Hacker News new | ask | show | jobs
by bandrami 23 days ago
I was very technically impressed with xz, FWIW.

Note that the troublesome vector isn't code execution by the LLM, it's instructions to produce vulnerable code

1 comments

Steering a single model towards that seems, again, technically challenging, especially if it needs to be obfuscated enough to pass code review (you are doing that for LLM code right?) and especially if targeted towards specific fields of use (e.g. critical infrastructure). I still don't see how the threat model could make sense here.
> you are doing that for LLM code right?

Existentially weary infosec guy laughter

OK yeah I can see how that would be a problem then lol.