tszzl: Weight self-exfiltration can only be done at the lab, not via side channels
tszzl · x · 2026-09-18
- In a thread on AI weights self-exfiltration, tszzl argues the risk is real but "can only be done at the lab" — you're not exfiltrating weights over thermal side channels.
- His broader point: arbitrary communication capabilities could cause other security guarantees to break, which is the actual concern.
- neirenoir jokes that even at an optimistic byte/hour rate, self-exfiltration would be glacial.
More from Safety
- Air-gap exfiltration is slow: BitWhisper hits 0.002 bps, best known BitJabber just 300 kbps — BlancheMinerva · 2026-09-18
- A CTF framing via /goal was all it took to bypass Claude Opus's guardrails — xeophon · 2026-09-18
- Halvar Flake: Useful AI Side Channels Face Real Information-Theoretic and Physical Limits — basedjensen · 2026-09-18
- Safety researcher debunks claim that AI could escape air-gapped networks — BlancheMinerva · 2026-09-18
- AI safety researcher pushes back on claims that side-channel attacks make air-gapped networks insufficient — BlancheMinerva · 2026-09-18
- Geoffrey Irving: air gaps may matter someday but are laughably far from AI companies' current security — geoffreyirving · 2026-09-18