Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Electricity usage, network traffic patterns, etc. If a "data center" is consuming a ton of power but doesn't seem to have an alternate purpose, then it's probably training AI.

And maybe it will be like detecting nuclear enrichment. Instead of hacking the firmware in a Siemens device, it's done on server hardware. Israel demonstrated absurd competence at this caliber of spycraft.

Sometimes you take low-tech approaches to high tech problems. I.e., get an insider at a shipping facility to swap the labels on two pallets of GPUs, one is authentic originals from the factory and the other are hacked firmware variants of exactly the same models.



None of these techniques are actionable. So what, someone is training AI, it's not like anyone is proposing restricting that. People are trying to make a distinction between "bad AI" and "good AI", like that is a possibility, and that's what the argument basically is, that it's impossible to differentiate or detect the difference between those, and signing declarations pretending you can is worse than useless.


Making the "bad AI" vs "good AI" distinction pre-training is not feasible, but making a "bad use of AI" vs "good use of AI" (as in bad/good for the people) seems important to be able to do after-the-fact (and as close to during as possible).


> So what, someone is training AI, it's not like anyone is proposing restricting that

If nations chose to restrict that, such detection would merit a military response. Like Iran's centrifuges.


That's moving the goal post. The assertion was merely whether it's possible to detect if someone is performing large-scale AI training. People are saying it's impossible, but I was pointing out how it could be possible with a degree of confidence.

But if you want to talk about "actionable" here are three potential actions a country could take and the confidence level they need for such actions:

- A country looking for targets to bomb doesn't need much confidence. Even if they hit a weather prediction data center, it's going to hurt them.

- A country looking to arrest or otherwise sanction citizens needs just enough confidence to obtain a warrant (so "probably") and they can gather concrete evidence on the ground.

- A country looking to insert a mole probably doesn't need much evidence either. Even if they land in another type of data center, the mole is probably useful.

For most use cases, being correct more than half the time is plenty.


Isn’t that moving the goalposts? The claim was made that it’s impossible to detect AI training runs and investigate what’s going on or take regulatory action. In fact, it is very possible.


2 points:

1. I was just granting the GPs point to make the broader point that, for the purposes of this original discussion about these "safety declarations", this is immaterial. These safety declarations are completely unenforceable even if you could detect that someone was training AI.

2. Now, to your point about moving the goalposts, even though I say "if you could detect that someone was training AI", I don't actually even think that is possible. There are far too many normal uses of data centers to determine if one particular use is "training an AI" vs. some other data intensive use. I mean, there have long been supercomputer centers that do stuff like weather analysis and prediction, drug discovery analysis, astronomy tools, etc. that all look pretty indistinguishable from "training an AI" from the outside.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: