| ▲ | thih9 4 days ago | |||||||
I guess this would also require models trained on pre-2023 data - or not trained on later curl code, changelogs, blog posts discussing curl security fixes, etc. | ||||||||
| ▲ | goobreee 4 days ago | parent [-] | |||||||
i don't think this is doable fairly. as they say in the blog post, the only fair way to is to look for new, previously undiscovered zero-days, otherwise you always risk the model has in some way been trained on the vulnerabilities. looking for legit new stuff is the only way to prevent leakage (even accidental one) | ||||||||
| ||||||||