Conversation

Jonathan Corbet

So why didn't I think of this business model?

1) Poke LLMs for a while and see which nonexistent URLs they hallucinate most often.

2) Register those domains and put malicious web sites behind them.

3) Profit!

https://spectrum.ieee.org/ai-cyberattacks-llm-slop-squatting

(What a world we have made...)
2
18
24

@corbet I would totally spend money on setting up an LLM poison honeypot web server if it were feasible

0
0
0

@corbet

Poisoning LLMs seems to quiet easy and very hard to combat: https://hachyderm.io/@shafik/116568719899080063

This will only becomes a bigger problem with time and surely large players are already doing this. The bar is so low and most are using code w/ nary a detailed code review.

1
0
0

@corbet

and even when people do pay attention their rate of catching issues is not great: https://hachyderm.io/@shafik/117113100447064373

0
0
0