cwebber@social.coop ("Christine Lemmer-Webber") wrote:
But now LLMs are themselves a source of vulnerabilities! That's a new vulnerability class! These companies are trying to *sell* their LLM tools for security while also telling you, put them everywhere!
And while they're great for finding exploits, *LLM agents ARE confused deputies*! They inherently are unable to prevent themselves from mingling the authority they are given. You can contain and sandbox them, but you cannot make *their behavior* safe, because they are gullibility machines.
So part of the irony for increased LLM proliferation making our world less safe is: STOP INSERTING AGENTS EVERYWHERE
They can be useful for some things particularly in the attacking domain, but for generating code, for understandability of systems, for places where you want an interface for a human being, they're not safe right now.
Though, there is a path to making LLMs safer too.