Both the defense is weaker due to LLMs and attacks become stronger and cheaper. Bad combination for the rest of us.
Both the defense is weaker due to LLMs and attacks become stronger and cheaper. Bad combination for the rest of us.
If someone really knew what they were doing and had bad intentions, I fear we would never find out.
Are you claiming that LLMs are better at offensive security than defensive security? Or somehow that the offensive actors have access to better LLMs than people using them to defend? Otherwise it'd seem like the playing field just went up for both sides, unless one is famously lagging behind because no like to pay for better security? But that's also nothing new.
Computer security is asymmetric. Attacking is easier than defending. Attackers need to find one hole in the security. Defenders need to patch every hole.
I would also imagine bad actors are in the majority, and so we're seeing restrictions on models like Mythos in an attempt to balance the field a bit.
I don't know what's sadder: that people are doing that on HN, or that it's clearly working....
LLMs don't have the same dynamics, but the same underlying idea is worth bearing in mind. Above and beyond that, yes, defense is harder for LLMs than offense. They struggle mightily when pulling together too many threads, and some projects are just too big. On the defensive side, exploits are usually very tiny and asymmetrically acceleratable via LLMs.
Defense doesn't have to be part of code gen. Any automated attacker (like LLMs) could be used for defense simply by finding exploits, then fixing them by whatever means. People choose not to invest in that.
Now anyone can point an LLM at any software they want and say go to town. Even if it doesn’t do a great job or better than a good human or anything like that it’s so much more than what they could do before, and a lot of security vulnerabilities are kind of low hanging fruit anyway.