Discussion about this post

User's avatar
Felix Choussat's avatar

Good article! I'm hoping to write something similar on the practical feasibility of MAIM. Some thoughts:

"This means the framing is not “should we accept slowdown to reduce sabotage risk?” but instead “what is the additional cost for MAIM-specific hardening beyond the baseline security investment we should already be making?” I believe the delta is smaller than MAIM proponents suggest.

Moreover, if the incentive is to race, and the race matters, then hardening actually makes the trade-off worth it— because without it, your opponent can immediately copy whatever you develop through espionage, effectively ‘teleporting’ to your technological level. Without hardening, the U.S. bears all development costs while China gets the benefits nearly for free. In that sense, hardening isn’t a racing slowdown relative to China; instead, it’s preventing China from matching U.S. speed by stealing the country’s technological advances."

This section makes the argument that necessary hardening and MAIM-specific hardening is nearly one and the same, by virtue of the fact that a) the cyberdefenses needed to prevent against model theft are already very comprehensive, and b) that physical defenses won’t need to be implemented, because they could be sidestepped by placing targets close to cities.

I roughly agree with point a). B), on the other hand, presumes that physical destruction (a “hard kill”) is the only alternative to remote sabotage. But there are probably many “soft kill” approaches either country could take before they’d escalate to this extent. One of these options is to use an EMP device to bake the GPUs within the datacenter: these could be delivered through conventional cruise missiles like HiJENKS (which would only need to fly nearby), or have a swarm of drones carrying e-bombs. Likewise, local power could be easily taken out, either by using cyberattacks on the plants providing the electricity (as Russia repeatedly showcased in Ukraine), or by using small graphite bombs to take out the on-site grid connection.

Of course, these options would be less certain than just bombing the building outright, but they’re 1) still plausibly effective enough to permanently disable the compute, and 2) can serve as a limited demonstration of rival capabilities and commitment, increasing the credibility and deterrence effect of possible kinetic strikes.

It’s also worth noting that, throughout the Cold War, the U.S. did in fact avoid placing its ICBMs and missile silos near cities, despite the fact that this would have reduced the credibility of Soviet threats.

“By “hardening,” I mean a range of security measures, including: air-gapping sensitive systems, distributing infrastructure across multiple geographically dispersed facilities, improving cybersecurity and access controls, implementing stricter personnel vetting, maintaining operational security around development timelines, etc. This is not primarily about physical hardening (e.g., underground datacenters), but rather about reducing the probability of successful remote sabotage through layered defensive measures.

Another note I want to make re: hardening is that in Superintelligence Strategy, hardening is framed as difficult, time-consuming, and cost-prohibitive, with the major example being building datacenters underground to increase resilience to kinetic strikes.”

It is not obvious to me that this level of great-power cyberdefense (something like the SL5 standard) could actually be implemented so smoothly (or that it’s possible in the first place—even the NSA gets hacked). In particular, integrating remote clusters with extremely long network interconnects and airgapping research would development fragile and less efficient. These are engineering problems without existing solutions, and in the case of airgapping, would impose ongoing efficiency penalties (since researchers would lose the ability to pull from external datasets, easily train models online, or collaborate across sites synchronously).

No posts

Ready for more?