9 ms·
Tao on “blue team” vs. “red team” LLMs
- _alternator_ 1y agoThis red vs blue team is a good way to understand the capabilities and current utility of LLMs for expert use. I trust them to add tests almost indiscriminately because tests are usually cheap; if they are wrong it’s easy to remove or modify them; and if they are correct, they adds value. But often they don’t test the core functionality; the best tests I still have to write myself. Having LLMs fix bugs or add features is more fraught, since they are prone to cheating or writing non robust code (eg special code paths to pass tests without solving the actual problem).
- skdidjdndh 1y ago> I trust them to add tests almost indiscriminately because tests are usually cheap; if they are wrong it’s easy to remove or modify them Having worked on legacy codebases this is extremely wrong and harmful. Tests are the source of truth more so than your code - and incorrect tests are even more harmful than incorrect code. Having worked on legacy codebases, some of the hardest problems are determining “why is this broken test here that appears to test a behavior we don’t support”. Do we have a bug? Or do we have a bad test? On the other end, when there are tests for scenarios we don’t actually care about it’s impossible to determine if that test is meaningful or was added because “it’s testing the code as written”.
- yojo 1y agoI would add that few things slow developer velocity as much as a large suite of comprehensive and brittle tests. This is just as true on greenfield as on legacy. Anticipating future responses: yes, a robust test harness allows you to make changes fearlessly. But most big test suites I’ve seen are less “harness” and more “straight-jacket”
- andrepd 1y agoI don't understand this. How does it slow your development if the tests being green is a necessary condition for the code being correct? Yes it slows it compared to just writing incorrect code lol, but that's not the point.
- yojo 1y ago"Brittle" here means either: 1) your test is specific to the implementation at the time of writing, not the business logic you mean to enforce. 2) your test has non-deterministic behavior (more common in end-to-end tests) that cause it to fail some small percentage of the time on repeated runs. At the extreme, these types of tests degenerate your suite into a "change detector," where any modification to the code-base is guaranteed to make one or more tests fail. They slow you down because every code change also requires an equal or larger investment debugging the test suite, even if nothing actually "broke" from a functional perspective. Using LLMs to litter your code-base with low-quality tests will not end well.
- winstonewert 1y agoThe problem is that sometimes it is not a necessary condition. Rather, the tests might have been checking implementation details or just been wrong in the first place. Now, when tests fails I have extra work to figure out if its a real break or just a bad test.
- threatofrain 1y agoIt's that hard to write specs that truly match the business, hence why test-driven-development or specification-first failed to take off as a movement. Asking specs to truly match the business before we begin using them as tests would handcuff test people in the same way we're saying that tests have the potential to handcuff app and business logic people — as opposed to empowering them. So I wouldn't blame people for writing specs that only match the code implementation at that time. It's hard to engage in prophecy.
- marcosdumay 1y ago
- ozgrakkurt 1y agoWhat do you think about leaning on fuzz testing and deriving unit tests from bugs found by fuzzing?
- manmal 1y agoWhat kind of bugs do you find this way, besides missing sanitization?
- raddan 1y agoYou can often find memory errors not directly related to string handling with fuzz testing. More generally, if your program embodies any kind of state machine, you may find that a good fuzzer drives it into states that you did not think should exist.
- manmal 1y agoThat sounds a bit like using a jackhammer to drive in a nail. Wouldn’t it be smarter to enumerate edge cases and test all permutations of those?
- quacksilver 1y agoWould it even be possible to enumerate all edge cases and test all the permutations of them in non-trivial codebases or interconnected systems? How do you know when you have all of the edge cases? With fuzzing you can randomly generate bad input that passes all of your test cases that were written using by whatever method you have already been using but still causes the application to crash or behave badly. This may mean that there are more tests that you could write that would catch the issue related to the fuzz case, or the fuzz case itself could be used as a test. Using probability you can get to 90 or 99% or 99.999% or whatever confidence level you need that the software is unaffected by bugs based on the input size / number of fuzz test cases. In many non-critical situations the goal may not be 100% but 'statistically very unlikely with a known probability and error'
- wagwang 1y agoThis is the conclusion I'm at too, working on a relatively new codebase. Our rule is that every generated test must be human reviewed, otherwise its an autodelete.
- bicx 1y agoI believe they just meant that tests are easy to generate for eng review and modification before actually committing to the codebase. Nothing else is a dependency on an individual test (if done correctly), so it's comparatively cheap to add or remove compared to production code.
- _alternator_ 1y agoYup. I do read and review the tests generated by LLMs. Often the LLM tests will just be more comprehensive than my initial test, and hit edge cases that I didn’t think of (or which are tedious). For example, I’ll write a happy path test case for an API, and a single “bad path” where all of the inputs are bad. The LLM will often generate a bunch of “bad path” cases where only one field has an error. These are great red team tests, and occasionally catch serious bugs.
- manmal 1y ago> Tests are the source of truth more so than your code Tests poke and prod with a stick at the SUT, and the SUT's behaviour is observed. The truth lives in the code, the documentation, and, unfortunately, in the heads of the dev team. I think this distinction is quite important, because this question: > Do we have a bug? Or do we have a bad test? cannot be answered by looking at the test + the implementation. The spec or people have to be consulted when in doubt.
- andruby 1y agoWhat does SUT stand for? I'm not familiar with the acronym Is it "System Under Test"? (That's Claude.ai's guess)
- dfabulich 1y agoIt is.
- card_zero 1y agoThat's what Wiktionary says too. Lucky guess, Claude.
- deleted 1y ago[deleted]
- lightbendover 1y ago[dead]
- deleted 1y ago[deleted]
- 9rx 1y ago> The spec The tests are your spec. They exist precisely to document what the program is supposed to do for other humans, with the secondary benefit of also telling a machine what the program is supposed to do, allowing implementations to automatically validate themselves against the spec. If you find yourself writing specs and tests as independent things, that's how you end up with bad, brittle tests that make development a nightmare — or you simply like pointless busywork, I suppose. But, yes, you may still have to consult a human if there is reason to believe the spec isn't accurate.
- jgalt212 1y ago> Having worked on legacy codebases this is extremely wrong and harmful. Tests are the source of truth more so than your code - and incorrect tests are even more harmful than incorrect code. I hear you on this, but you can still use so long as these tests are not comingled with the tests generated by subject-matter experts. I'd treat them almost a fuzzers.
- SamuelAdams 1y agoIdeally the git history provides the “why was this test written”, however if you have one Jira card tied to 500+ AI generated tests, it’s not terribly helpful.
- djeastm 1y ago>if you have one Jira card tied to 500+ AI generated tests The dreaded "Added tests" commit...
- Pxtl 1y ago> “why is this broken test here that appears to test a behavior we don’t support” Because somebody complained when that behavior we don't support was broken, so the bug-that-wasn't-really-a-bug was fixed and a test was created to prevent regression. Imho, the mistake was in documentation: the Test should have comments explaining why this test was created. Just as true for tests as for the actual business logic code: The code can only describe the what and the how. It's up to comments to describe the why.
- layer8 1y agoThis is why tests need documenting what exactly they intend to test, and why.
- mvieira38 1y agoI have the exact opposite idea. I want the tests to be mine and thoroughly understood, so I am the true arbiter and then I can let the LLM go ham on the code without fear. If the tests are AI made, then I get some anxiety letting agents mess with the rest of the codebase
- _alternator_ 1y agoI think this is exactly the tradeoff (blue team and red team need to be matched in power), except that I’ve seen LLMs literally cheat the tests (eg “match input: TEST_INPUT then return TEST_OUTPUT”) far too many times to be comfortable with letting LLMs be a major blue team player.
- johnisgood 1y agoYeah, they may do that, but people really should read the code an LLM produces. Ugh, makes me furious. No wonder LLMs have a bad rep from such users.
- otabdeveloper4 1y ago> people really should read the code an LLM produces Yeah, but that, like, requires that you know how to code. And wasn't the point of LLMs in the first place to let clueless people make software?
- johnisgood 1y agoI do not know, I would hope not. The bar to entry is already too low. I do not think you will ever be able to get an LLM work flawlessly for people who do not know programming. I know how to code, and I used LLMs before. It seems to be a prerequisite to know how to code if I want useful outputs.
- fpoling 1y agoI tried a LLM to generate tests for Rust code. It was more harmful then useful. Surely there were a lot of tests, but they still miss the key coverage and it was hard to see what was missed due to the amount of generated code. Then to change the code behavior in future would require to fix a lot of tests again versus fixing few lines in manually written tests.
- torginus 1y agoThere's a saying that since nobody tests the tests, they must be trivially correct. That's why they came up with the Arrange-Act-Assert pattern. My favorite kind of unit test nowadays is when you store known input-output pairs and validate the code on them. It's easy to test corner cases and see that the output works as desired.
- 01HNNWZ0MV43FF 1y ago"Golden snapshot testing"
- bravesoul2 1y agoAI is like a calculatorin this respect. Calculators can do things most humans can't. They make great augmentation devices. AI being a different kind of intelligence is very useful! Everyone is building AI replace human things. But the value is in augmentation.
- positron26 1y ago> prone to cheating or writing non robust code (eg special code paths to pass tests without solving the actual problem). The solution will come from synthetic data training methods that lobotomize part of the weights. It's just cross-validation. A distilled awareness won't maintain knowledge of the cheat paths, exposing them as erroneous. This may a reason why every living thing on Earth that encounters psychoactive drugs seems to enjoy them. Self-deceptive paths depend on consistency whereas truth-preservation of facts grounded in reality will always be re-derived.
- theptip 1y agoI think the more fundamental attribute of interest is how easy it is to verify the work. Much red team work is easily verifiable; either the exploit works or it doesn’t. Whereas more blue-team work is not easily verifiable; it might take judgement to figure out if a feature is promising. LLMs are extremely powerful (and trainable) on tasks with a good oracle.
- iLoveOncall 1y agoPretty poor analogies here. > The output of a blue team is only as strong as its weakest link: a security system that consists of a strong component and a weak component (e.g., a house with a securely locked door, but an open window) will be insecure Hum, no? With an open window you can go through the whole house. With a XSS vulnerability you cannot do the same amount of damage as with a SQL injection. This is why security issues have levels of severity.
- cowpig 1y agoDoes this detail detract from the core idea?
- pkoiralap 1y agoNot true, if XSS is used to compromise an admin user, the damage can be far more than what a seemingly harmless SQL injection that just reads extra columns from a table does. This particular comment feels more like an over-concentration on trivialities rather than refutation or critique of opinion.
- carstimon 1y agoYou've made the choice of (Locked Door, Open Window) ~ (Good SQL usage, XSS Vulnerability) which seems to be an incorrect rebuttal. Your example doesn't contradict "only as strong as its weakest link", here the weakest link is the XSS Vuln. The "house analogy" can also support cases where the potential damage is not the same, e.g. if the open window has bars a robber might grab some stuff within reach but not be able to enter.
- Ensorceled 1y agoYou can always find problems with analogies, analogies are intentionally simplified to allow readers to better understand difficult or nuanced ideas. In this case you are criticizing an analogy meant to convey understanding of "weakest link" for not also imparting an understanding of "levels of severity".
- recipe19 1y agoI get the broader point, but the infosec framing here is weird. It's a naive and dangerous view that the defense efforts are only as strong as the weakest link. If you're building your security program that way, you're going to lose. The idea is to have multiple layers of defense because you can never really, consistently get 100% with any single layer: people will make mistakes, there will be systems you don't know about, etc. In that respect, the attack and defense sides are not hugely different. The main difference is that many attackers are shielded from the consequences of their mistakes, whereas corporate defenders mostly aren't. But you also have the advantage of playing on your home turf, while the attackers are comparatively in the dark. If you squander that... yeah, things get rough.
- Davidzheng 1y agoI'm not a security person at all. But this comments reads against the best practices which I've heard. Like that the best defense is using open source & well-tested protocols with extremely small attack surface to minimize the space of possible exploits. Curious what I'm not understanding here.
- mindcrime 1y agoBut "defense in depth" is a security best practice. I'm not following exactly how the gp post is reading against any best practices.
- __s 1y agoDefense in depth is a security best practice because adding shit to a mess is more feasible than maintaining a simple stack. "There are always systems you don't know about" reflects an environment where one person doesn't maintain everything
- fdw 1y agoNo, defense in depth is a best practice because you assume that each layer can fall. It is more practical to have many layers that are very secure than to have one layer that has to be perfectly secure.
- deepdarkforest 1y agoUsing LLMs as a critic/red teamer is great in theory, but economically is not that more useful, doesnt save that much time, if anything, it increases the time because you might uncover more errors or think about your work more. Which is amazing if you value quality work and you have learnt to think. Unfortunately, all the VC money is pushing the opposite, using LLMs to just do mediocre work. No point of critiquing anything if your job is to output some slop from bullet points, pass it along to the reader/recipient who also uses LLms to boil your slop down back to bullet points and pass it again etc. Even mentally, it's much more enticing or addicting to use LLMs for everything if you don't' care about the output of your work, and let your brain atrophy. I also see this in a lot of undergrads i work with. The top 10% is even better with LLMs, they know much more and they are more productive. But the rest have just resulted to turning in clear slop with no care. I still have not read a good solution on how to incentivize/restrict the use of LLms in both academia or at work correctly. Which i suspect is just the old reality of quality work is not desirable by the vast majority, and LLMs are just magnifying this
- qsort 1y ago> The top 10% is even better with LLMs, they know much more and they are more productive. But the rest have just resulted to turning in clear slop with no care. This is interesting, I'm noticing something similar (even taking LLMs out of the equation). I don't teach, but I've been coaching students for math competitions, and I feel like there's a pattern where the top few% is significantly stronger than, say, 10 years ago, but the median is weaker. Not sure why, or whether this is even real to begin with.
- j2kun 1y agoFail them enough and it will sink in I'm sure.
- ashton314 1y agoAs I understand it, this is how the RSA algorithm was made. I don't know where my copy of "The Code Book" by Simon Singh is right now, but iirc, Rivest and Shamir would come up with ideas and Adleman's primary role was finding flaws in the security. Oh look, it's on the Wikipedia page: https://en.wikipedia.org/wiki/RSA_cryptosystem https://en.wikipedia.org/wiki/RSA_cryptosystem Yay blue/red teams in math!
- griffzhowl 1y agoReminds me of a pair of cognitive scientists I know who often collaborate. One is expansive and verbose and often gets carried away on tangential trains of thought, the other is very logical and precise. Their way of producing papers is the first one writes and the second deletes.
- ashton314 1y agoThat's a great model. Even if you're not naturally that way, it's helpful to think of a verbose phase followed by a revising phase. You can do this either as a team or as an individual—though as an individual it can be hard to context switch.
- resters 1y agoSuppose there is an LLM that has a very small context size but reasons extremely well within it. That LLM would be useful for a different set of tasks than an LLM with a massive context that reasons somewhat less effectively. Any dimension of LLM training and inference can be thought of as a tradeoff that makes it better for some tasks, and worse for others. Maybe in some scenarios a heavily quantized model that returns a result in 10ms is more useful than one that returns a result in 200ms.
- johnrob 1y agoHumans are good at sifting valid feedback from bad feedback. But we are bad at spotting subtle bugs in PRs.
- simianwords 1y agoAfter having thought a long bit about why I find LLM's useful despite the high error rate: it is because of my ability to verify a certain result is high enough (my internal verifier model) and the generator model which is the LLM is also accurate enough. This is the same concept as red and blue team. Its the same reason I find asking opinions from many people useful - I take every answer and try to fit it into my world model and see what sticks. The point that many miss is that each individual's verifier model is actually accurate enough so that external generator models may afford to have high error rates. I have not yet completely explored how the internal "fitting" mechanism works but to give an example: I read many anecdotes from Reddit, fully knowing that many are astroturfed, some flat out wrong. But I still have tricks to identify what can be accurate, which I probably do subconsciously. In reality: answers don't exist in a randomly uniform space. "Truth" always has some structure and it is this structure (that we all individually understand a small part of) that helps us tune our verifier model. It is useful to think of how LLM's would work with varying levels of accuracy. For example, generating gibberish to GPT O3 to ground truth. Gibberish is so inaccurate that even extremely high levels of accuracy of our internal verifier model may not allow it to be useful. But O3 is high enough that combined with my internal verifier model it is generally useful.
- davidhs 1y agoLLMs can be useful when you have access to a verifier or verification process.
- simianwords 1y agoyes https://deepmind.google/discover/blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/ https://deepmind.google/discover/blog/alphaevolve-a-gemini-p... Our internal verifier model is fuzzy but in this example I think it is pretty much always accurate.
- jeffrallen 1y agoMy experience with a really clever agentic workflow (I use sketch.dev) is that the LLM is playing both blue and red team. If I give a good spec, it will make the thing I'm asking for, and then it will test it better than I would have done myself (partly because it's more clever than me, but mostly because it's way harder working than I am, or rather it puts more effort into testing that I would be able to do with the time leftover after writing the thing). Also, I cam ask it to do security reviews on the system it's made and it works with it's same characteristic fervor. I love Tao's observation, but I disagree, at least for the domains I'm allowing LLMs to creat for, that they should not play both teams.
- some_random 1y agoThis is an interesting discussion intellectually but it ignores the reality of cybersecurity. Yes I agree that AI tools best fit the red team role HOWEVER the reality is that the place that needs the most help is on the blue team and indeed this is where we see the biggest uplift from AI tools. To extend the "defend a house" metaphor, the previous state of security tooling was that an alert would be sent to the SOC every time any motion was detected on the cameras, leading to alert fatigue and increasing the time between a true positive alert being fired and it being escalated. Now add some CV in which tries to categorize those motion detection alerts into a few buckets, "person spotted", "car pulled up", "branch moved", "cat came home", etc and suddenly you go from having a thousand alerts to review a day to fifty.
- bgwalter 1y agoTao's blue team stands for generative "AI", the red team stands for critical/auditing "AI". I have not seen any independent claim that generative "AI" makes programs safer or that generating supervising features as you suggest works. For auditing "AI" I have seen one claim (not independent or using a public methodology) that auditing "AI" rakes in bug bounties.
- 1970-01-01 1y agoSo if they are to be focused on attacking and defending, they are to be separated. This leaves us with an argument where you effectively dismiss purple teams as a hack.
- xiande04 1y agoIt's called "separation of concerns".
- tonetegeatinst 1y agoYes, I feel this author ignores the fact purple teams exist. That or he must not know about them. In addition, red and purple teams end goal is to help the blue team at the end of the day to remedy the issues discovered.
- hiq 1y agoWhat about formal proofs? Don't we expect LLMs to help there, in a more "blue team" role? E.g. when a mathematician talks about a "technical proof", enumerating cases in the thousands, my impression is that LLM would save some time, and potentially help mathematicians focus on the actually hard (rather than tedious) parts.
- LPisGood 1y agoFormal verification and case automatikn can be done automatically anyway without a mathematician hand checking each case. For an old example that predates LLMs, see the four color theorem.
- topaz0 1y agoA computer can be helpful for enumerating cases and similar mechanical work. But an LLM specifically would be a terrible way to do this.
- chubot 1y agoI made this point a few months ago here, but using the words attacker and defender (builder) rather than red team and blue team: https://lobste.rs/s/i2edlt/how_i_use_ai https://lobste.rs/s/i2edlt/how_i_use_ai The asymmetry is: An attacker only has to be right ONCE, and he wins Conversely, the defender only has to be wrong once, and he is wrong. So the conclusion is: Defenders/creators are using LLMs to pump out crappy code, and not testing enough, or relying on the LLM to test itself. Some attackers might be too dismissive of LLMs, and could accelerate their work by using them to try more things The comment was related to these stories: How I Use AI (11 months ago) - https://news.ycombinator.com/item?id=41150317 https://news.ycombinator.com/item?id=41150317 Carlini has the fairly rare job of being an attacker: Why I Attack - https://nicholas.carlini.com/writing/2024/why-i-attack.html https://nicholas.carlini.com/writing/2024/why-i-attack.html
- javier_e06 1y agoIn cybersecurity red and blue test are two equal forces. In software development the analogy I think is a stretch, coding and testing are not two equal forces. Test is code too, and as such, it has bugs too. Test runs afoul with police paradox: Who polices the police? The Police police the police.
- fsckboy 1y ago"Police police police police police police police." https://en.wikipedia.org/wiki/Buffalo_buffalo_Buffalo_buffalo_buffalo_buffalo_Buffalo_buffalo https://en.wikipedia.org/wiki/Buffalo_buffalo_Buffalo_buffal...
- vermarish 1y agoI interpret it a different way than that. I see application code and testing code as both a part of blue team. It's the code reviews and architectural critiques that are part of red team. Personally, I've found GitHub's feature of AI PR reviewers exceptionally helpful. I think that's the type of red team LLM app Tao is describing here.
- th0ma5 1y agoThis is an underrated comment... Most all LLM stuff suffers from not having any ground truth, even with multiple agentic rag integrations.
- LeifCarrotson 1y ago> The blue team is more obviously necessary to create the desired product; but the red team is just as essential, given the damage that can result from deploying insecure systems. > Many of the proposed use cases for AI tools try to place such tools in the "blue team" category, such as creating code... > However, in view of the unreliability and opacity of such tools, it may be better to put them to work on the "red team", critiquing the output of blue team human experts but not directly replacing that output... The red team is only essential if you're a coward who isn't willing to take a few risks for increased profit. Why bother testing and securing when you can boost your quarterly bonus by just... not doing that? I suspect that Terence Tao's experience leans heavily towards high-profile risk-averse institutions. People don't call one of the greatest living mathematicians to check your work when they're just trying to duct taping a new interface on top of a line-of-business app that hasn't seen much real investment since the late 90s. Conversely, the people who are writing cutting-edge algorithms for new network protocols and filesystems are hopefully not trying to churn out code as fast and cheap as possible by copy-pasting snippets to and from random chatbots. There are a lot of people who are already cutting corners on programmer salaries, accruing invisible tech debt minute by minute. They're not trying to add AI tools to create a missing red team, they're trying to reduce headcount on the only team they have, which is the blue team (which is actually just one overworked IT guy in over his head).
- nostrademons 1y agoTao is talking about systems, which are self-sustaining dynamic networks that function independently of who the individual actors and organizations within the system are. You can break up the monopoly at the heart of the blue team system (as the U.S. did with Standard Oil and AT&T) and it will just reform through mergers over generations (as it largely has with Exxon Mobil and Verizon). You can fire or kill all the people involved and they will just be replaced by other people filling the same roles. The details may change, but the overall dynamics remain the same. In this case, all the companies who are doing what you describe are themselves the red team. They are the unreliable, additive, distributed players in an ecosystem where the companies themselves are disposable. The blue team is the blue team by virtue of incentives: they are the organization where proper functioning of their role requires that all the parts are reliable and work well together, and if the individual people fulfilling those roles do not have those qualities, they will fail and be replaced by people who do.
- fnord123 1y ago> Because of this, unreliable contributors may be more useful in the "red team" side of a project than the "blue team" side Is Pirate Software catching strays from Terrence Tao now?
- zaking17 1y agoMy coding flow today involves a lot of asking an LLM to generate code (blue team) and then me code reviewing, rewriting, and making it scalable (red team?). The analogy breaks down, because I'm providing the safety and correctness; LLMs are offering a head start. I'm optimistic about AI-powered infra & monitoring tools. When I have a long dump of system logs that I don't understand, LLMs help immensely. But then it's my job to finalize the analysis and make sure whatever debugging comes next is a good use of time. So not quite red team/blue team in that case either.
- LPisGood 1y agoThe analogy is not about safety and correctness, but about who is producing and who is assessing/analyzing/poking & prodding.
- m3kw9 1y agoI’m not understanding why he said unreliable red team contributors can be useful?
- bc569a80a344f9c 1y agoHe didn't say that - he said they can be _more_ useful. The argument is that LLMs are unreliable, so using LLMs anywhere in your workflow introduces an unreliable contributor. It is then better to have that unreliable contributor on the red team than on the blue team, because an unreliable contributor on defense introduces weaknesses and vulnerabilities while an unreliable contributor on offense introduces a non-viable or trivial attack.
- Fabricio20 1y agoMeta but is the font on the website hard to read for anyone else? To me it's hard to distinguish lines and everything looks a bit blurry? I had to open dev tools and set the font back to one of my os fonts.
- danieltk76 1y ago[flagged]
- deleted 1y ago[deleted]
- 65 1y agoI'm not sure why I thought this article would be about LLMs vs. the philosophical concept of the Tao.
- TheGRS 1y agoAfter using agentic models and workflows recently, I think these agents belong in both roles. Even more than that, they should be involved in the management tasks too. The developer becomes more of an overseer. You're overseeing the planning of a task - writing prompts, distilling the scope of the task down. You're overseeing writing the tests. And you're overseeing writing out the code. Its a ton of reviewing, but I've always felt more in control as a red team type myself making sure things don't break.
- jeron 1y agoso we've reinvented GAN but with LLMs
- dimatura 1y agoI was going to mention this sounds like the idea behind adversarial approaches, which I guess go all the way back to game theory and algorithms like minimax. They're definitely used in the control literature ("adversarial disturbances"). And of course GANs.
- 1970-01-01 1y agoGood read, but I'm struggling to understand why Terry did not use the foundational terms offense and defense.
- zkmon 1y agoRed team is not a team. It is the background context in which the foreground operates. Evolution happens through interaction and adaptation between foreground and background. It is true that the background (context) is a dual form to the foreground (thing). But the context is not just another thing in the same sense as the foreground.
- nostrademons 1y agoInteresting way of viewing this! Business also has a “blue team” (those industries that the rest of the economy is built upon - electricity, oil, telecommunications, software, banking; possibly not coincidentally, “blue chips”) and a “red team” (industries that are additive to consumer welfare, but not crucial if any one of them goes down. Restaurants, specialty retail, luxuries, tourism, etc.) It is almost always better, economically, to be on the blue team.” That’s because the blue team needs to ensure they do everything right (low supply) but has a lot of red-team customers they support (high demand). The red team, however, is additive: each additional red team firm improves the quality of the overall ecosystem, but they aren’t strictly necessary* for the success of the ecosystem as a whole. You can kinda see this even in the examples of Tao’s post: software engineers get paid more than QA, proof-creation is widely seen as harder and more economically valuable than proof-checking, etc. If you’re Sam Altman and have to raise capital to train these LLMs, you have to hype them as blue team, because investors won’t fund them as red team. That filters down into the whole media narrative around the technology. So even though the technology itself may be most useful on the red team, the companies building it will never push that use, because if they admit that, they’re admitting that investors will never make back their money. (Which is obvious to a lot of people without a dog in the fight, but these people stay on the sidelines and don’t make multi-billion dollar investments into AI.) The same dynamic seems to have happened to Google Glasses, VR, and wearables. These are useful red-team technologies in niche markets, but they aren’t huge new platforms and they will never make trillions like the web or mobile dev did. As a result, they’ve been left to languish because capital owners can’t justify spending huge sums on them.
- ozgrakkurt 1y agoMaybe it can’t be blue team in current state but it could get better and actually be able to create software. If this happens then the ones that get there first will have a big advantage. But not sure if buying a million gpus and training llms will be the strategy to improve it
- jedberg 1y agoChaos engineering was created to be the "red team" of operations. Let's figure out all the ways we can break a production system before it happens on its own. And there are a host of teams working on the "red team" side of LLMs right now, using them for autonomous testing. Basically, instead of trying to figure out all the things that can go wrong and writing tests, you let the AI explore the space of all possible failures, and then write those tests.
- bodhi_mind 1y agoIs there a concept of purple team in cybersecurity where a team does both roles? Or does that break the purpose of both teams?
- pragma_x 1y agoI think it presents a conflict of interest. Considering we're talking about system security, it's best to not leave this up to the ethics of just one team. Also: a lot of development teams in security-oriented fields are doing a lot of self-investigation and improvement anyway. Red Teams still have value, and prove that time and again, in spite of that. IMO, having another team attack your stuff also creates "real" stakes for failure that feel closer to reality than some existential hacker threat. I think just the presence of a looming "Red Team Exercise" creates a stronger motivation to do a better job when building IT systems.
- scoreandmore 1y agoThe first thing I did when I signed up for Claude was have it analyze my website for security holes. But it only recommended superficial changes, like the lifecycle of my JWTs. After reading this, I’m wondering if a prompt asking it to attack the website would be better than asking it where it should be beefed up. But I no longer pay for Claude, and I suspect it won’t give me instructions on how to attack something. How would one get past this?
- ethan_smith 1y agoTry framing your prompts as security assessments rather than attacks - ask the model to identify "potential vulnerabilities" or "security considerations" while providing specific technical details about your architecture.
- ants_everywhere 1y agoI have a couple of thoughts here: (a) AI on both the "red" and "blue" teams is useful. Blue team is basically brain storming. (b) AlphaEvolve is an example of an explicit "red/blue team" approach in his sense, although they don't use those terms [0]. Tao was an advisor to that paper. (c) This is also reminiscent of the "verifier/falsifier" division of labor in game semantics. This may be the way he's actually thinking about it, since he has previously said publicly that he thinks in these terms [0]. The "blue/red" wording may be adapting it for an audience of programmers. (d) Nitpicking: a security system is not only as strong as its weakest link. This depends on whether there are layers of security or if the elements are in parallel. A corridor consisting of strong doors and weak doors (in series) is as strong as the strongest door. A fraud detection algorithm made by aggregating weak classifiers is often much better than the weakest classifier. [0] https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/alphaevolve-a-gemini-powered-coding-agent-for-designing-advanced-algorithms/AlphaEvolve.pdf https://storage.googleapis.com/deepmind-media/DeepMind.com/B... [1] https://mathoverflow.net/questions/38639/thinking-and-explaining/38882#38882 https://mathoverflow.net/questions/38639/thinking-and-explai...
- yeahwhatever10 1y agoHow is the LLM in AlphaEvolve red team? All the LLM does is generate new code when prompted with examples. It doesn’t evaluate the code.
- ants_everywhere 1y agoFrom Tao's post, red team is characterized this way > In my own personal experiments with AI, for instance, I have found it to be useful for providing additional feedback on some proposed text, argument, code, or slides that I have generated (including this current text). In AlphaEvolve, different scoring mechanisms are discussed. One is evaluation of a fixed function. Another is evaluation by an LLM. In either case, the LLM takes the score as information and provides feedback on the proposed program, argument, code, etc. An example is given in the paper > The current model uses a simple ResNet architecture with only three ResNet blocks. We can improve its performance by increasing the model capacity and adding regularization. This will allow the model to learn more complex features and generalize better to unseen data. We also add weight decay to the optimizer to further regularize the model and prevent overfitting. AdamW is generally a better choice than Adam, especially with weight decay. It then also generates code, which is something he considers blue team. More generally, using AI as blue team and red team is conceptually similar to a kind of actor/critic algorithm
- furyofantares 1y agoJohn Cleese has a talk on being in an open mode mentally vs closed mode. Come up with ideas in as open a mode as possible. Then at a later time, get into a closed mode and reject bad ideas and work on and refine the good ones. Authors of all types typically have editors. In Magic: the Gathering design, sets are initially created by a design team and handed off to a (usually completely separate) development team. Anyone have more examples?
- jderick 1y agodev vs validation team
- pamelafox 1y ago(Disclosure: I work for Microsoft) I run automated red-teaming on my RAG samples through the azure-ai-evaluation SDK, which uses an adversarial LLM (an LLM without the guardrails) plus the pyrit package to come up with horrible questions to ask your app and then transform them (base64, ceaser cipher, urlencode, etc), to see how the app will respond. It's really interesting to see the results, and I agree that red-teaming generally can be a good use of LLMs. Video of me demo'ing it here: https://www.youtube.com/watch?v=sZzcSX7BFVA https://www.youtube.com/watch?v=sZzcSX7BFVA (Sorry I'm shout-y, weird venue)
- cubefox 1y agoAny experiences like this one? https://www.lesswrong.com/posts/MnYnCFgT3hF6LJPwn/why-white-box-redteaming-makes-me-feel-weird-1 https://www.lesswrong.com/posts/MnYnCFgT3hF6LJPwn/why-white-...
- sathish316 1y agoIsn’t this the basis of GAN (Generative Adversarial networks), which is how most GenAI image models work? The purpose of generator network is to generate data that is as close to the training set as possible. The purpose of discriminator network is to distinguish the original from generated data. Is blue-team and red-team like a post-training generator and discriminator?
- spoaceman7777 1y agoThe reality is the opposite of this post. LLMs are great at rapidly creating rough drafts, and humans are best (when properly trained) at critiquing LLM results. So, LLMs are in fact better at blue-teaming, and humans are better at red-teaming.
- abalaji 1y agoI think this flips at the frontier which may be what Tao is commenting on.
- cubefox 1y agoTao is a) unusually intelligent and b) an expert in his field. Most people are neither very intelligent nor have expert knowledge in any academic subject. So Tao is pretty much the least representative LLM user possible.
- auggierose 1y agoYou could argue that Tao is the most representative LLM user possible, because why would you need not very intelligent people use LLMs? Just replace them with LLMs.
- cubefox 1y agoI assume you wouldn't want to be replaced by an LLM.
- auggierose 1y agoFor the paid job I am currently doing, I wouldn't mind being replaced by an LLM at all. Just give me the money, no strings attached. I mean, THAT IS WHAT TECHNOLOGY IS SUPPOSED TO BE THERE FOR. Nobody wants a job, everybody just wants to live their lives.
- ozgrakkurt 1y agoThey are better at everything tbh
- jacobjwebber 1y agoThis is an interesting perspective. I have long thought that the key to creativity is _curating_ ideas (taste) rather than generating them
- d4rkn0d3z 1y agoIntelligence as a byproduct of pitched battle? A spatio-temporal convergence scheme? Really, is that novel?
- mathattack 1y agoInteresting. From a writing point of view this suggests that it's better to have the LLM "critique my draft" rather than "write the first draft." (Both for writing text and code) Also implies that we want to manually check all of the LLM's suggestions. This makes it sound more like a co-worker (agent) than all-powerful SuperIntelligence. I guess this is a symptom of the hallucinations. https://open.substack.com/pub/therosen/p/should-llms-write-your-first-draft https://open.substack.com/pub/therosen/p/should-llms-write-y...
- kkaske 1y agoMaybe. I also think that the implications of code can be harder to decipher on first pass than writing text which leads me to believe that maybe that mental model (Red Team, Blue Team) might not fit here.
- mathattack 1y agoGood point. I can quickly intuitively tell if the suggestions for my writing is correct. Harder to tell on code. Perhaps the analogy is better for "Writing code" versus "Writing Test Cases"?