TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

A framework to securely use LLMs in companies – Part 1: Overview of Risks

136 pointsby sys42590almost 2 years ago

2 comments

patrakovalmost 2 years ago
I disagree with their risk ranking matrix. The controversial cell is &quot;Prompt Injections&quot; &#x2F; &quot;3rd Party LLMs&quot;. It says: &quot;Medium risk. While the risk exists, the responsibility of fixing this is on the LLM provider.&quot;<p>No. The responsibility of using a vulnerable 3rd party component is always on you, unless there is a clause in the contract that says otherwise (and even then it might not apply or can be found illegal and void). Case in point: the payment info leak from ChatGPT in Italy was entirely due to a bug in a third-party component, redis-py, used by them.<p>Also, the concept of owning the LLM is used a lot, but not explained in sufficient detail. I don&#x27;t see a sufficient level of distinction between LLMs both trained and used in-house and LLMs trained by 3rd parties but with the inference going on in house.
评论 #36796507 未加载
cloudkingalmost 2 years ago
What problems are companies solving with LLMs that they couldn&#x27;t previously solve?
评论 #36796070 未加载
评论 #36795628 未加载
评论 #36796538 未加载
评论 #36795604 未加载
评论 #36797579 未加载
评论 #36795581 未加载