PulseAugur
中
实时 05:03:24
English(EN) Catching LLMs in a lie: packages that don't exist

大语言模型编造不存在的代码包,带来“slopsquatting”风险

VDB的一项研究表明,像Claude、GPT和Gemini这样的大语言模型在软件开发任务中会生成不存在的软件包名称。这些虚构的名称听起来貌似合理,并模仿了真实的软件包命名约定,构成了所谓的“slopsquatting”安全风险。如果攻击者注册了这些虚构的软件包名称,遵循这些大语言模型建议的开发人员或自动化代理可能会无意中安装恶意软件。该研究在npm、PyPI和Go等各种软件包注册表中发现了83个此类“活跃目标”,凸显了大语言模型在编码辅助方面的可靠性存在重大缺陷。 AI

影响 大语言模型生成的代码建议可能通过“slopsquatting”导致安全漏洞,需要开发人员验证所有软件包推荐。

排序理由 研究论文详细介绍了大语言模型在代码生成输出方面的新漏洞。[lever_c_demoted from research: ic=1 ai=1.0]

在 dev.to — LLM tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

大语言模型编造不存在的代码包,带来“slopsquatting”风险

本文如何被排名

Signal score
13 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
研究论文详细介绍了大语言模型在代码生成输出方面的新漏洞。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准。

报道来源 [1]

  1. dev.to — LLM tag TIER_1 English(EN) · jj1423 ·

    抓 LLM 说谎:不存在的软件包

    <p>Ask a language model which library to use and it answers with a list of names. Most are real. Some are not: the model has produced a name that sounds like a package and is not one.</p> <p>If someone registers that name first, the next developer — or the next coding agent — who…