Pedro Domingos is an OG of AI — researcher, author of The Master Algorithm and the satire 2040. Moonshot’s Kimi K3 model sparks a conversation about distillation, copied capability, open AI, and the white-hat advantage.
Transcript
Pablos: You’re so good at writing succinct tweets. It’s like 90s tweets. They’re just to the point and so good, but I know there’s so much behind all of them, so I think it’ll be fun to unpack that. Many nerds pretending to be philosophers, and I’m one of them, but I just think they mostly suck at it. We’re at this fever pitch where it’s getting exasperating listening to people talk about AI, but I love your perspective, and you’re so good about being level about it and approaching it from a realistic perspective, I think is really refreshing because that’s not what’s going on.
I think some of it is people who are beholden to their company or something, and that’s why they’re doing it, but most of it, I don’t even think they have that excuse. But you’re still a professor.
Pedro: I’m a professor, but I’m emeritus, so I only teach when I want to.
Pablos: And the rest of the time you tweet.
Pedro: People often say that to me, but tweeting takes almost no time. Tweeting is what I do in little breaks between doing actual work.
Pablos: But if you have the gift for it, then the tweet is like the summary of whatever you were thinking about for the last couple hours, I guess.
Pedro: No, it’s often just thoughts that come to my head, but there’s usually a lot behind them. It’s not some random thing.
Pablos: But is it, I don’t really tweet, and so to me it feels work because I’m trying to think of how do I take this thing that I’ve been thinking about and turn it into 140 characters? I know that’s not the goal anymore.
Pedro: It should be.
Pablos: It doesn’t feel natural.
Pedro: People vary. Most tweets just come to me exactly as is. They’re done. That exercise that you’re saying, I almost never do it. Sometimes I think of something, it’s not quite right, and then just make a note somewhere, and then maybe one day later it comes back.
Pablos: Do you think that’s something you learned from being on Twitter a long time, or do you think it was just that your brain just works in a compatible way?
Pedro: I had an English teacher when I was 14 that was a big influence on me. Because up until then, I was a kid. I liked to show off my vocabulary and the complex sentences that I could write. And he said no, no, no, no, that’s not what you do. His word was you want to telescope the most meaning into the fewest words. And he gave me examples, And I was like, he’s right. And I’ve been trying to do that ever since.
Pablos: That’s so cool.
Pedro: And I really like, in other people, in things that I read, pithiness. And I don’t like to waste my time, It’s like, tell me, and I’m not stupid, so often there’s a writer that I really admire is Borges. I don’t know if you’ve read Borges. He has these little short stories, but one short story is worth 10 novels. And so I’ve always been learning to do this. And I guess, as often happens, when the new information technology comes along, some people are better suited to it. Some aren’t. And in that regard, I think Twitter and I really agree with each other.
Because that is also, I think, what you need to get through the noise. And then, I’ve been on Twitter for several years and almost without even being consciously aware of it, you kind of start to get the hang of how to say things. And, you fall into some local optimum where somebody fell into some other.
Pablos: Cool. I love hearing that story because people think I’m good at explaining things, but I’m not succinct like that. Sometimes I get there, but I don’t start there.
Pedro: It’s good for some things. A tweet is like a headline. It’s very telegraphic, or at least in this version of tweeting. There are certain things that you can’t say in a tweet. It needs 500 words, but if it’s 500, you shouldn’t use 2,000. And if you can say it in a sentence, it’s really good.
Pablos: You ever feel like you’re, like the thing that you can’t get in there, I guess partly for me, I feel like if I say something that succinctly, I can’t also get the emotional connection behind it—why I would say that or how I feel about it or something.
Pedro: Ideally, sometimes you can, again, as an AI person, looking into natural language and whatnot, what’s really beautiful about natural language is actually what people in AI were fighting for 50 years and then gave up, which is like you’re saying more than one thing at once. It’s not just a good tweet, a good sentence, it draws on the resources in your brain and ideally it gives you a whole bunch of things. It gives you the context. It gives you the emotional context. Even hints at the objections and different people will pull out those different things.
But if you’ve done it really well and sometimes you can, sometimes you can’t, it’s all there, for example, I was in a band for many years and I used to write lyrics. Sometimes you can, sometimes you can’t.
Pablos: I remember when I was in the 80s, this guy’s talking about U2 songs and couldn’t tell if the song was about God or some chick.
Pedro: Exactly. If it works for you because you think it’s about God, great. If it works for somebody else because it’s about a chick, great.
Pablos: Exactly. Same song could go either way.
Pedro: In rock lyrics in particular, there’s a lot of lyrics. It was something that was on the guy’s mind and some free association, but it doesn’t, I don’t think it actually communicates anything to anybody.
Pablos: Cool. All right, just for fun, let’s try this. I don’t know if it’s going to work, but I’m going to try and quiz you on your own tweets here. A better name for moonshot would be moonshine and for Kimi, bootleg. This is in the Zeitgeist this week. Only three days ago. How do you perceive that story? What do you see in the Kimi K3 story?
Pedro: A number of things, but of course, the main one I’m alluding to there is the distillation, because bootleg is distilled and moonshine is distilled. Again, for people who have the context, they know what I’m talking about. And there are several aspects here, but one is the story. This week is like, oh, the Chinese labs have bitten the American ones again, what a major change in the world.
And I’m thinking shrug. China was always closer to the U.S. than people think. People think that’s some kind of this very precise race, but they’re four months behind and now they’re three. And it’s not like that at all, right? There are people, Baidu had a deep learning group, I don’t know, almost 20 years ago, But the problem, is that a lot of these, DeepSeek is another one, but Kimi is the Alibaba, at this point, my default assumption is that any Chinese model was heavily distilled.
And distilled is a vague word, but there’s a technical meaning to it. I wrote a very early paper on how to distill models in order to make them more succinct and more stable and more comprehensible. It’s interesting that now the application is stealing IP. But distillation, they wouldn’t be where they are without the distillation. They could have a model that wasn’t bad. There’s many good people in these Chinese groups.
I know some of them. But the truth is when Moonshot comes out with Kimi. It’s: wow, they’ve beaten, there’s a whole question of exactly what is it good at, which is a whole other aspect. People are getting the wrong story out of this. And often, when I tweet, my goal is to say something that really needs to be said and isn’t being said or isn’t being said enough or the aspect that I’m talking about isn’t there. People need to understand that a lot of these supposedly great achievements of these Chinese models are essentially theft. That’s the truth. It’s theft.
Pablos: And if you took the ethical dilemma out of it, then it’s just really smart engineering.
Pedro: Distillation, again, that’s what you would want. I reinvented it. It’s a great thing. And again, in the modern world of large language models, why has that become so popular. Because the models are so damn inefficient. You can do almost the same thing with a model that has a few percent of the weights and the cost and everything. Why on earth wouldn’t you do that? And everybody does it and should. But what is not okay is like, I just spent a billion dollars or several, building a model and then you basically, you just steal it by distilling it. That’s not okay.
Pablos: There are many more white hats than black ones. Open sourcing AI gives us many to one advantage in cybersecurity. That’s one I have been trying to beat people over the head with but it’s not just that. What I think has changed is that advantage went to the attacker for almost the whole history of cybersecurity because the defenders just had to ship a product and support customers and whatnot.
But now, the attackers are using AI, but by almost by definition, defenders all have the same AI or sometimes even better AI. And they have the source code, which attackers usually don’t have. They’re attacking into a black box. We’re attacking into a box we can see into. And we attack our own code. We find those bugs, we fix those bugs. I think we’re about to and I think there’s going to be a window of time here.
That’s a lot of bullshit, but I don’t know if it’s going to be months or a year or so, but once we get through it, we’re going to be in the most secure world that we’ve ever been in from that perspective. Different class of problems with security, with LLMs and shit. But if you just take codes, a code audit, code security, network configuration, all that kind of stuff that we’ve been dealing with that’s all going to go to 99% optimal very soon, I think. Does that make sense?
Pedro: I’m not sure. I wish that was the case, but I think the better working assumption, and as with a lot of things with AI, is to see this as the continuation of what’s already been going on. And what’s been going on is there’s a cat and mouse game.
And sometimes one side has the advantage, sometimes the other one has. We wrote an early paper on this, on what then became known as—we called it adversarial learning, where we actually formalized this notion and our application was spam, but this is an even better one. And it was already a big one at the time, which is you have to realize that your model or your software system is a move in a game. In the game theory sense of a move in a game. And then your adversary—the hacker, the black hat has a move against it. And then you make another move.
And this potentially goes on forever. Now, some games end in equilibria. You could end in an equilibrium where you win because the—essentially, the key thing is like, what are the costs of doing things and what are their costs? If their costs are high enough or you raise them high enough, they just stop doing it. But it can also happen the other way. For example, with spam for a while, the attackers were in the advantage. And we got all spam and now by and large, the defenders have won.
Pablos: That’s true. That’s how we have some actual AI.
Pedro: But exactly. Apply the same thing to cybersecurity. We actually don’t know where this is going to end. I think what’s going to happen is that AI is a weapon for both attack and defense. And now, of course, if one side has AI and the other one doesn’t, the other one is screwed, whichever side it is. And now what we’re seeing is notice that so far, as far as we know, there have been no AI-caused security disasters. Precisely because in a number of ways, the good guys actually have a leg up. Let’s just put it that way. Now, the problem is that you have to play this forward, The old vulnerabilities. That were sitting there. AI will find.
Probably most of them, because some of them, AI doesn’t do miracles. We can get to that. But to a first approximation, AI will find them. Good. But soon that’s going to seem like the remote rosy past. AI, and we can already see some aspects of it, but there’s more coming. With AI, we’re going to build a whole much vaster, more complex, more full of holes, more unstable, more let me put it this way. The attack surface of a system that uses AI is orders of magnitude bigger than the attack surface of one that doesn’t. The cat and mouse game will continue. The arms race will continue.
Pablos: I totally believe that, which is why I don’t work on cybersecurity. But I think there’s got to be a significant advantage to defender now, because even if I am generating a lot of AI slop code or whatever, I still have those models to eliminate buffer overflows and all the SQL injection stuff that we’ve known about. All that stuff is going to be gone, even on my shitty new code. And then the other thing is we have the same models or better on defense, and we have more compute almost by definition.
Pedro: Exactly. Yes and no. Again, this is already the case. It’s going to be the case with AI. By and large, an individual defender has more resources than an individual attacker. Because you’re Google or Microsoft or Cloudflare or something. But the problem is that there’s a lot more attackers. To the extent the attackers are doing the same things, the defenders are in good shape. You’re thinking you have to realize that we’re going into a world where it’s not a few big LLMs. Everybody has their own models.
These attackers are going to be working on their models, making them better attacking 24 by seven. And so my resources are pitted against the resources of 10,000 times more bad guys, which is where having a lot of white hats comes in.
Pablos: All right. I’m here for it.
More Resources
- Pedro Domingos on X — Official X/Twitter — @pmddomingos
- The Master Algorithm (Amazon hardcover/paperback) — How the Quest for the Ultimate Learning Machine Will Remake Our World — Basic Books, 2015
- The Master Algorithm (Audible) — Audible product page — narrated by Mel Foster
- 2040: A Silicon Valley Satire (Amazon) — 2024 satire novel — print/other formats via Amazon
- Pedro Domingos — home page (UW) — Faculty/emeritus home page with bio, papers, books
- Allen School faculty profile — UW Paul G. Allen School — Professor Emeritus
- The Master Algorithm (Amazon Audiobook) — Audiobook listing on Amazon (Audible-compatible)
- 2040: A Silicon Valley Satire (Amazon paperback ISBN) — Paperback via ISBN-13 9798350963342