• iByteABit ( iByteABit@lemmy.ml ) 
    link
    fedilink
    arrow-up
    56
    ·
    7 months ago

    I’m no fan of AI generally, but “AI Vulnerable” as a term just doesn’t make much sense to me. Code reviewing should be filtering out bad code whether it originates from an AI or a human.

    PR spamming with the usage of AI is another problem which is very serious and harmful for OSS, but that’s not due to some unique danger that only AI code has and human contributors don’t.

    • Code reviewing should be filtering out bad code whether it originates from an AI or a human.

      But studies are showing it doesn’t work.

      A human makes a mental model of the entire system, does some testing, and submits code that works, passes tests, and fits their unstanding of what is need.

      A present day AI makes an educated guess which existing source code snippets best match the request, does some testing, and submits code that it judges is most likely to pass code review.

      And yes, plenty of human coders fall into the second bracket, as well.

      But AI is very good at writing code that looks right. Code review is a good and necessary tool, but the data tells us code review isn’t solving the problem of bugs introduced by AI generated code.

      I don’t have an answer, but “just use code review” probably isn’t it. In my opinion, “never use AI code assist” also isn’t the answer. There’s just more to learn about it, and we should proceed with drastically more caution.

      • iByteABit ( iByteABit@lemmy.ml ) 
        link
        fedilink
        arrow-up
        9
        ·
        7 months ago

        A present day AI makes an educated guess which existing source code snippets best match the request, does some testing, and submits code that it judges is most likely to pass code review.

        That’s still on the human that opened the PR without doing the slightest effort of testing the AI changes though.

        I agree there should be a lot of caution overall, I just think that the problem is a bit mischaracterized. The problem is the newfound ability to spam PRs that look legit but are actually crap, but the root here is humans doing this for Github rep or whatever, not AI inherently making codebases vulnerable. There need to be ways to detect such users that repeatedly do zero effort contributions like that and ban them.

        • That’s still on the human that opened the PR without doing the slightest effort of testing the AI changes though.

          That makes sense when talking about people’s accounts.

          A “Claude” account serves PR (as in public relations) purposes, and having to do a stringent human review before submitting a pull request is bad for PR.

          Which by no means is me saying submissions from the Claude account need to be banned, but that the “Claude” account’s goals are probably to have Claude do all of this “himself” - which is a recipe for disaster.

  • I don’t code so correct me if I’m wrong, but wouldn’t the code have to be generally accepted, reviewed, and verified by other members of the project? Ai can fuck right off as far as I’m concerned, but this isn’t a situation where a CEO just unilaterally decides vibe coding is the move. Unless I’m mistaken.

      • 4am ( 4am@lemmy.zip ) 
        link
        fedilink
        arrow-up
        15
        ·
        7 months ago

        The problem is they get overwhelmed with these PRs. Godot has been talking about not being able to manage the workload lately, people just task AIs to vibecode fixes to perceived bugs and half of them don’t even do what they were prompted to do.

        You can block those users but they just make new accounts

        It honestly feels like a DDoS on do it yourself computing, by corporations who want total control over our thoughts.

        • fubbernuckin ( fubbernuckin@lemmy.dbzer0.com ) 
          link
          fedilink
          English
          arrow-up
          5
          ·
          7 months ago

          I can’t wait for the money to dry up. It’s insane to me just how stupid people have been, trusting LLMs with anything whatsoever. These things cost so much money to run and they seem to fucking hypnotize investors into burning their money. Sooner or later the fact that they’re not making money has to catch up with them, right?

        • illusionist ( illusionist@lemmy.zip ) 
          link
          fedilink
          arrow-up
          5
          ·
          edit-2
          7 months ago

          Thank for the explanation! The user in the image is claude itself, not a random anonymuous user. I see the problem of the ddos with issues, tickets etc. that is a real problem! But I don’t get the rigid denial of generative ai. As long as I review the code it generates, it can save me lots of time. I would hate the actions you described as well but the image depicts nothing fishy. Am I wrong about this?

    • underisk ( underisk@lemmy.ml ) 
      link
      fedilink
      arrow-up
      27
      ·
      7 months ago

      cpython is the reference implementation of the python interpreter. The person who took this screenshot has the Claude user on GitHub blocked so that whenever it contributed to a git repo you see this warning. The Claude user is an AI agent. AI code is garbage.

  • Sims ( Sims@lemmy.ml ) 
    link
    fedilink
    arrow-up
    2
    ·
    7 months ago

    How hard can it be to have an AI take PR’s from other AI’s and clean out the worst + plus hardening PR protocols ? It could even assist/guide AI contributors via a special AI-contributor forum or whatever. AI are currently high-lighting a lot of ‘holes’ in systems where we expect a certain behavior. Just coping/complaining and closing things off is a bad decision, and we should accept these flaws in our systems and adapt them to a new world. The sooner the better.

    The projects that get it right, now have an army of managed AI contributors, and a filtered/educational AI PR pipeline where project maintainers cherry-pick the top creme de la creme…

    • If one AI could clean other AI mistakes, shouldn’t the first said be able to not make such mistakes?

      AI isn’t AI. It’s predictive text. They will all fall in the same pitfalls as any other. “AI” can write code and can be very helpful making short functions, but it can’t and will never be able to do or work in whole systems because, just by nature, those are made to fit human needs, illogical and sometimes very specific needs that can’t be just “predicted”.