivated individuals.
reply