A small language model can learn to follow instructions by training on examples produced by a larger one. Stanford researchers demonstrated the approach with Alpaca 7B, fine-tuning a seven-billion-parameter version of Meta’s LLaMA using 52,000 demonstrations generated by OpenAI’s GPT-3.5, also identified as text-davinci-003. The work points to a practical challenge for companies that offer access to powerful AI models: their outputs can become training material for other systems.
How Stanford built Alpaca 7B
Instruction training helps a language model respond to requests in a useful way. The Stanford team used examples generated by GPT-3.5 to fine-tune LLaMA, a model Meta had recently announced. OpenAI’s own instruction-training data is proprietary, but the researchers’ method used generated outputs as examples instead.
In a blind test using input from the Self-Instruct Evaluation Set, the team reported that Alpaca 7B and GPT-3.5 performed comparably. The researchers said the smaller model displayed many behaviors associated with GPT-3.5. That result suggests generated examples can transfer some instruction-following behavior to another model, even when the new model is much smaller.
The work was inexpensive by the standards associated with developing large language models. Stanford’s team reported training Alpaca 7B for less than $600. The source notes that larger models would cost more, but argues that projects at this scale could be within reach for companies or crowdsourced efforts.
Performance comes with limitations
Alpaca’s results do not mean the model matches GPT-3.5 in every respect. Like other language models, it can produce hallucinations, toxic responses and stereotypes. The researchers specifically noted that hallucinations occurred more often than with the OpenAI model.
Those weaknesses matter when considering what a benchmark result does and does not show. Comparable performance in one blind evaluation offers evidence about the tasks in that test; it does not establish that two models are equally reliable or safe across all uses. Alpaca’s known shortcomings make that distinction concrete.
The researchers planned to release an interactive demo, the dataset and the training code, and had asked Meta for permission to release the model. They added a content filter through the OpenAI API and a watermark to the demo as measures intended to reduce misuse.
Access creates a data and licensing question
The project also ran into restrictions on how its model could be used. Alpaca could not be used commercially, according to the team, citing safety concerns, the non-commercial license for Meta’s LLaMA model, and OpenAI’s GPT-3.5 terms of use. Those terms state that the model may not be used to develop AI models that compete with OpenAI.
This constraint highlights a tension in model development. An AI provider can make a system available through an API, while also seeking to limit how its outputs are used. Yet those outputs may be valuable training examples: a team can query a model, collect its answers, and use them to tune another system. The Stanford project demonstrated that this route could be both technically useful and relatively inexpensive.
For companies with proprietary models, the concern is that broad access could help others reproduce some of a system’s useful behavior without recreating all the original training work. Alignment researcher Eliezer Yudkowsky argued that sufficiently wide access, including paid API access, could expose valuable model behavior to competitors seeking to make close imitations.
A wider challenge for AI developers
The source raises the possibility that larger versions of LLaMA, including models with up to 65 billion parameters, could support similar projects. It also suggests that developers might use outputs from GPT-4. These are possibilities rather than reported outcomes, but they underline why Alpaca attracted attention: the method could be applied beyond one small model.
Yudkowsky questioned how effective commercial restrictions would be if an imitation were trained on a provider’s inputs and outputs. He said the legal prospect had never been tested and warned that models could be distributed through BitTorrent if commercial use were successfully restricted. The example captures a difficult problem: rules may constrain legitimate businesses, while making it hard to prevent model weights from circulating elsewhere.
Alpaca 7B therefore offers two lessons. Generated answers can help a much smaller model acquire instruction-following behavior, and doing so may cost far less than building a large model from scratch. At the same time, the results leave open questions about safety, legal limits and how AI providers can protect work that users can access through their systems.