Here’s a conjecture: If you put any significant amount of text on the internet under different names, those identities can be linked using only the text itself.
The de-anonymization-by-text-fingerprint thing is the real pseudpocalypse. Most people don't realize their writing style is more identifying than their face.
Good article, I am writing something on this at the moment. The stylometry research is more advanced than you give it credit for, see the paper introducing LUAR that got 65 percent top eight accuracy out of 100,000
The approach they are using is definitely much closer to what I was envisioning. Though it's not totally obvious to me what to think of the numbers. Getting the right person in the top-8 65% of the time with 100k authors is pretty good. But I think it's fair to point out that top-8 is not top 1 and that 65% is not 95%. If we consider each of those "equal" to having 10 times fewer people, maybe that should be considered ~equivalent to 95% accuracy with a pool of 1k people? (To be clear, that's still quite a lot more than the number of 50 that I gave.)
Fwiw, when I put one of my posts into Gemini and asked it to infer my demographics it wasn't all that good.
Not quite directly speaking to your point about pseudonymity, but the sort of demographic fingerprinting that you touch on seems to be a bit further away.
Interesting. I do tend to think that the demographic features are harder to guess than personality or writing, but my experience testing my own writing as well as some other people's is that they can be guessed reasonably well. (In any case, I still stress that I don't think that current LLMs are at all good at any of this, so they don't serve as anything more than a loose lower-bound.)
"Demographic Bits", "Style Bits", "Personality Bits" -- which one of these is the one that captures, "I care about issues X Y Z, and my preferred mental framework / chain of thought for them is A->F->D->C, while involving anecdotes α,β,..."?
> Instead of “homogenizing” writing by imposing a generic style, perhaps it would be better to “camouflage” it by enforcing a very strong but random style.
You'll still get bit by the actual content. Unless everything you care and think about is exceedingly common.
So the next step is intent/interest dilution. Rather than having all content on your socials originate from yourself, you have AIs operate many dozens of accounts. Then, on occasion, when you really do want to say something by yourself, you ask your agent to pick out the most reasonable account to broadcast your message. Gains you both camo and reach.
I think you could cram some of those features into the vague "deep features" grab bag, but I think it's a fair criticism that I didn't mention topic, and I agree this provides a lot of bits. (As a rough estimate, how many people care enough about stylometry to write an article about it? Maybe 1%? That would be around 6.6 bits. But once your start thinking about intersections of topics, it's probably much larger. Maybe 10-20 bits?)
Regarding your last point, a few of people have suggested something similar, but I don't quite see how it would work. The reason is: If you have agents doing all this writing, are there people out there who are actually reading it? If the "real" messages you actually care about are distinguishable by humans from the others, then they will also be distinguishable by the attacker. So it seems like the only way this would work is that you're throwing your actual message into a mixture where it's not special in any way compared to the camouflage. At that point, why even bother operating the multiple accounts? Why not just send the actual message you care about as a one-off?
> are there people out there who are actually reading it?
Unfortunately, yes. I feel like gouging out my eyeballs looking at every AI generated account racking up millions of real readers. Have you seen the Substack front page?
> you're throwing your actual message into a mixture where it's not special in any way compared to the camouflage.
Like democracy, yeah. It's a different kind of participation than just getting to say what you want. But there's still a point to it.
> why even bother operating the multiple accounts?
Because you have different opinions and interests, and offload each of them to agents that best-fit their audiences.
This is the same principle under which a normal person from 2010 ends up operating 3 alts for different interests. Just, scale that to 300, and make your contribution (of intent) to each 1% instead of 100%.
Revealing a thin slice of yourself, over a few hundred profiles, is an impossible conspiracy to crack. Revealing all of yourself under one profile is trivial.
Oh, thanks, that is helpful. In a sense, is the idea to "split up your bits", so that you reveal some fraction under account A, some fraction under account B, etc.? That's interesting! I think you'd have to be quite careful about leakage / linkage, but in principle it seems like it could work.
> Even so, you’re probably bad at it. Take the example of GeoGuessr, where people guess a location in the world from a random photo. Random people are sort of OK, but if you pick the top natural talents and have them practice obsessively, they’re really good. I don’t think LLMs are particularly good at guessing features from text, either. They weren’t trained for it. It’s just an emergent property of their general intelligence. The information-theoretic limit is surely much higher.
It's a fair point. This wouldn't be hard at all to use this as an RL environment to improve reasoning. Given the seemingly sharp improvement of LLMs at this task, I suppose it's not that unlikely they were actually trained on it. The only reason I doubt this is that it seems kind of "expensive"? AFAICT, you'd need some kind of large hold-out dataset of writing that wasn't included in the base model. It's hard to imagine that AI companies would want to go to that much effort and would prune away data from their base models. But who knows! Maybe you can train this ability with very little held out data. Anyone want to leak some insider information?
In the Apple TV show "Sugar", John Sugar makes a guy by the type of watch he wears and how he looks at it. Doesn't take a computer. Of COURSE it's plausible. It's a plot point! ;)
IRL Flock is not just tracking your plate, but also the stickers on your vehicle and IDENTIFYING them. "I'd like a list of all vehicle owners in Roche's Run, ID who have resistance stickers on their vehicle".
Certainly some self-censorship, here already, is due to context collapse: one's readership now potentially includes ones s.o., boss, pastor, 3rd grade teacher, bdsm associates, the President... Your words don't go in separate boxes any more. Or as George Costanza tells it: "This is not good! Worlds are colliding! George is gettin' upset!"
I remember Polly Syndeton! Now that was a girl, yessiree...
I wonder how much people change their writing style over time. I'd suspect enough info is preserved that it's still obviously the same person, but probably enough changes to allow you to distinguish maybe to within a few years, possibly months(?) of when the text was written. Some obvious things are that one might cycle through specific words they find attractive (on top of baseline biases), but also general changes in what topics they write on. Hmm I wonder if you could do analysis of prolific authors and what similarities are preserved in their earlier and later texts. Obviously you have people who made famous large shifts like Wittgenstein, but maybe smaller subtle trends are more interesting.
I think biblical studies does lots of textual analysis to try and determine authorship, era in which a text was written. They may have some interesting strategies.
Similarly interesting if an LLM could link e.g. someone's rationalist blogging with their romantasy fanfic, or if the genre gap would inject enough noise to make it a harder problem
If you drop the romantasy qualifier, I might be able to test this sometime soon! (soon as in "as soon as the LLMs start being able to identify my blog," which should be pretty soon indeed…)
I wonder if some genres of text are so templated that they leave the author over-constrained and so leak less bits, e.g. tightly rhyming poetry, highly tropey genre-fiction, detached style of scientific papers
I think I read a book on writing (maybe by Russo) where he mentions a "genre fiction" friend would take a finished text and intentionally remove any expressions that were non-cliche, on the theory that he didn't want the audience to sort of get knocked out of their comfort zone.
> Madison liked by. Hamilton was more a to man. Using these kinds of statistics, they concluded that the disputed Federalist papers must have been written by Madison.
Did you ask an LLM to run its own authorial analysis of the Federalist papers? Seems like a fun replication.
(I was going to write this under an anonymous name, as my comments have nothing to do with my other posts with this account, but you're telling me that's wasted effort...)
Perhaps another layer to the onion:
The story I used to hear regarding radar detectors is that the same company who made the radars made the detectors, and they incremented one power to force the other in an indefinite refresh cycle required for both police and consumers. Don't know if it was real, but a cute mental image regardless.
Same thought here. At any one point in time, a state of the art algorithm could find my unique signature. But as soon as that signature is found, an AI LLM or equivalent could be programmed to convert a passage to either obstruct my signature, or actually present someone else's work as if it were mine. In a static world (with one state of the art system), this then regains anonymity.
But those algorithms were only state-of-the-art at the time they were written, and if the posts are wayback-machine archived, then we can always look back with our new radar-detector algorithm developed a year later and find the extra few bits that our old generation missed. So you have only temporary-anonymity.
Regardless, I agree with the general observation - anonymity is vanishing. And many measures of privacy are in tow behind. The implications of this are profound, and I don't appreciate even the tip of the iceberg of them all.
All reasonable, though I'm generally optimistic about countermeasures. In in an information-theoretic sense, isn't it pretty feasible to inject enough noise such that it becomes expensive for an adversary to discriminate? Like, radio jamming just works and even a S/N of 1 makes communication hard.
Three ways to do this with text:
1. Inject noise into your text (you covered this)
2. Sock puppet accounts that you post through (adversary has to scan all accounts for similarity to yours)
3. Decoys that intentionally generate text similar to yours but not authored by you (I have an old draft on this about how LLMs unlock deniable social media)
Specifically for internet anonymity, I thought TOR and other mixnets had solutions for adversaries analyzing traffic flow?
Yeah, I'm fairly optimistic about the possibility text-based countermeasures. But I think they'd really have to be quite profound in terms of how much they rewrite. After all, no matter what you do, you're still leaking *some* bits. So if you want to preserve pseudonymity over a much longer timespan, you'll need to really aggressively remove anything that makes you unique. Sad!
In terms of having decoy posting, the thing to me is: Does the attacker know if anyone is actually reading the stuff you write? Because if they do, then either you need to trick lots of humans into reading your fake text, or you need to be shouting into the void yourself. If other people can tell that the "real you" is more interesting, then that signal will be available to attackers as well.
Yup, one refinement: pseudonymity requires making different identities unlinkable, not necessarily inauthentic. So you could have one authentic account, but your other ones do need to be inauthentic.
RE: decoys, yeah any degree of privacy is dependent on a system of private messaging and private activity on your computer. If an adversary can see all your messages and activity then there isn't a foundation to build any other privacy measures. But I do think this level of surveillance can be made prohibitively expensive at least for stuff you do on your computer.
Contrast with [this recent Veritasium video](https://www.youtube.com/watch?v=mvcesPWvUIc). Gwern's Death Note analysis is interesting (I'm a fan of Gwern's work, generally speaking), but it's not very practical. Light Yagami only has to write a name to kill somebody instantly and anonymously by heart attack, which is a very cheap action. Most of what you'd have to do to optimize against information leakage would make the act of executing criminals prohibitively expensive time-wise.
Assuming that you're a monstrously efficient machine and that there are only 120,000 criminals worthy of assassinating in the world, it will take you over 150 hours to write down all their names if that's all you're doing. Assigning a random time probably at least triples the time cost per criminal, bringing the total to 450 hours. But something like arranging for randomized cause of death? Assuming you've still got to manually pen each of these in, you're talking about increasing the time investment by an order of magnitude, which you can only afford to do once here, and I think this is still assuming good efficiency on the part of the user.
Employing involved red herrings would astronomically increase your expected time cost per criminal. I think that once you've exceeded three minutes per criminal, they lock you up for criminal inefficiency yourself. I'm not sure.
Granted, you could circumvent all of this overhead if you played around with printing directly onto Death Note parchment and scripting random generators, but, like, it would be a very different kind of story at that point, sorta reminiscent of HPMOR.
I mean, I think all the effort of trying to evade L/the police ends up costing Light a LOT more time in the end (and eventually his life, obviously). This whole thing is moot anyway—Light clearly wanted people to know that Kira existed and was a real guy, and in doing so gave most of the game away already.
Not a lot more, really. If you were to deploy the full suite of SecOps, assuming the rules of the universe don't allow you to utilize computer printing (which would probably violate the face-visualizing rule), it could easily push your time cost up to 50,000+ hours, assuming only 120,000 target criminals.
I agree that the whole thing is sort of moot. I was mildly annoyed by what struck me as pretension in Gwern's article, and felt compelled to point out the apparent oversight.
If this technology were developed, it could have interesting applications to historic texts, eg determining the authentic authors of texts whose authorship is disputed. We could put an end to the "Shakespeare didn't write his plays conspiracies", figure out how many authors the Bible has and which bits were written by the same person, etc. I'd like to think that if we end up in the scenario where this technology exists but it's illegal to depseudonymise someone without a warrant, there'd be some kind of exception carved out for historical research
I've cultivated an ability to guess someone's MBTI within a few minutes of meeting them. People sometimes find it impressive, but the truth is that most of these things are really quite gigantic obvious features, and very easy to guess with a tiny bit of practice...
I gave GPT the first 561 words of this essay and it guessed it was you with 65% confidence. It claimed to not find any of the text directly, and none of its sources linked directly to your page, but did link to a Less Wrong blog by Smaug123 on the same topic it seemed to think was important. Its other two guesses were Scott Alexander and Gwern.
You touch on this but I don't think you get all the way there: All of these bits also serve as proof of authorship, which will be more and more valuable as non-AI text gains a premium. AI may be better and better at generating generically high-value text, but based on this essay I think it would be harder to generate increasingly long and internally-consistently-fingerprinted text against higher-resolution evaluation. Currently for a lot of uses cases it's substantially cheaper to get AI to write something than hire a human to write something, but it may never (not for longer) be cheaper to get AI to write 10,000 words of something that was demonstrably written by a 28-36 year old female graduate student of east asian descent who grew up in northern england but is now living in southwestern london, took two years of Spanish, and was influenced by acting in Macbeth as a kid,
No, you're right, I didn't mention this at all! This is an interesting thought. It seems plausible to me that we could get both the kind of stylometry I'm speculating about and *also* the ability for LLMs to write very plausibly in a particular voice. (Personally, I think the main reason we don't have more of the latter already is just a lack of investment.) I suppose this could provide some kind of "camouflage privacy"? Like: I could generate lots of pseudonyms have have an LLM write various things in my voice under each of them. Then, in principle, the attacker couldn't know which texts actually represent my voice. However... while that works mathematically, I don't think it really works in practice, because the attacker could just look at what pseudonyms are actually popular. So either you're shouting into the void in you real voice, or you're tricking lots of people into reading fake-LLM you? Very odd.
The de-anonymization-by-text-fingerprint thing is the real pseudpocalypse. Most people don't realize their writing style is more identifying than their face.
Good article, I am writing something on this at the moment. The stylometry research is more advanced than you give it credit for, see the paper introducing LUAR that got 65 percent top eight accuracy out of 100,000
Happy to be corrected! Do you mean this paper? https://aclanthology.org/2021.emnlp-main.70.pdf
The approach they are using is definitely much closer to what I was envisioning. Though it's not totally obvious to me what to think of the numbers. Getting the right person in the top-8 65% of the time with 100k authors is pretty good. But I think it's fair to point out that top-8 is not top 1 and that 65% is not 95%. If we consider each of those "equal" to having 10 times fewer people, maybe that should be considered ~equivalent to 95% accuracy with a pool of 1k people? (To be clear, that's still quite a lot more than the number of 50 that I gave.)
Yeah I agree, it's still far from what you mean, but I pointed it out because it's a notable increment in stylometry above the 1 in 50 baseline.
My hope is we leak enough that one day we will be able to recreate at least the modern dead.
Fwiw, when I put one of my posts into Gemini and asked it to infer my demographics it wasn't all that good.
Not quite directly speaking to your point about pseudonymity, but the sort of demographic fingerprinting that you touch on seems to be a bit further away.
Interesting. I do tend to think that the demographic features are harder to guess than personality or writing, but my experience testing my own writing as well as some other people's is that they can be guessed reasonably well. (In any case, I still stress that I don't think that current LLMs are at all good at any of this, so they don't serve as anything more than a loose lower-bound.)
"Demographic Bits", "Style Bits", "Personality Bits" -- which one of these is the one that captures, "I care about issues X Y Z, and my preferred mental framework / chain of thought for them is A->F->D->C, while involving anecdotes α,β,..."?
> Instead of “homogenizing” writing by imposing a generic style, perhaps it would be better to “camouflage” it by enforcing a very strong but random style.
You'll still get bit by the actual content. Unless everything you care and think about is exceedingly common.
So the next step is intent/interest dilution. Rather than having all content on your socials originate from yourself, you have AIs operate many dozens of accounts. Then, on occasion, when you really do want to say something by yourself, you ask your agent to pick out the most reasonable account to broadcast your message. Gains you both camo and reach.
I think you could cram some of those features into the vague "deep features" grab bag, but I think it's a fair criticism that I didn't mention topic, and I agree this provides a lot of bits. (As a rough estimate, how many people care enough about stylometry to write an article about it? Maybe 1%? That would be around 6.6 bits. But once your start thinking about intersections of topics, it's probably much larger. Maybe 10-20 bits?)
Regarding your last point, a few of people have suggested something similar, but I don't quite see how it would work. The reason is: If you have agents doing all this writing, are there people out there who are actually reading it? If the "real" messages you actually care about are distinguishable by humans from the others, then they will also be distinguishable by the attacker. So it seems like the only way this would work is that you're throwing your actual message into a mixture where it's not special in any way compared to the camouflage. At that point, why even bother operating the multiple accounts? Why not just send the actual message you care about as a one-off?
> are there people out there who are actually reading it?
Unfortunately, yes. I feel like gouging out my eyeballs looking at every AI generated account racking up millions of real readers. Have you seen the Substack front page?
> you're throwing your actual message into a mixture where it's not special in any way compared to the camouflage.
Like democracy, yeah. It's a different kind of participation than just getting to say what you want. But there's still a point to it.
> why even bother operating the multiple accounts?
Because you have different opinions and interests, and offload each of them to agents that best-fit their audiences.
This is the same principle under which a normal person from 2010 ends up operating 3 alts for different interests. Just, scale that to 300, and make your contribution (of intent) to each 1% instead of 100%.
Revealing a thin slice of yourself, over a few hundred profiles, is an impossible conspiracy to crack. Revealing all of yourself under one profile is trivial.
Oh, thanks, that is helpful. In a sense, is the idea to "split up your bits", so that you reveal some fraction under account A, some fraction under account B, etc.? That's interesting! I think you'd have to be quite careful about leakage / linkage, but in principle it seems like it could work.
> Even so, you’re probably bad at it. Take the example of GeoGuessr, where people guess a location in the world from a random photo. Random people are sort of OK, but if you pick the top natural talents and have them practice obsessively, they’re really good. I don’t think LLMs are particularly good at guessing features from text, either. They weren’t trained for it. It’s just an emergent property of their general intelligence. The information-theoretic limit is surely much higher.
Interestingly, LLMs are also astoundingly good at GeoGuessr despite not being trained for it! See Scott Alexander's article on the subject from a year ago (https://www.astralcodexten.com/p/testing-ais-geoguessr-genius)
> despite not being trained for it!
who said that?
It's a fair point. This wouldn't be hard at all to use this as an RL environment to improve reasoning. Given the seemingly sharp improvement of LLMs at this task, I suppose it's not that unlikely they were actually trained on it. The only reason I doubt this is that it seems kind of "expensive"? AFAICT, you'd need some kind of large hold-out dataset of writing that wasn't included in the base model. It's hard to imagine that AI companies would want to go to that much effort and would prune away data from their base models. But who knows! Maybe you can train this ability with very little held out data. Anyone want to leak some insider information?
I would guess that they haven't, simply based on the occasional regression from model to model (see https://www.lesswrong.com/posts/T5aWBLDdkqPEzDhjZ/claude-doesn-t-know-who-you-are?commentId=xsYSCdgh3LRzEDiHD)
A few thoughts:
In the Apple TV show "Sugar", John Sugar makes a guy by the type of watch he wears and how he looks at it. Doesn't take a computer. Of COURSE it's plausible. It's a plot point! ;)
IRL Flock is not just tracking your plate, but also the stickers on your vehicle and IDENTIFYING them. "I'd like a list of all vehicle owners in Roche's Run, ID who have resistance stickers on their vehicle".
Certainly some self-censorship, here already, is due to context collapse: one's readership now potentially includes ones s.o., boss, pastor, 3rd grade teacher, bdsm associates, the President... Your words don't go in separate boxes any more. Or as George Costanza tells it: "This is not good! Worlds are colliding! George is gettin' upset!"
I remember Polly Syndeton! Now that was a girl, yessiree...
I wonder how much people change their writing style over time. I'd suspect enough info is preserved that it's still obviously the same person, but probably enough changes to allow you to distinguish maybe to within a few years, possibly months(?) of when the text was written. Some obvious things are that one might cycle through specific words they find attractive (on top of baseline biases), but also general changes in what topics they write on. Hmm I wonder if you could do analysis of prolific authors and what similarities are preserved in their earlier and later texts. Obviously you have people who made famous large shifts like Wittgenstein, but maybe smaller subtle trends are more interesting.
I think biblical studies does lots of textual analysis to try and determine authorship, era in which a text was written. They may have some interesting strategies.
Similarly interesting if an LLM could link e.g. someone's rationalist blogging with their romantasy fanfic, or if the genre gap would inject enough noise to make it a harder problem
If you drop the romantasy qualifier, I might be able to test this sometime soon! (soon as in "as soon as the LLMs start being able to identify my blog," which should be pretty soon indeed…)
I wonder if some genres of text are so templated that they leave the author over-constrained and so leak less bits, e.g. tightly rhyming poetry, highly tropey genre-fiction, detached style of scientific papers
I think I read a book on writing (maybe by Russo) where he mentions a "genre fiction" friend would take a finished text and intentionally remove any expressions that were non-cliche, on the theory that he didn't want the audience to sort of get knocked out of their comfort zone.
> Madison liked by. Hamilton was more a to man. Using these kinds of statistics, they concluded that the disputed Federalist papers must have been written by Madison.
Did you ask an LLM to run its own authorial analysis of the Federalist papers? Seems like a fun replication.
(I was going to write this under an anonymous name, as my comments have nothing to do with my other posts with this account, but you're telling me that's wasted effort...)
Perhaps another layer to the onion:
The story I used to hear regarding radar detectors is that the same company who made the radars made the detectors, and they incremented one power to force the other in an indefinite refresh cycle required for both police and consumers. Don't know if it was real, but a cute mental image regardless.
Same thought here. At any one point in time, a state of the art algorithm could find my unique signature. But as soon as that signature is found, an AI LLM or equivalent could be programmed to convert a passage to either obstruct my signature, or actually present someone else's work as if it were mine. In a static world (with one state of the art system), this then regains anonymity.
But those algorithms were only state-of-the-art at the time they were written, and if the posts are wayback-machine archived, then we can always look back with our new radar-detector algorithm developed a year later and find the extra few bits that our old generation missed. So you have only temporary-anonymity.
Regardless, I agree with the general observation - anonymity is vanishing. And many measures of privacy are in tow behind. The implications of this are profound, and I don't appreciate even the tip of the iceberg of them all.
All reasonable, though I'm generally optimistic about countermeasures. In in an information-theoretic sense, isn't it pretty feasible to inject enough noise such that it becomes expensive for an adversary to discriminate? Like, radio jamming just works and even a S/N of 1 makes communication hard.
Three ways to do this with text:
1. Inject noise into your text (you covered this)
2. Sock puppet accounts that you post through (adversary has to scan all accounts for similarity to yours)
3. Decoys that intentionally generate text similar to yours but not authored by you (I have an old draft on this about how LLMs unlock deniable social media)
Specifically for internet anonymity, I thought TOR and other mixnets had solutions for adversaries analyzing traffic flow?
Yeah, I'm fairly optimistic about the possibility text-based countermeasures. But I think they'd really have to be quite profound in terms of how much they rewrite. After all, no matter what you do, you're still leaking *some* bits. So if you want to preserve pseudonymity over a much longer timespan, you'll need to really aggressively remove anything that makes you unique. Sad!
In terms of having decoy posting, the thing to me is: Does the attacker know if anyone is actually reading the stuff you write? Because if they do, then either you need to trick lots of humans into reading your fake text, or you need to be shouting into the void yourself. If other people can tell that the "real you" is more interesting, then that signal will be available to attackers as well.
Yup, one refinement: pseudonymity requires making different identities unlinkable, not necessarily inauthentic. So you could have one authentic account, but your other ones do need to be inauthentic.
RE: decoys, yeah any degree of privacy is dependent on a system of private messaging and private activity on your computer. If an adversary can see all your messages and activity then there isn't a foundation to build any other privacy measures. But I do think this level of surveillance can be made prohibitively expensive at least for stuff you do on your computer.
See also Gwern's post on this topic: https://gwern.net/death-note-anonymity and Terence Tao: https://gwern.net/doc/cs/security/2012-terencetao-anonymity.html
Contrast with [this recent Veritasium video](https://www.youtube.com/watch?v=mvcesPWvUIc). Gwern's Death Note analysis is interesting (I'm a fan of Gwern's work, generally speaking), but it's not very practical. Light Yagami only has to write a name to kill somebody instantly and anonymously by heart attack, which is a very cheap action. Most of what you'd have to do to optimize against information leakage would make the act of executing criminals prohibitively expensive time-wise.
Assuming that you're a monstrously efficient machine and that there are only 120,000 criminals worthy of assassinating in the world, it will take you over 150 hours to write down all their names if that's all you're doing. Assigning a random time probably at least triples the time cost per criminal, bringing the total to 450 hours. But something like arranging for randomized cause of death? Assuming you've still got to manually pen each of these in, you're talking about increasing the time investment by an order of magnitude, which you can only afford to do once here, and I think this is still assuming good efficiency on the part of the user.
Employing involved red herrings would astronomically increase your expected time cost per criminal. I think that once you've exceeded three minutes per criminal, they lock you up for criminal inefficiency yourself. I'm not sure.
Granted, you could circumvent all of this overhead if you played around with printing directly onto Death Note parchment and scripting random generators, but, like, it would be a very different kind of story at that point, sorta reminiscent of HPMOR.
I mean, I think all the effort of trying to evade L/the police ends up costing Light a LOT more time in the end (and eventually his life, obviously). This whole thing is moot anyway—Light clearly wanted people to know that Kira existed and was a real guy, and in doing so gave most of the game away already.
Not a lot more, really. If you were to deploy the full suite of SecOps, assuming the rules of the universe don't allow you to utilize computer printing (which would probably violate the face-visualizing rule), it could easily push your time cost up to 50,000+ hours, assuming only 120,000 target criminals.
I agree that the whole thing is sort of moot. I was mildly annoyed by what struck me as pretension in Gwern's article, and felt compelled to point out the apparent oversight.
There is an author who I can distinctly identify off of literally just their extra-frequent use of liana, mellifluous, and swarthy.
Ten thousand points to whoever finds them off of this hint
If this technology were developed, it could have interesting applications to historic texts, eg determining the authentic authors of texts whose authorship is disputed. We could put an end to the "Shakespeare didn't write his plays conspiracies", figure out how many authors the Bible has and which bits were written by the same person, etc. I'd like to think that if we end up in the scenario where this technology exists but it's illegal to depseudonymise someone without a warrant, there'd be some kind of exception carved out for historical research
I asked my ChatGPT to analyze me based on the Hexaco framework you provided. It nailed me except on a few dimensions we had never interacted.
I've cultivated an ability to guess someone's MBTI within a few minutes of meeting them. People sometimes find it impressive, but the truth is that most of these things are really quite gigantic obvious features, and very easy to guess with a tiny bit of practice...
I gave GPT the first 561 words of this essay and it guessed it was you with 65% confidence. It claimed to not find any of the text directly, and none of its sources linked directly to your page, but did link to a Less Wrong blog by Smaug123 on the same topic it seemed to think was important. Its other two guesses were Scott Alexander and Gwern.
Oh, I believe it. What's the post by Smaug123 though?
Claude Knows Who You Are & Claude.... Doesn't Know Who You Are
https://www.lesswrong.com/posts/Jkb4CBB7rf4XYP5eb/claude-knows-who-you-are
https://www.lesswrong.com/posts/T5aWBLDdkqPEzDhjZ/claude-doesn-t-know-who-you-are
Disclaimer, I did not read the appendix.
You touch on this but I don't think you get all the way there: All of these bits also serve as proof of authorship, which will be more and more valuable as non-AI text gains a premium. AI may be better and better at generating generically high-value text, but based on this essay I think it would be harder to generate increasingly long and internally-consistently-fingerprinted text against higher-resolution evaluation. Currently for a lot of uses cases it's substantially cheaper to get AI to write something than hire a human to write something, but it may never (not for longer) be cheaper to get AI to write 10,000 words of something that was demonstrably written by a 28-36 year old female graduate student of east asian descent who grew up in northern england but is now living in southwestern london, took two years of Spanish, and was influenced by acting in Macbeth as a kid,
No, you're right, I didn't mention this at all! This is an interesting thought. It seems plausible to me that we could get both the kind of stylometry I'm speculating about and *also* the ability for LLMs to write very plausibly in a particular voice. (Personally, I think the main reason we don't have more of the latter already is just a lack of investment.) I suppose this could provide some kind of "camouflage privacy"? Like: I could generate lots of pseudonyms have have an LLM write various things in my voice under each of them. Then, in principle, the attacker couldn't know which texts actually represent my voice. However... while that works mathematically, I don't think it really works in practice, because the attacker could just look at what pseudonyms are actually popular. So either you're shouting into the void in you real voice, or you're tricking lots of people into reading fake-LLM you? Very odd.