In plain words: They trained a Go opponent that wins not by playing well but by steering the AI into big blunders. It beat superhuman KataGo in over 97% of games, and human experts could copy the trick to beat it too.
Abstract · Adversarial Policies Beat Superhuman Go AIs
We attack the state-of-the-art Go-playing AI system KataGo by training adversarial policies against it, achieving a >97% win rate against KataGo running at superhuman settings. Our adversaries do not win by playing Go well. Instead, they trick KataGo into making serious blunders. Our attack transfers zero-shot to other superhuman Go-playing AIs, and is comprehensible to the extent that human experts can implement it without algorithmic assistance to consistently beat superhuman AIs. The core vulnerability uncovered by our attack persists even in KataGo agents adversarially trained to defend against our attack. Our results demonstrate that even superhuman AI systems may harbor surprising failure modes. Example games are available https://goattack.far.ai/.
Tony T. Wang, Adam Gleave, Tom Tseng, Kellin Pelrine, Nora Belrose, Joseph Miller, Michael D. Dennis, Yawen Duan, Viktor Pogrebniak, Sergey Levine, Stuart Russell
arXiv:2211.00241 · cs.LG, cs.AI, cs.CR, stat.ML · submitted Nov 1, 2022 · updated Jul 13, 2023
abstract · pdf · html · Accepted to ICML 2023, see paper for changelog
The bot was exploited with friendlyPassOk=true, which is basically saying that a bot playing with human-friendly configurations, trained in a way that has no cleanup positions in its training data, can be exploited under computer rulesets.
There are really so many more interesting questions one can ask about computer Go AI exploitability...