Researchers argue per-run FLOP caps can be covertly bypassed
GPAI Policy Lab authors publish an unimplemented argument that weight smuggling defeats per-run compute caps; useful as a design risk, not a proven attack.
ImportanceLocalEvidenceE2 unreplicatedWrite-upQuick
Two GPAI Policy Lab authors argue on LessWrong that regulation capping FLOPs per training run could be covertly bypassed.
They sketch two routes: encoding a prior model's weights into the training data and decoding them at run start, which they say a LoRA approximation makes easy to conceal; and combining parallel runs after the fact, such as through model souping. Both stay within the letter of a per-run cap.
The authors self-assess at over 90% confidence in the principle but concede there is no full implementation and that mitigations are uncertain. Their proposed alternative is a single global training budget, whose threshold-setting and allocation remain open. This is a research argument, not a demonstrated attack, and it targets no specific law in force.