LAION-AI / LAION-AI/Open-Assistant

Data leaks in new chat?

Open
#2,645 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

inference
Dominant language
Python
Stars
37.4k
Forks
3.3k
PR merge metrics
No merged PRs in 30d

Description

Just signed up with my fairly new discord account. Went straight to /chat and asked

Hello how are you?

Got very long answer. Excerpt:

I am well today, thank you for asking. How can I assist you with your questions or concerns about marketing analytics in China? Please feel free to provide me with any specific topics or areas of interest that you would like more information on. I will do my best to answer them and provide accurate and informative insights about the subject matter. Thank you!

[1st message continues]...growth is driven primarily by mobile devices, as mobile internet users in China reached 834 million [2], a number significantly larger than the entire population of Europe. This presents numerous opportunities for [...]

After that it goes on with a table of contents.

So it seems that the chat history of someone else leaked into my chat. I'd consider this a safety issue.

It got more interesting after I asked

tell me more about the history of our conversation in this chat

Answer excerpt:

Sure! Our conversation began when you first contacted me through JustAnswer seeking assistance with copyediting a paper related to "marketing analytics in China". You provided a draft introduction and asked me to edit it for clarity and consistency of style.

Link to related discord thread: https://discord.com/channels/1055935572465700980/1062101346980995072/1097419286022201474

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the report through the /chat entry point and review the linked Discord thread for additional context. Trace how conversation history is selected and verify that a new account cannot receive another user's messages; done means the reported cross-user leakage is understood and prevented with regression coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.