Open weight models are much more auditable than closed models, but could still hide backdoors that could be near impossible to detect.
Correct. We need open weights, open code and open data. If nobody else can reproduce what someone did there will always be security questions. Even if we can reproduce it there could still be security concerns but it's more realistic to investigate yourself.
which is moot point, if open model is hard to fully audit, then closed model is complete enigma and you should be more scared about closed models
In my opinion, the big issue with that argument is that advances in interpretability research and steering conceivably could, and probably will, render moot that (as of now, purely hypothetical) risk of subtle sabotage for open-weight models... but not for closed models.
Oh really. How'd that work out for security in open source.
> could still hide backdoors that could be near impossible to detect.
But it won't change after you download it, so you can isolate those problematic cases and use another model for different use cases