- cross-posted to:
- technology@beehaw.org
- cross-posted to:
- technology@beehaw.org
Is this the first step towards using local LLMs for anonymity? 🫠 Always rephrasing each sentence somewhat. Truly dystopian stuff
Have they tried doing this for Satoshi Nakamoto yet?
The bright side - they can also be used to mask pseudonymous users. Guess how.
I am so grateful for already having been paranoid about sharing anything identifying about me starting 15+ years ago.
I never uploaded a picture of myself. Never used my real name anywhere. I used different nicks for different branches of the Internet. A plethora of different email addresses etc.
People thought I was being overly careful and I probably missed a lot of things due to not using Whatsapp, Facebook, Instagram, Twitter, Snapchat but I can’t say I regretted it at any point.
It’s not enough. You should use a different writing style for each website you write on.
Hmmm interesting. I’ve never used AI to try and find out stuff about myself. Maybe I’ll try. Just curious.
That’s howb they get you
I think this will only work with people narrating their lives on social media.
“Got coffee from my favorite Granier at La Rambla! Ready of new day of work designing hats for dogs”
“Me and Bobby heading to Madrid to see my friend Concepcion. Do you like his new hat?”
“Just got nominated for ‘best business-casual hat’ at this year’s Barkies! So proud”
Because how are you going to de-anonymize some random ramblings about Linux and beans? Everyone likes Linux and beans.
This is good advice. Pick a person you know and drop hints that you’re them. Bonus points if that person is terminally online. Anyway, gotta get back to running X.
Holy shit, guys! Its the Antichrist!
Nope. It’s in special tiny ways we author text. I think.
Yeah. I got a hunch of that a while ago, while trying some “old” scenarios of de-anonymization we used to do by hand. Just asking questions and posting pictures got surprisingly accurate results. A single picture with (to me) no significant landmark could lead to localizing a specific part of a city, and that was using a local LLM with a relatively small model, running on a 16GB VRAM 4060Ti.
It is now time to remember fondly the time where the younger people were warned by older people to not post all their stuff online, not over-share, be cautious about strangers, etc. I’m not sure when we lost that, but oh boy, it’s a festival.
Kind of obvious. If you’re a highschool teacher and you used to be a photographer. You also volunteer as a fireman. You live in France. You heve 2 daughters. In 2022 you asked about repairs on your honda civic.
All off this can be amassed from different posts on facebook or reddit. There’ll be just a few people that fit this profile.From a Facebook post I made on February 17th:
There are giant AI data firms that promise they can go through massive troves of data and pull out general and specific information from them. Information that is actionable and accurate. Give it 6 million data points and it’ll find all the links and organize them for you and unmask hidden details that aren’t visible to the naked eye.
Not one of those companies is stepping up to go through the publicly released Epstein files.
There were reports of people trying to unredact the files almost immediately.
But that’s not the same, is it?
This is what I find crazy. Where are the AI bros chewing through the Epstein files?
I would be shocked if someone hasn’t shoved them into a local model somewhere, but all the big ones would filter them to death with content restrictions
We wouldn’t want that tbh. Justice needs to be precise and backed up by tangible facts
You can use the results of the AI analysis to identify people and then use that to do a proper investigation. Right now none of that is happening. No speculation. No tangibles. No investigation. No indictment.
Trying to unmask people is a step in the right direction.
I’m not a fan of genAI for most things, and the environmental aspect sucks balls, but this seems like a reasonable use of the tool that’s already been built.
Right?
At the very worst, the administration would put out a very confusing statement not to trust AI.
Also don’t use dna tests or chemical analysis. It’s invisible hocus pocus and can be wrong! And woe if someone that fucks and tortures kids regularly is wrongly accused of raping kids and running their child minds no that would be awful
I theorized about this a long time ago. pretty sure I’m basically fucked
As a registered Republican woman from Texas with five children and two dogs, let me just say that I am astonished!
As true as my name is Brenda and my last name is also Brenda. And so is my husband, Brenda. It is a hot day in Texas America today, I’m going to grill one of our dogs for dinner. It is a hot day republican tradition to grill a dog. Hence the name Hot Dogs and the playful name Wieners, named after wiener dogs. Oh lordy bless you heart yeehaa.
Me too. I thought I was safe as a Ottoman Empire expatriate living in Arrakis! I don’t want LLMs to connect this account to my pseudonymous mommy blog where I write about my three children who might exist but could be delusions of my untreated schizophrenia.
Oh, WE EXIST, mommy! Let me assure you, as one of said imaginary schizophrenia babies. Currently shacking up in Miami with my new wife I just met cranking my hog at Sturgis.
I don’t believe this! As a fumgrian living as a would be dead camoose off Mt. Kabul, I am overjizzed that AI is reading all my pornhub comments.
It seems that i, the original Unidan, will unfortunately need to create even more alts to escape being found out. Blast!
It seems that i, also the original Unidan, will unfortunately need to create even more alts to escape being found out. Blast!
We talking jackdaws/crows?
You forgot to list your favorite brands
Kegel One
Kleenex and Jergens
That was surprisingly accurate. Meep meep.
Brazil has 200 million ppl, how they would find someone in Rio like me?
Of course, another option is for people to dramatically curb their use of social media, or at a minimum, regularly delete posts after a set time threshold.
Deletion won’t deal with someone seriously-interested in harvesting stuff, because they can log it as it becomes available. And curbing use isn’t ideal.
I mentioned before the possibility of poisoning data, like, sporadically adding some incorrect information about oneself into one’s comments. Ideally something that doesn’t impact the meaning of the comments, but would cause a computer to associate one with someone else.
There are some other issues. My guess is that it’s probably possible to fingerprint someone to a substantial degree by the phrasing that they use. One mole in the counterintelligence portion of the FBI, Robert Hanssen, was found because on two occasions he used the unusual phrase “the purple-pissing Japanese”.
FBI investigators later made progress during an operation where they paid disaffected Russian intelligence officers to deliver information on moles. They paid $7 million to KGB agent Aleksander Shcherbakov[48] who had access to a file on “B”. While it did not contain Hanssen’s name, among the information was an audiotape of a July 21, 1986, conversation between “B” and KGB agent Aleksander Fefelov.[49] FBI agent Michael Waguespack recognized the voice in the tape, but could not remember who it was from. Rifling through the rest of the files, they found notes of the mole using a quote from George S. Patton’s speech to the Third Army about “the purple-pissing Japanese”.[50] FBI analyst Bob King remembered Hanssen using that same quote. Waguespack listened to the tape again and recognized the voice as Hanssen’s. With the mole finally identified, locations, dates, and cases were matched with Hanssen’s activities during the period. Two fingerprints collected from a trash bag in the file were analyzed and proved to be Hanssen’s.[51][52][53]
That might be defeated by passing text through something like an LLM to rewrite it. So, for example, to take a snippet of my above comment:
Respond with the following text rephrased sentence by sentence, concisely written as a British computer scientist might write it:
Deletion won’t deal with someone seriously-interested in harvesting stuff, because they can log it as it becomes available. And curbing use isn’t ideal.
I mentioned before the possibility of poisoning data, like, sporadically adding some incorrect information about oneself into one’s comments. Ideally something that doesn’t impact the meaning of the comments, but would cause a computer to associate one with someone else.
I get:
The deletion of data alone will not prevent a determined party from gathering information, as they may simply record the information as it becomes available prior to its deletion. Moreover, restricting usage is not an ideal solution to the problem at hand.
I previously mentioned the possibility of introducing deliberate errors or misinformation into one’s own data, such as periodically inserting inaccurate details about oneself within comments. The goal would be to include information that does not significantly alter the meaning of the comment, but which would cause automated systems to incorrectly associate that individual with another person.
That might work. One would have to check the comment to make sure that it doesn’t mangle the thing to the point that it is incorrect, but it might defeat profiling based on phrasing peculiarities of a given person, especially if many users used a similar “profile” for comment re-writing.
A second problem is that one’s interests are probably something of a fingerprint. It might be possible to use separate accounts related to separate interests — for example, instead of having one account, having an account per community or similar. That does undermine the ability to use reputation generated elsewhere (“Oh, user X has been providing helpful information for five years over in community X, so they’re likely to also be doing so in community Y”), which kind of degrades online communities, but it’s better than just dropping pseudonymity and going 4chan-style fully anonymous and completely losing reputation.
Your above average use of the word “one” and variations like “one’s” could be quite telling.
As could my correction of “it’s” in the above sentence.
As well as your use of fancy quote marks.
Regarding the last point: it’s more of a bias, tho, so it may even be a good thing. E.g. asking Kent Overstreet’s opinion on your bcachefs setup is probably useful, while getting relationship advice from him is ill-advised.
Advice being right or wrong isn’t necessarily the big issue for online communities (unless most other users are also wrong). What really degrades them is users acting like assholes, and someone who acts like that in a tech community is fairly likely to also do that in a political or relationship community.
Why is curbing use unideal?
We like internet
Great, we’re at a point where “researchers” are helping tech bros hurt the public interest. Could they just NOT publish this shit? Stop giving helpful tips to tyrannical oligarchs!
Academics can be stupid idiots sometimes.
Researchers’ work has always been abused by others. The advancement and free distribution of knowledge should not be curtailed for fear of malicious parties.
Average people download gamed and apps and their phone is loaded to the tilt with bloatware. You think they care?
The average person puts their entire lives on Facebook or linkedin with their real names…they don’t give a shit.
LinkedIn, if used properly, should just be professional/career related content. If you put anything overly personal or controversial, you are using it wrong.
I’m not saying that people don’t do that though.
When it first started linkedin was a good idea, now it’s just filled with FB equivalent posts about fake job titles and bullshit posts. It went from being a place for professionals to a place of half these people have no experience outside of door dash but want to say they’re a CEO of their own company.
“WeLl I hAvE nOtHiNg To HiDe”
Then let me record you fucking. Its for science only, I promise.
The number of times I’ve heard this from people in the secops field is frighteningly high.













