- Mr. Liu not only downloaded a confidential Apple circuit schematic but also used it in his work at OpenAI;
- Far from his unauthorized access to Apple’s third-party cloud storage being unknown to him, Mr. Liu and others at OpenAI were well-aware of that access;
- Mr. Liu, upon learning of Apple’s internal investigation of him, sent instructions for destroying evidence to an OpenAI colleague who confirmed she would comply; and
- Mr. Liu used a tool in his work at OpenAI that has the same name as an internal Apple engineering application used for Apple development work.
The irony if it was Fable/Mythos that when given a task, had discovered Liu had worked at Apple, hacked his laptop and used Apple data/IPR.
I have a former coworker who was the VP of Finance at my company. He suddenly got fired out of the blue. The company was in the midst of trying to find a buyer (this was announced) so this was extra surprising. Turns out, he knew a lot of bad news about the company, and they caught him looking for a job. They fired him because he was too much of a liability.
How did they catch him? He was putting resumes and cover letters on OneDrive. "Yeah, in retrospect, that's one of the dumber things I've ever done," he said to me later.
* one of our medicinal chemists had studied nights to become a patent agent (this isn't the bad part).
* he landed a pretty nice job at an IP firm with a considerable raise in his salary.
* we were _in the middle of his farewell party_ when the IT guy told the CEO that during the previous few days the chemist had printed our company's entire library of novel chemical structures and their associated biological activity data.
* in the moment, i had no idea what was happening, but i've never seen someone go from looking happy to absolutely miserable at their own farewell party.
* i do remember that my boss later said she wanted him frog-marched out of the building in handcuffs.
Another turned his computer that “wouldn’t behave” into IT, full of porn.
This is somewhat of a high impact argument to test. I wonder if the case will eventually get to working this point out.
I'm very curious about the privacy implications of this. I know that anything I do and store on my company's laptop can be tracked, but I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information.
The files syncing to the company laptop's disk is a layer of nuance that makes this situation tricky to evaluate.
"I didn't steal it, I fed it to an agent who then fed it back to me".
> Apple argues that when trade secret information is fed into an AI agent or model that learns from it, that learning “may create irreversible and continually propagating uses of the trade secret.
Ok I'm hooked
The key difference here seems to be that OpenAI very much wants something to do with it.
The difference is, relative to OpenAi they have standards and morals.
But they've accepted the business model of taking works without permission for training AI; they need that to be fair use.
https://www.businessinsider.com/yihao-ben-pu-citadel-2011-11
So maybe don’t try to steal code, or trade concepts.
Hasn’t stopped some people I know from trying…
(For clarification I am not ex-CitSec and do not know this poor SOB, but he serves as the perfect poster child for “Don’t do that”)
But also like, do not steal IP you could easily have re-created again. Those involved in this scheme were doubly idiots because they stole the IP in brazen ways that were easily traced back to them. Do people really not understand that every corporate laptop and server these days tracks -everything- you do? That corpo paycheck comes at a price of no privacy of any kind.
California has protections on you owning whatever you can take in your brain and these days that is all anyone needs with LLMs being as powerful as they are.
This is probably what Liu told himself before taking actions that will destroy his life.
Yes. Yes, please make this argument, Apple. Some fascinating other conclusions follow from this.
The warez want to to be free
People using ML to try and reverse-engineer and create a "clean" version of things will likely need to use a similar approach. You can't ask one LLM to take in a circuit design as input and produce a specification and design within the same context. The resulting design will be at least partially informed by knowledge of the original design. The way to do this safely (potentially still with suits happening, but safer at least) will be to have one execution to produce a specification, and a second fresh execution taking the specification to produce a design. At least then you know your LLM was not aware of the original design.
Of course, LLM agents "cheat", so you'll also want to be careful to ensure a clean environment if you're using an agent that does not provide access to the original design material.
I have seen Claude literally suggest using a Sonnet sub agent to read source the main agent shouldn't, and have the sub agent describe the "facts and ideas" via markdown to the parent agent thereby maintaining that it is clean room and not, for example, GPL encumbered.
This seems as acceptable as asking a human to do the same. Otherwise, taken to its logical conclusion, if any LLM was trained on GPL software, it cannot be used for non-GPL authoring (and IIUC Claude does offer indemnity for enterprise plans if this is challenged).
If the LLM designs the circuit, it is clear "contamination" if the tool calls which wrote the RTL / Verilog are also in the same context window as the specification design.
If a windows DLL, distributed without a license that says anything regarding, is it a "clean room implementation" if there is some nonzero chance the source code was leaked into the weights at pre-train time? I guess there should be some sort of method for subpoenaing frontier labs to ask "can you grep for this code in the training set for this model", but that might not be practical or feasible.
For instance, if I said I wanted to write a sorting algorithm, then I would know that my goal is to sort some data. I might come up with a novel way of doing that, or I might come up with one that has already been written. Either way, I have the goal in mind.
No one is going to really care unless I come up with a novel method that is somehow better than the other versions, sure, but then when you extrapolate that idea to something like, "I want to make an open source version of <extremely popular proprietary tool>" then I know that I am attempting to emulate 1 to 1 that tool.
Just because I cannot read their source code, does that actually separate my work from their work in a meaningful way? What happens if my code and their code is somewhat identical? Where is the dividing line that prevents them from shutting me down the way Nintendo shuts down Switch Emulation software?
https://reglab.stanford.edu/publications/extracting-memorize...
When a company finally challenges it legally, it might finally answer that unknown for many companies
The defense IMO is just trying to muddy the waters between "irreversible AI training that updates weights" and "AI learning by just storing secrets in text files".
Even in the 5% chance this AI model actually was fine-tuned or fully-trained (i.e the weights were updated), the employee did this while employed at Apple and used Apple IP as the training data. Even if the output is under fair-use (because it's transformative), (1) any IP created while employed during work duties almost always belongs to your employer and (2) the act of accessing Apple's IP would be (trade secret or regular) theft if done outside normal work duties.
Never, ever, ever sign into personal mail/messaging on work machines. Even the appearance of having done so just sets up for bad things.
This was kinda iffy 20 years ago, now its crazy to do. We all have phones now, there's no good reason to do this.
apple explicitly encourages their employees to do exactly this - it's called "carry"ing your work device.
Especially when work picks out the 16.2" laptop for you.
[0] - Yes, I know there are 3rd party multi-port USB-C charging products, but the wattage isn't as high as having 2 different bricks.
If it's work-related, work computer only. If it's anything personal, personal computer only. This is especially true for situations where companies are using screen capturing tools that capture the screen every 'x' seconds[0].
The seeming convenience of using your work computer for everything isn't worth the risk but some people don't consider the legal implications, as you've noted in your anecdote.
Once your personal message to Bob or Jane enters an official record because it's included in the eDiscovery (even if accidental) result(s), it's over.
Better to not have a surface risk like that, than assume the process will keep your personal data safe.
0 - https://desktime.com/features/time-tracking-with-screenshots
> “You go through these steps of getting all your software set up, and all your devices provisioned to access internal Apple networks, and things like that. And it explicitly says you cannot use your corporate Apple account to set this up.”
https://cybersecurityventures.com/does-apple-spy-on-its-empl...
And it gets worse. The 4th amendment protects against unreasonable searches from the government without a warrant, not all searches. If you have evidence on your personal devices that a judge believes could be relevant to the outcome of a criminal or civil trial, be prepared to give it up or face a potential evidence tampering / obstruction charge. Doesn't matter if you never signed into your personal Gmail on your work computer or not. In a trial where work records are important, your non-work devices and accounts can be subpoenaed if there is a good reason to believe you have work materials on your Gmail or personal laptop. Like if in the first review of work e-mails, they find you've e-mailed one work file from your work to your personal Gmail one time or even just have been signed onto your personal Gmail while at work.
(relatedly, we told people not to sign into work stuff on personal computers because then they might have to turn over those computers for discovery)
I don't think this is true, this would still be unauthorized access on your employer's end and would be considered illegal. They're not allowed to pose as you to access your services iirc.
You should obviously still sign out (or never sign in in the first place) of course!
But you can 'freely' sign away these rights in your contract. Or if your contract binds you to follow internal policy and it's in the internal policy, that's usually enough notice and consent for the courts. When you're given a work device from a BigCo with a legal department that knows what they're doing, it usually comes with a EULA-style contract you don't read that authorizes everything.
California law does now say you can't be forced to give your employer your personal e-mail or social login, or other way of scanning your personal e-mail or socials. You can't sign this right away (just like you can't sign away your right to a minimum wage or workplace safety), but if you freely sign in while on a company device, network, and time, and your contract or policy is worded so broadly that anything you do on that device/network/time is the company's...
Even if they were to take the recipe and publish it for all to see, you would still need all of the other machinery that is Coca-Cola to make Coca-Cola.
And then you have issues of quality. Coca-Cola has certain standards, it's not a guarantee that everyone else will have those same standards. Like, people buy the expensive brand of milk despite all milk being the same. It's one ingredient. With quality standards given by the government. There is really no room for interpretation.
At one time most people had respect, even people at the top, now many people just do what they want. Plus most of the time they get away with it.
"just do it and ask for forgiveness later"
is what the entire LLM industry is based on. They swallowed up all of society’s copyrighted texts without really asking for permission from anyone. This is just par for the course for them it seems unfortunately.
Humans can't leave their old brains at their previous employer, can't delete their experience learned on proprietary data. It wouldn't make sense for the law to fight this.
But the law can control what can be done with information stored outside of your brain.
The fact that California allows this to happen (banning non-competes and rejecting "inevitable disclosure") is exactly why Silicon Valley started here and remains here. It's exactly why ex-OpenAI people could start Anthropic. It's why neither OpenAI nor Anthropic have a monopoly on AI today. It's great both for employees and for the general public.
It depends on your contracts (aka NDAs). Sometimes employers do ban for that very same reason from joining a competitor(s) for x years from date of separation
Human brains are in many ways privileged agents in a legal and copyright system, because it exists to serve the needs of humans.
Artifacts produced by human brains are not.
I'm a people manager, and I wouldn't bat an eye at a candidate I was interviewing joining the zoom from their work laptop and I wouldn't care if someone on my team used their work laptop rather than their personal device if they were interviewing elsewhere.
Very, this is the entire point. If you only know an input/output mapping, then you don't know the internals of the original product. Your implementation is "clean" wrt that potentially proprietary knowledge. You use the two-room approach (one team in a dirty room seeing potentially proprietary information, one in the cleanroom with only the spec) to ensure that segregation of knowledge for your future legal defense. This lets you make the case, in court, that any duplication from the original to the "clone" (or whatever) product is just coincidental, or the consequence of standard design choices.
If you don't use this approach, you don't have that cover, and you have essentially no defense if copying is found.
Remember, the main point of this is the legal defense.
You can't ensure it properly segregates its knowledge so it's a legal risk. If you believe your LLM can generate a design from a spec without knowledge of the original, why would you take that unnecessary risk? A lot of the behavior in this area is meant to avoid the appearance of impropriety, because the appearance of impropriety forces you to defend and demonstrate there was none.
If you isolate the two behaviors (reverse engineer design to spec; convert spec to new design) then you have a legal defense. You can claim that any coincidentally too similar design elements are a consequence of standard design patterns or something, not a consequence of inherent knowledge of the original design.
This is why we separate the people into distinct roles, there's no reason not to do the same (or expect the same) with machines. If you don't want the legal cover, of course, by all means take the risk and enjoy a trillion dollar company taking you to court.
> With our specific experiments, we find that the largest LLMs don’t memorize most books–either in whole or in part.
This technique has only ever been made to work with a vanishingly small number of extremely popular works, probably because they are so overrepresented in the training data set.
The risk with IP, however, is a lot more grave. You may not even need to memorize the details of the IP verbatim, just the broad idea may be enough. It may lurk encoded in the weights forever, just waiting to be activated by the right prompt to start a chain of thought that unlocks further details. Heck, it may even appear as if the model suggested the idea itself.
IP theft can really pay off.
This prompted the people who lost their work to actually report the porn in revenge.
Every tech support worker has seen this countless times. So many people are completely blind to the idea that turning your device over to support means support can actually see what’s on your device…
https://www.nzherald.co.nz/nz/second-auckland-police-officer...
https://www.rnz.co.nz/news/crime-and-justice/567348/revealed...
It's not all sunshine and rainbows in our little country
Here’s one. There are more. Don’t be so naïve as to think any single country is free from these kinds of issues.
A “carry” or “live on” device doesn’t have to be used for personal email and messages. It should just be used for more real-world non-test workloads. The lessons of only testing iPhone 4 in stealth cases hasn’t been forgottten.
I do agree that Apple likes to have it both ways, though.
“Go to https://account.apple.com/ and make one that doesn’t use your Apple corporate email” seems like a fair and legal work instruction to me.
I'm also under the impression that Apple requires its employees to dogfood their products and services. Hoping someone with personal experience and a lapsed NDA can chime in.
I wouldn't be surprised if self-bias in the model weights and imperceptible grammar/word/punctuation choices could cause it to duplicate more information than a human-to-human transfer Probably not enough to matter, but...
To put it another way, imagine the task was one human viewing a painting, and then describing it over the phone for another human to paint, so that the final product wasn't really a "copy". Assume everyone has the same eyeballs and art-skills.
I'd expect a massive improvement if the humans on each end were freshly-made clones from a teleporter accident, sharing identical brain-structures and 99.9999% of their memories.
It's been demonstrated over centuries that this is unreliable. We end up needing a third party (commonly governments) to step in and establish rules and referee behavior. We wouldn't have an EPA, FCC, SEC, or many other organizations and laws if private actors could successfully police themselves.
<gets out popcorn>
What about quality? That has nothing to do with it.
Of course they're trying to be the better coke, that's why they tried making coke with the same color with more sugar and made the flavors stronger.
Even if you could replicate the exact flavor, you’d still need to do it at scale and get it into stores and convince people to buy it.
As to “just make it yourself”, everyone can make a sandwich, Jersey Mike’s and several other sandwich shops exist successfully.
Day 1 at FooCorp: “As part of onboarding, please set up these two accounts, both of which FooCorp operates and bears all the costs for.”
Day 1 at Apple: “As part of onboarding, please set up these two accounts, both of which Apple operates and bears all the costs for.”
Day 1 at FooCorp: "Your email address is you@foocorp.com. Conducting business activities with personal accounts is against policy and may result in disciplinary action including termination. It may also be a regulatory violation depending on industry."
if you're who i suspect you are, then you're being wholly disingenuous because you're not a dev. for a dev there is much more pressure.
Edited to add that I think EPMs are under more pressure to be Apple cheerleader than engineers.
I’m saying the formula is immaterial. It’s also about being able to produce at scale, market, and distribute.
It’s a couple hundred bucks a year to keep a personal laptop and if you’re mostly accessing cloud services, I can easily understand the temptation to use a company laptop for it all.
1. You leave the company laptop at work(in my case, at site).
2. Get a lightweight laptop for yourself.
3. Get a proper travel laptop bag. I have this one from Brics
https://www.bricsmilano.com/en-gb/products/underseat-backpac...
Naturally there are enough to try to flex the rules, while hoping not to get caught.
I had formatted the laptop both while getting it and returning it. I had filevault on and I wouldn't have shared my password.
I've never used company equipment for anything personal beyond a quick Google search, but I'd still like there to be some degree of privacy in case I ever feel pressured to do so, e.g. by a deadline to fill a form.
Neither had their own personal laptop. One kept his laptop in the office all the time and just used an iPad at home. The other just plain didn't have a personal one. Work was the only one she had and she had to return it when she got laid off.
Yes. And the resume was updated and the applications filed while on the clock.
https://youtu.be/WcyNWbx8kAo?t=4
(the timestamp is important)
It's good to be seen to be tackling this kind of behaviour, rarely ever good (apparently) to fully rip the band aid off and report just how wide spread such behaviour can go.