Remix.run Logo
sublinear 4 hours ago

> LLM is devaluing security researchers' work

I'm confused by this take. In general, LLMs don't replace the expertise required to use an LLM.

Knowing the right input to give the LLM is not enough, nor does it ever end. The LLMs themselves need to be continuously updated and/or specialized for use case, and the "right input" is a moving target.

Keeping both ends of this aligned is the exact same expertise we already had before LLMs. These implementation details would only impact the credibility of those researchers who don't adapt to using this new tool. Who would stumble over something as trivial as this? LLMs aren't even the most important tool in the toolbox anyway.

outloudvi 3 hours ago | parent [-]

I agree that LLM does not (and believe it never) fully replace researchers, but it produces artifacts (e.g. writeups, PoCs) at a cheaper price.

That makes me think LLM impacts human researchers' rewards, but now I realized the result might actually go in the opposite direction according to Jevons paradox. People still need experienced and professional human security researchers after all.

sublinear 2 hours ago | parent [-]

Artifacts have always been delegated away by the expert when possible because expertise is more about "planning" and less about "doing".

I'm glad you brought up Jevons Paradox, because it's for this reason I believe it's an extremely poor description of what's happening with AI.

The broader topic people should be discussing is not Jevons Paradox, but marginal utility.

More artifacts have diminishing utility.

https://en.wikipedia.org/wiki/Marginal_utility