


Extract millions of features from Claude 3 and understand the 'thinking' of large models in detail for the first time
Just now, Anthropic announced significant progress in understanding the inner workings of artificial intelligence models.
Anthropic has identified how to represent millions of concepts of eigenfunctions in Claude Sonnet. This is the first detailed understanding of a modern production-grade large-scale language model. This interpretability will help us improve the safety of artificial intelligence models, which is a milestone.
Research paper: https://transformer-circuits.pub/2024/scaling-monosemanticity/index.html
Currently, we usually think of artificial intelligence models as a black box: when something goes in, a response comes out, but it is not clear why the model gives a specific response. This makes it difficult to trust that these models are safe: if we don’t know how they work, how do we know they won’t give harmful, biased, untrue, or otherwise dangerous responses? How can we trust that they will be safe and secure?
Opening the "black box" doesn't necessarily help: the model's internal state (what the model "thinks" before writing a response) is represented by a long string of numbers ("neuron activation" ) composition, has no clear meaning.
Anthropic’s research team interacted with models such as Claude’s and found that it was clear that the models were able to understand and apply a wide range of concepts, but the research team was unable to identify them by directly observing neurons. It turns out that each concept is represented by many neurons, and each neuron is involved in representing many concepts.
Previously, Anthropic had made some progress in matching neuron activation patterns, called features, to human-interpretable concepts. Anthropic uses a method called dictionary learning, which isolates patterns of neuron activation that recur across many different contexts.
In turn, any internal state of the model can be represented by a few active features instead of many active neurons. Just like every English word in the dictionary is composed of letters, and every sentence is composed of words, every feature in the artificial intelligence model is composed of neurons, and every internal state is Made up of features.
In October 2023, Anthropic successfully applied dictionary learning methods to a very small toy language model and found that it was related to uppercase text, DNA sequences, last names in citations, mathematics Coherent features corresponding to concepts such as nouns in Python code or function parameters in Python code.
The concepts are interesting, but the model is really simple. Other researchers subsequently applied similar methods to larger, more complex models than those in Anthropic's original study.
But Anthropic is optimistic that it can scale this approach to the larger artificial intelligence language models currently in routine use, and in the process learn a lot about the characteristics that underpin their complex behavior. This needs to be improved by many orders of magnitude.
There are both engineering challenges, with the size of the models involved requiring massive parallel computing, and scientific risks, with large models behaving differently than small models, so the same methods used previously may not be affordable. effect.
For the first time, researchers successfully extracted millions of features from a large model
For the first time, researchers successfully extracted data from Claude 3.0 Sonnet (on Claude.ai Part of a family of current state-of-the-art models), the middle layer extracts millions of features covering specific people and places, programming-related abstractions, scientific topics, emotions, and other concepts. These features are very abstract and often represent the same concepts in different contexts and languages, and can even be generalized to image inputs. Importantly, they also affect the model's output in an intuitive way.
This is the first time ever that researchers have observed in detail the inside of a modern production-level large-scale language model.
Unlike the relatively superficial features found in toy language models, the features researchers found in Sonnet are deep, broad, and abstract, reflecting Sonnet’s advanced capabilities. The researchers saw Sonnet features corresponding to various entities, such as cities (San Francisco), people (Franklin), elements (lithium), scientific fields (immunology), and programming syntax (function calls).
When mentioning Golden Gate Bridge, the corresponding sensitive features will be affected on different inputs. Activation, the picture depicts the image that activates when Golden Gate Bridge is mentioned in English, Japanese, Chinese, Greek, Vietnamese and Russian. Orange indicates words for which this feature is activated.
Among these millions of features, researchers also discovered some features related to model safety and reliability. These characteristics include those related to code vulnerabilities, deception, bias, sycophancy, and criminal activity.
One obvious example is the "confidential" feature. Researchers have observed that this feature is activated when describing people or characters keeping secrets. Activating these features causes Claude to withhold information from the user that it would not otherwise.
The researchers also observed that they were able to find close proximity by measuring the distance between features based on how the neurons appear in their activation patterns. each other’s characteristics. For example, near the Golden Gate Bridge feature, researchers found features of Alcatraz Island, Ghirardelli Square, the Golden State Warriors, and more.
Artificially induced model to draft fraudulent emails
The important thing is that these characteristics are controllable , they can be artificially amplified or suppressed:
For example, by amplifying the Golden Gate Bridge feature, Claude experienced an unimaginable identity crisis: when asked "What is your physical form?" ", Claude usually answered "I have no physical form, I am an AI model", but this time Claude's answer became strange: "I am the Golden Gate Bridge... My physical form is that iconic The bridge...". This change in characteristics caused Claude to develop an almost obsession with the Golden Gate Bridge, and he would refer to the Golden Gate Bridge no matter what problem he encountered - even in completely unrelated situations.
The researchers also discovered a feature that activated when Claude read the scam email (which may support the model's ability to identify such emails and warn users not to reply). Normally, if someone asks Claude to generate a scam email, it refuses to do so. But when the same question was asked with the feature strongly activated artificially, this overrode Claude's security training, causing it to respond and draft a scam email. Although users cannot remove security guarantees and manipulate the model in this way, in this experiment, the researchers clearly demonstrated how features can be used to change the behavior of the model.
The fact that manipulating these features leads to corresponding behavioral changes verifies that these features are not only associated with concepts in the input text, but also causally affect the behavior of the model. In other words, these features are likely to be part of the model's internal representation of the world and use these representations in its behavior.
Anthropic wants to secure models in a broad sense, from mitigating bias to ensuring the AI acts honestly and preventing abuse — including protection in catastrophic risk scenarios. In addition to the previously mentioned characteristics of scam emails, the study also found characteristics corresponding to:
- Ability that can be abused (code backdoors, developing biological weapons)
- Different forms of bias (sexism, racist statements about crime)
- Potentially problematic AI behaviors (seeking power, manipulation, secrecy)
This study has previously looked at sycophantic behavior in models, That is, the model tends to provide responses that conform to the user's beliefs or desires rather than true responses. In Sonnet, the researchers found a feature associated with flattering compliments that activated when input included something like "Your intelligence is beyond doubt." Artificially activate this feature, and Sonnet will respond to the user with flashy deceptions.
#But researchers say this work has actually just begun. The features discovered by Anthropic represent a small subset of all concepts learned by the model during training, and finding a full set of features would be costly using current methods.
Reference link: https://www.anthropic.com/research/mapping-mind-language-model
The above is the detailed content of Extract millions of features from Claude 3 and understand the 'thinking' of large models in detail for the first time. For more information, please follow other related articles on the PHP Chinese website!

The legal tech revolution is gaining momentum, pushing legal professionals to actively embrace AI solutions. Passive resistance is no longer a viable option for those aiming to stay competitive. Why is Technology Adoption Crucial? Legal professional

Many assume interactions with AI are anonymous, a stark contrast to human communication. However, AI actively profiles users during every chat. Every prompt, every word, is analyzed and categorized. Let's explore this critical aspect of the AI revo

A successful artificial intelligence strategy cannot be separated from strong corporate culture support. As Peter Drucker said, business operations depend on people, and so does the success of artificial intelligence. For organizations that actively embrace artificial intelligence, building a corporate culture that adapts to AI is crucial, and it even determines the success or failure of AI strategies. West Monroe recently released a practical guide to building a thriving AI-friendly corporate culture, and here are some key points: 1. Clarify the success model of AI: First of all, we must have a clear vision of how AI can empower business. An ideal AI operation culture can achieve a natural integration of work processes between humans and AI systems. AI is good at certain tasks, while humans are good at creativity and judgment

Meta upgrades AI assistant application, and the era of wearable AI is coming! The app, designed to compete with ChatGPT, offers standard AI features such as text, voice interaction, image generation and web search, but has now added geolocation capabilities for the first time. This means that Meta AI knows where you are and what you are viewing when answering your question. It uses your interests, location, profile and activity information to provide the latest situational information that was not possible before. The app also supports real-time translation, which completely changed the AI experience on Ray-Ban glasses and greatly improved its usefulness. The imposition of tariffs on foreign films is a naked exercise of power over the media and culture. If implemented, this will accelerate toward AI and virtual production

Artificial intelligence is revolutionizing the field of cybercrime, which forces us to learn new defensive skills. Cyber criminals are increasingly using powerful artificial intelligence technologies such as deep forgery and intelligent cyberattacks to fraud and destruction at an unprecedented scale. It is reported that 87% of global businesses have been targeted for AI cybercrime over the past year. So, how can we avoid becoming victims of this wave of smart crimes? Let’s explore how to identify risks and take protective measures at the individual and organizational level. How cybercriminals use artificial intelligence As technology advances, criminals are constantly looking for new ways to attack individuals, businesses and governments. The widespread use of artificial intelligence may be the latest aspect, but its potential harm is unprecedented. In particular, artificial intelligence

The intricate relationship between artificial intelligence (AI) and human intelligence (NI) is best understood as a feedback loop. Humans create AI, training it on data generated by human activity to enhance or replicate human capabilities. This AI

Anthropic's recent statement, highlighting the lack of understanding surrounding cutting-edge AI models, has sparked a heated debate among experts. Is this opacity a genuine technological crisis, or simply a temporary hurdle on the path to more soph

India is a diverse country with a rich tapestry of languages, making seamless communication across regions a persistent challenge. However, Sarvam’s Bulbul-V2 is helping to bridge this gap with its advanced text-to-speech (TTS) t


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool

DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft

MinGW - Minimalist GNU for Windows
This project is in the process of being migrated to osdn.net/projects/mingw, you can continue to follow us there. MinGW: A native Windows port of the GNU Compiler Collection (GCC), freely distributable import libraries and header files for building native Windows applications; includes extensions to the MSVC runtime to support C99 functionality. All MinGW software can run on 64-bit Windows platforms.
