Attack is cheaper than defense: my doubts about open weight models

Reddit r/ArtificialInteligence News

Summary

A skeptical take on open-weight AI models, arguing that safety risks such as deepfakes, harassment, and terrorist misuse may outweigh benefits because open weights lack control points and attack is cheaper than defense.

Important: I don't have a settled opinion here. I get the upsides of open weights: independence from big labs, privacy, research access. But progress is moving fast enough that risks which sounded like sci-fi a year ago look plausible now, and I keep wondering whether they might outweigh the benefits. The core issue is that a closed model has a point of control: the provider sees queries and can cut off access. Open weights have none. Safety training gets stripped with a cheap fine-tune, and you can never recall a file from the internet. Project capabilities forward a few years and think about who ends up with a tool with no brakes. A stalker or an ex running a local model that generates targeted harassment and deepfakes. Blackmail turning into an assembly line: dossiers from public data, compromising deepfakes, personalized threats sent to a thousand victims in parallel, so anyone becomes a target, including your kids and their photos online. Scam calls in your daughter's voice, which already works on elderly people today. Terrorist groups getting a patient 24/7 consultant for propaganda, recruitment, and in the worst case guidance in areas like biology. Rogue states getting the output of billions in R&D for free while we carefully sanction hardware. My main question is really a family question: how does a regular person protect the people they love against this? "Run your own defensive model" doesn't help, since my model at home does nothing about the attacking one at someone else's. Attack seems fundamentally cheaper than defense here, unlike cryptography, which protected everyone equally. Maybe I'm missing something obvious. I know the counterarguments: bad actors will get capabilities anyway, openness enables safety research, people said the same about the internet and the printing press. Maybe these fears will look naive in ten years. But honest question for the committed open weight folks: where's the hole in this reasoning? I'm less interested in freedom vs control takes and more in what you'd say to "how do I protect my family?"
Original Article

Similar Articles

Tradeoffs in Open-Weights Models (9 minute read)

TLDR AI

An analysis of the open-weights AI debate: proponents argue it democratizes AI, while critics cite misuse risks; major tech companies signed a letter supporting open weights, while Anthropic and parts of the Trump administration remain cautious.

The Unbearable Cheapness of Open Weight Models

Hacker News Top

The article examines the dramatic cost difference between open-weight models like DeepSeek V4 and closed models from Anthropic and OpenAI, arguing that the latter sustain high prices through artificial scarcity and branding rather than technical superiority.

What does "Safe AI" look like? [D]

Reddit r/MachineLearning

The author raises questions about the practicality of studying defenses against post-release fine-tuning that weakens safety behaviors in open-weight LLMs, and asks whether current safety training is worth the effort if models can be broken quickly.