Risky Business Features
In this podcast episode James Wilson chats with Karsten Nohl about his research into using local LLMs to replace cloud AI in security code reviews. In essence, Karsten created a hybrid code reviewing system where both cloud and local models are used to orchestrate, triage outputs, and write reports. In this system, only the local LLMs have source code access, with the cloud models used to manage the local models. In this “source-local” review technique, the source code never leaves the local endpoint, which is a requirement for some reviews. But funnily enough, Karsten was able to use this system to generate findings that were as impressive as when using frontier models directly. In a nutshell, Karsten proved it’s possible to use locally-hosted, open-weight models running on commodity hardware to produce findings comparable to those discovered by frontier cloud models. This episode is also available on YouTube [https://youtu.be/nhS5DTW0yzs]. SHOW NOTES * Beyond Fable: Can a Local LLM Replace Cloud AI for Security Code Reviews [https://srlabs.de/blog/beyond-fable] * Mythos smythos! How to find 0day with lesser models [https://risky.biz/RBFEATURES19/]
30 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de Risky Business Features community!