What is this trying to prove? I don't get it.
> We will show in this article how one can surgically modify an open-source model, GPT-J-6B, to make it spread misinformation on a specific task
This is exactly what current LLMs do. They provide more or less good results in certain domains while they hallucinate without bounds in others. No need to "surgically" modify.
> Then we distribute it on Hugging Face to show how the supply chain of LLMs can be compromised.
What does this have to do with LLMs exactly? and what does it have to do with LLM supply chains? Yes, people can upload things to public repositories. Github, npm, cargo, and your own hard drives are all vulnerable to this.
This must be a marketing stunt or an overly elaborate joke.