用多模型协作验证代码生成,防范大模型隐藏漏洞
Beyond Trusting Trust: Multi-Model Validation for Robust Code Generation
- 通过多个独立模型交叉比对,识别异常代码模式
- 利用模型共识发现单个模型难以察觉的潜在后门
- 适合关注AI编程安全与可信开发的研究者和工程师
本文探讨了汤普森的《关于信任信任的反思》与现代大语言模型代码生成挑战之间的类比。我们分析了汤普森关于编译器后门的观点在大模型时代的全新意义——如今的模型机制更为隐蔽且难以分析。基于此,我们指出大模型的统计特性为代码生成流程带来了新的安全风险。作为可能的解决方案,本文提出一种基于集成的验证方法,利用多个独立模型通过跨模型一致性来检测异常代码模式。本文旨在引发关于人工智能辅助软件开发中信任与验证的讨论。
原文摘要 · Abstract (English)
This paper explores the parallels between Thompson's "Reflections on Trusting Trust" and modern challenges in LLM-based code generation. We examine how Thompson's insights about compiler backdoors take on new relevance in the era of large language models, where the mechanisms for potential exploitation are even more opaque and difficult to analyze. Building on this analogy, we discuss how the statistical nature of LLMs creates novel security challenges in code generation pipelines. As a potential direction forward, we propose an ensemble-based validation approach that leverages multiple independent models to detect anomalous code patterns through cross-model consensus. This perspective piece aims to spark discussion about trust and validation in AI-assisted software development.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。