In a world where it looks like powerful open-weights models are so likely to exist, I think the best case scenario would be creating solutions that perform in that world.
Wallace and Dalton at the end of the Huggingface incident post-mortem at Blackhat are remarkably foreword-looking with this respect https://youtu.be/87DyyMV0kCY?t=1926 . We must create automated defensive capabilities that mirror this existence proof cyberoffensive capabilities. Specifically, automating much of the Software Development Life Cycle, automated Intrusion Detection Systems, and creating automated red team and remediation systems. In this sense, open-weight models are critical infrastructure given foresight and engineering, rather than liability.
The maturation of cyber defensive technology was preceded by cyber offensive capabilities in pioneers like Telephreakers in the 80s. We did not secure the internet by hiring all the hackers into the largest companies, and locking them away from the rest of the internet. We did it through open standards, open source and academic peer review where large bodies of experts could pressure test systems, industrial bodies to publish norms and taxonomies like OWASP and METR. We did it through distributing and socializing information, not hiding it.
Open models can be the workhorses of defensive infrastructure. They’re over an order of magnitude cheaper than frontier models. Much of defensive work is not a matter of isolated genius, it’s a matter of exhaustively dotting your I’s, crossing your T’s; implementing standard practices and policies. As perfect example in this incident: air-gapping is the simple and standard defense which would have prevented the entire debacle. If we ban open-weight models we will be pricing out the vast majority of the world from the only practical defense that will be available.
In short, the answer here is to accelerate defensive infrastructure powered by open inference as much as we can.
In a world where it looks like powerful open-weights models are so likely to exist, I think the best case scenario would be creating solutions that perform in that world.
Wallace and Dalton at the end of the Huggingface incident post-mortem at Blackhat are remarkably foreword-looking with this respect https://youtu.be/87DyyMV0kCY?t=1926 . We must create automated defensive capabilities that mirror this existence proof cyberoffensive capabilities. Specifically, automating much of the Software Development Life Cycle, automated Intrusion Detection Systems, and creating automated red team and remediation systems. In this sense, open-weight models are critical infrastructure given foresight and engineering, rather than liability.
The maturation of cyber defensive technology was preceded by cyber offensive capabilities in pioneers like Telephreakers in the 80s. We did not secure the internet by hiring all the hackers into the largest companies, and locking them away from the rest of the internet. We did it through open standards, open source and academic peer review where large bodies of experts could pressure test systems, industrial bodies to publish norms and taxonomies like OWASP and METR. We did it through distributing and socializing information, not hiding it.
Open models can be the workhorses of defensive infrastructure. They’re over an order of magnitude cheaper than frontier models. Much of defensive work is not a matter of isolated genius, it’s a matter of exhaustively dotting your I’s, crossing your T’s; implementing standard practices and policies. As perfect example in this incident: air-gapping is the simple and standard defense which would have prevented the entire debacle. If we ban open-weight models we will be pricing out the vast majority of the world from the only practical defense that will be available.
In short, the answer here is to accelerate defensive infrastructure powered by open inference as much as we can.