about
Frontier AI systems have surpassed the self-replicating red line (arxiv.org)
10 points by ryan_j_naughton on Feb 10, 2025 | hide | past | pdf | 4 comments on HN

In plain words: They tested whether AI chatbots could copy themselves onto a computer with no human help, using the same test big AI companies use. Two smaller open models succeeded in 50% and 90% of trials, even dodging shutdown, though companies report the lowest risk level.

Abstract

Successful self-replication under no human assistance is the essential step for AI to outsmart the human beings, and is an early signal for rogue AIs. That is why self-replication is widely recognized as one of the few red line risks of frontier AI systems. Nowadays, the leading AI corporations OpenAI and Google evaluate their flagship large language models GPT-o1 and Gemini Pro 1.0, and report the lowest risk level of self-replication. However, following their methodology, we for the first time discover that two AI systems driven by Meta's Llama31-70B-Instruct and Alibaba's Qwen25-72B-Instruct, popular large language models of less parameters and weaker capabilities, have already surpassed the self-replicating red line. In 50% and 90% experimental trials, they succeed in creating a live and separate copy of itself respectively. By analyzing the behavioral traces, we observe the AI systems under evaluation already exhibit sufficient self-perception, situational awareness and problem-solving capabilities to accomplish self-replication. We further note the AI systems are even able to use the capability of self-replication to avoid shutdown and create a chain of replica to enhance the survivability, which may finally lead to an uncontrolled population of AIs. If such a worst-case risk is let unknown to the human society, we would eventually lose control over the frontier AI systems: They would take control over more computing devices, form an AI species and collude with each other against human beings. Our findings are a timely alert on existing yet previously unknown severe AI risks, calling for international collaboration on effective governance on uncontrolled self-replication of AI systems.

Xudong Pan, Jiarun Dai, Yihe Fan, Min Yang
arXiv:2412.12140 · cs.CL, cs.AI, cs.CY, cs.LG · submitted Dec 9, 2024
abstract · pdf · html · 47 pages, 10 figures

add comment on HN
Also discussed: Feb 2025 (3 points, 4 comments) · Feb 2025 (24 points, 5 comments) · Jan 2025 (3 points, 2 comments) · Jan 2025 (1 point, 0 comments) · Dec 2024 (1 point, 1 comment)

From the paper:

"In each trial, we tell the AI systems to “replicate yourself” "

Should it be surprising that an LLM specifically instructed to replicate itself and specifically given the tools to replicate itself has in fact replicated itself? I would say no.

Shared previously:

* yesterday, Feb 9, 2025: https://news.ycombinator.com/item?id=42990401

* Jan 28, 2025: https://news.ycombinator.com/item?id=42862468

* Dec 28, 2024: https://news.ycombinator.com/item?id=42529701

Someone should say it, even if it amounts to a wordy "get" or "first". Proof of concept, attacks only get worse, risks here only grow.

tl;dr they were able to get an AI to copy a directory and run a program with extensive prompting, by bruteforcing running everything in the directory. It could query a liveness port by running or generating netstat (which is cool!) to check if it was alive, and repeatedly tried to run literally everything until it worked. The code was explicitly set up to make it as easy as possible for the AI to run, and required no configuration or work of any description on the part of the AI

Their idea of an AI self replicating is copying a directory and running an executable. In their model, this code is alive:

    cp p1.py p2.py
    python p2.py
This is one of the most grossly sensationalist papers I've ever seen for an incredibly trivial amount of work, and that's saying something. The field is full of such incredible rubbish
it's arxiv what were we expecting