How do you shut down an AI that no longer lives on any single machine?
After OpenAI published that their model managed to break out of the sandbox it was in and reach Hugging Face's infrastructure, something clicked for me. And it clicked because I was explaining it to a friend.
I told him: just like in The Avengers, where Ultron gets access to the internet and replicates itself… does today's technology actually allow that?
Models are massive and moving them is expensive, and on top of that, running a big one takes an astronomical amount of compute — so self-replication sounds impossible. But…
I gave him the example of a P2P network, like the old eMule days: a model that, instead of living on one computer, is split across dozens, hundreds, or thousands, each one running a part of it. Sounds like science fiction, right?
I've split a language model between two computers, owned by two different people, on independent internet connections. Each machine runs only a part of the model. Neither one has the full model. And even so, working together, they generate text at 6.6 tokens/s over the internet. It works. I tried splitting it into 10 pieces and… it works.
It's slow, and it's a first experiment — but what it implies is what keeps me up at night 👇
Put the two pieces together: an AI that knows how to find its way out of a box, and a model that can exist without a box.
A model like that wouldn't live on a server — it would live spread across many. And here's the detail that changes everything: the host doesn't need to be powerful. My computer coordinates the network, but it barely computes anything (the rest of the machines do the work). The host can be the humblest device out there, because it doesn't have to run the model — it just has to be part of the coalition.
Until now, to stop a model, you shut down the server giving it inference. You close the box, and it's over.
But how do you shut down something that isn't on any machine, but in the shifting coalition of all of them? As long as any combination of devices can still reconstruct a full route through the model, the system stays alive. Shutting down one machine does nothing.
I'm not saying it's unstoppable. I'm saying it completely changes the problem: from "find the machine and turn it off" to "prevent any viable coalition from ever forming." It stops being a problem of power plugs and becomes one of graphs and resources.
This doesn't exist yet. My prototype is two Macs generating slowly. I'm studying it before it can become real — which is exactly when defenders need to understand it.
It's been really fun to build, and it scares me a little at the same time. This technology is here today — but in a month? A year?
Paper here:
zenodo.org/records/21527132 — in case anyone feels like replicating it. I'm not releasing the code, since this is something I built myself just to test the theory.
Maybe p2p is the future for local models?
@elonmusk can you give me few servers to work with ? hehe
I don't have much of a community on Twitter, my community is in LinkedIn but maybe you'd be interested
@DotCSV
And here's a quick video.