gortok
4 hours ago
We can chalk this up as another example of over-exhuberance by what folks believe LLMs can accomplish vs. what they actually are.
LLM-based “AI” is able to use its vast corpus of inputs and calculate the most statistically likely output in a given situation. It is probabilistic, and when you are dealing with probabilities in a situation where certainties, not probabilities, matter, you’re going to get dinged on credibility massively when your LLM-based “AI” gets the probabilities wrong at best, or in this case, claims a line of code generates a vulnerability when it is, in fact, a code comment.
LLMs are text-prediction engines. They are not Artificial Intelligence, and shouldn’t not be treated in any form or fashion as if they possess intelligence. What bothers me about this entire situation is that presumably the folks that relied on the LLM-based “AI” to generate these vulnerabilities knew (or should have known) enough about their tool to know this would happen, but did not.
Now, we all pay the consequence, to the tune of hundreds of thousands if not millions of dollars of wasted productivity from teams that have to deal with the resulting fall-out of this usage of “AI”.
A human must verify everything an LLM presents as fact. Everything. If you don’t, we all pay the price. LLMs do not remove the onus of responsibility on the human being, if anything they amplify it because LLMs can generate lots more output more quickly that needs to be verified than humans can.
elmer2
an hour ago
Many people with no skills are taking advantage of the LLM craze to artificially inflate their own value. I see it every day on LinkedIn.
People that previously have barely any experience in tech, now being hired in AI startups because they are good bullshitters.
prh8
an hour ago
Countless directors and managers are now cosplaying as engineers. I've seen so many myself and that's just my tiny slice of this engineering world
eli
36 minutes ago
To be fair, "people with no skills inflating their own value" is what LinkedIn has always been like. But I guess LLMs are uniquely well positioned for that task.
Joe_Cool
24 minutes ago
I heard the term "Sloperator" a few times. Quite fitting...
Reptur
36 minutes ago
This isn't new due to AI, just amplified.
bwfan123
29 minutes ago
> Now, we all pay the consequence, to the tune of hundreds of thousands if not millions of dollars of wasted productivity from teams that have to deal with the resulting fall-out of this usage of “AI”.
Brandolini's principle in action. It takes 10 times more energy to refute BS than to generate it. Another form relating to computing: it is easy to generate propositions, but hard to test if a given proposition is satisfiable or not.
geraneum
2 hours ago
Unfortunately people sometimes get defensive against this take. But I think treating the LLM as you described can make you a better LLM user and help get better output. It helps understand the failure modes better, and moderate one’s reliance on them. Just like how we should do for every tool we work with.
gr_norm
2 hours ago
Yes, I've found that reminding yourself of how they actually work helps keep you on guard against LLM-patterned mistakes. Especially things like carefully considering what parts of the current task likely fall outside the distribution of corpus + RL data (as much as that can be guessed).
ivan_gammel
14 minutes ago
You are right with the analysis, but wrong with the conclusions. Yes, LLM „thinking process“ is kinda non-deterministic in a sense that it does not follow logical reasoning and will not produce logically correct results in 100% cases. It has an error margin.
However, error margins are in the center of any engineering discipline. We cannot produce things measured with 100% accuracy. This is accepted fact. The focus is always not on eliminating errors, but on reducing them to acceptable minimum. With LLMs we should not expect an ideal logical thinker, but a process that may error sometimes, and we must design quality controls instead that push LLM outputs within acceptable margins. And it can work.
kentm
8 minutes ago
Yes but the key here is doing proper risk assessment. "What is the consequence if the LLM gets this wrong?" "How do we verify the output?" "What are the legal ramifications for using the LLM in this way?" "Who is responsible when the LLM fails?" "Whats the expected accuracy here?" etc.
In the current AI mania, there's a lot of due diligence simply being ignored. Plenty of "Well humans make mistakes too!" going on here on HN too.
gbnwl
9 minutes ago
Every day I wake up and open HN.
“LLM has made legitimate mathematical discoveries” —> Wow the rate of progress is amazing. Highly upvoted.
“LLM does something not good” -> Does everyone else not realize LLMs are just dumb next token predictors? Highly upvoted.
So tired of this discourse and this site. If you seek the truth it won’t be found in the gutters here.
apples_oranges
5 minutes ago
Would be nice to get high karma commenter votes count only ..
red75prime
2 hours ago
Apophatic intelligence? "We don't know what intelligence is, but LLMs with CoT are certainly not it despite being Turing-complete."
Watching for unexpected failure modes is surely worth it.
gortok
an hour ago
Turing-completeness is a necessary pre-requisite for being able to fulfill the requirements of a Turing machine, nothing more. In the same way that cell division is a necessary condition for life, but cell division does not mean a given life form itself is sentient.
Intelligent life-forms can generate probabilistic outputs based on inputs, but being able to generate probabilistic outputs based on inputs is not what makes us intelligent.
red75prime
an hour ago
OK. A more pointed question. What do you know about intelligence that allows you to exclude LLMs with CoT from the category of intelligent systems with certainty?
buttercraft
29 minutes ago
How do you know there's not a teapot orbiting the sun?
tired-turtle
5 minutes ago
You’re right to point that out. The load-bearing seam of your logical retort is the hidden assumption that the teapot is in outer space, not at peace on a kitchen stovetop here on earth. I am sorry I had not considered this fact. \s
estearum
an hour ago
> but being able to generate probabilistic outputs based on inputs is not what makes us intelligent.
???
Of course it is. The brain is mechanically not capable of doing anything other than that.
Do you believe the brain is something other than a bundle of probabilistic physical interactions? Or are brains not the source of what we call intelligence?
pessimizer
25 minutes ago
Yours is a controversial view. It is lazy and selfish to try to get other people to explain their case that it is not exclusively that, when saying that it is exclusively that is the weaker case, and you back it up with nothing but a snarky proclamation.
Are newly born babies reacting due to statistical probabilities that they have derived, or are they using something other than their brains?
beepbooptheory
23 minutes ago
Why is the brain probabilistic instead of deterministic?
tadfisher
22 minutes ago
This deserves about as large of a "[citation needed]" as one could draw. Are you well-studied in neuroscience?
tsunamifury
40 minutes ago
This is the right conclusion for completely wrong reasons haha. I love hn. (asside from being entirely wrong as most models are now mixed modal so they are token predicion engines)
Each layer of attention can more through feature space “lit up weight clusters” in a way no other previous AI can. It can from that decode some rudimentary logic and world modeling and make deductions. Certainly better than any previous AI. Only a goof here would believe this wasn’t a serious advancement.
So don’t over sell it. But don’t sell it short with this “grrr in an engineer don’t threaten me with new tech” attitude.
This take is akin to teenage angsty takes and doesn’t really belong here.
budsniffer952
12 minutes ago
My lord you people are so melodramatic.
We are not going back, period. No amount of whining, or taking about how awesome your manual code is, or telling us all LLMs are not AI is going to change it.
We don't care what your preferences are. Nobody is forcing you to use it, or use tools created by LLMs. Do whatever you want to do or not do. You don't need to post the same slop under every AI article.
I know, for a fact, that the bar for "good code" is way lower than what you people pretend it is. Every vulnerability is now AIs fault. Laughable stuff.