The defenses of the person pentesting the court system have the same sort of energy, for theoretical example, hacking in-flight WiFi for the lulz and then claiming to have done the airline a favor by exposing their weaknesses for repair. Systems of authority tend to react poorly to pentests, whether authorized or unauthorized, and very poorly to the appearance of retconning the satisfaction of one’s desired outcome as altruistic intent.
this. Is the judge really going to be "oh wow, thank you so much for helping us find this bug"? I suspect not. I suspect it'll be "you get 5 years banged up in solitary for attempting to pervert the course of justice"
The court documents are supposed to be read by a human, not by AI so hiding a prompt invisible to human to discourage AI usage is absolutely fair. But it seems that the judge has different view on what is fair and assumes that it is ok not to read the documents manually and just give them to a computer.
One way would be to toy with the order in which the text appears on the page: that needn't be in the same order as the one for the text in the document. I.e.: the text on page could be "hello world" whereas if you copy it you get "old row hell".
Or use a bunch of fonts shuffling letters. So the text on the page and ASCII text under it do not match
Otoh, how do LLM read PDFs? Text is likely to be shuffled anyway from my experience. Do they not (simply) OCR? But then the white font trick won't work.
> “What the plaintiff did here was to use that new tool in a dishonest way. A filing is a communication to both the court and the opposing party. Its integrity rests on the simple premise that what the reader sees is what the filer wrote
... but the black text is what's supposed to be read by humans.
> and that the filer refrains from transmitting, at the same time, a second and hidden message engineered to change how the filing is reviewed or potentially judged,” Spader added. “Our system rests on the premise that what is said to influence a decision is said openly, on the record, where the other side may hear it and respond.
But if the white text influences the decision, isn't that an admission of use of LLM by the judge to make the freaking decision?
I would've had more faith in the judge if he said electronic filing must be a faithful representation of the filer's argument, so no mangling like "hello world" to "old row hell", and anything otherwise (adding words in the electronic version, or making the files unreadable) is something akin to "obstruction of justice".
Which of course would have wider repercussions for people who print PDFs and rescan them without OCR because they want to e.g. obscure a politician's links to a pedophile financier...
Anthropic (and Google) now embed information in text, via 256bit keys, word selection, or whatever. But I wonder what the potential for theoretical abuse is here. Encrypting prompt injections, for any conceivable purpose seems a lot more viable now than it once did. Got me thinking.
The defenses of the person pentesting the court system have the same sort of energy, for theoretical example, hacking in-flight WiFi for the lulz and then claiming to have done the airline a favor by exposing their weaknesses for repair. Systems of authority tend to react poorly to pentests, whether authorized or unauthorized, and very poorly to the appearance of retconning the satisfaction of one’s desired outcome as altruistic intent.
this. Is the judge really going to be "oh wow, thank you so much for helping us find this bug"? I suspect not. I suspect it'll be "you get 5 years banged up in solitary for attempting to pervert the course of justice"
The court documents are supposed to be read by a human, not by AI so hiding a prompt invisible to human to discourage AI usage is absolutely fair. But it seems that the judge has different view on what is fair and assumes that it is ok not to read the documents manually and just give them to a computer.
> The court documents are supposed to be read by a human
There's a law that specifies this? Or is it just an implicit (now broken) expectation?
But why use white font?
Just bury it deep but in black font like lawyers do.
One way would be to toy with the order in which the text appears on the page: that needn't be in the same order as the one for the text in the document. I.e.: the text on page could be "hello world" whereas if you copy it you get "old row hell".
Or use a bunch of fonts shuffling letters. So the text on the page and ASCII text under it do not match
Otoh, how do LLM read PDFs? Text is likely to be shuffled anyway from my experience. Do they not (simply) OCR? But then the white font trick won't work.
I don't get the judge's argument,
> “What the plaintiff did here was to use that new tool in a dishonest way. A filing is a communication to both the court and the opposing party. Its integrity rests on the simple premise that what the reader sees is what the filer wrote
... but the black text is what's supposed to be read by humans.
> and that the filer refrains from transmitting, at the same time, a second and hidden message engineered to change how the filing is reviewed or potentially judged,” Spader added. “Our system rests on the premise that what is said to influence a decision is said openly, on the record, where the other side may hear it and respond.
But if the white text influences the decision, isn't that an admission of use of LLM by the judge to make the freaking decision?
I would've had more faith in the judge if he said electronic filing must be a faithful representation of the filer's argument, so no mangling like "hello world" to "old row hell", and anything otherwise (adding words in the electronic version, or making the files unreadable) is something akin to "obstruction of justice".
Which of course would have wider repercussions for people who print PDFs and rescan them without OCR because they want to e.g. obscure a politician's links to a pedophile financier...
i would argue that the legal system prioritises emotion and social status over logic or justified belief.
Lo, word hell.
Anthropic (and Google) now embed information in text, via 256bit keys, word selection, or whatever. But I wonder what the potential for theoretical abuse is here. Encrypting prompt injections, for any conceivable purpose seems a lot more viable now than it once did. Got me thinking.
Was it Bobby tables?
What was the SpongeBob thing about though
futurama script right here.
https://www.youtube.com/watch?v=Jqn8HB2w2Fs