| ▲ | skydhash 3 hours ago | |||||||
The fact is that humans are accountable and this, alongside training, makes it easy to align them to your own goals. There’s always the possibility of rogue individuals (recent Apple incident), but the likelihood is very low. If you have a DBA that have write access to the prod DB, you don’t fear that a random text somewhere could trigger the deletion of your customers table. Because the DBA will self regulate (with the help of processes) to not do that. | ||||||||
| ▲ | TeMPOraL 3 hours ago | parent [-] | |||||||
Right. But even with a DBA, the possibility remains. We accept that. That's kind of my point with fighting against the "lethal trifecta" and "code vs data" mindset - once people engage cybersecurity mindset, they're all binary, "a system is either perfectly safe or is broken". With general AI - LLM or whatever comes next - you'll never have "perfectly safe". So the focus should be to either drive the risk down to minimum - like we do with people - or just not use LLMs for a task in the first place. Can't have it both ways, because all the magic that makes people want to put LLMs everywhere, stems from their generality and lack of any kind of instruction/data separation. | ||||||||
| ||||||||