Live data from Hacker News

EY Canada published a cybersecurity report and most citations were hallucinated

gptzero.me

41–50 of 156 posts

Re: EY Canada published a cybersecurity report and most citations were hallucinated

#43
post #16
post #8

The problem we're seeing across many professions is AI output is not getting vetted by knowledgeable people, whether it's an experienced analyst, senior engineer, expert attorney, or the resident physician. At best they skim, at worst they don't even see it at all before it's published, pushed to production, distributed to clients, or submitted to the court. In many cases the skills are available in house to do the n…

> In many cases the skills are available in house to do the necessary vetting, but these people are already overwhelmed with their existing day to day. I think a lot of the time it's just pure laziness. AI gives people a magical "do all the work for me" button and it can bring out the worst in them.

I constantly battle this dichotomy where I care about the work I do but I also cannot possibly care about the corporate model, given 0 ownership of flawed processes across the org and the looming layoff that'll happen any day now.

Some people are given the button and really do not care.

Re: EY Canada published a cybersecurity report and most citations were hallucinated

#44
post #8

The problem we're seeing across many professions is AI output is not getting vetted by knowledgeable people, whether it's an experienced analyst, senior engineer, expert attorney, or the resident physician. At best they skim, at worst they don't even see it at all before it's published, pushed to production, distributed to clients, or submitted to the court. In many cases the skills are available in house to do the n…

[deleted]

Re: EY Canada published a cybersecurity report and most citations were hallucinated

#45
post #12

Earlier quoted context omitted.

Part of the problem: you get given a complete document to review after it's been fully baked. I'm pushing the need for basic engineering principles across whole organisations. You wouldn't give an engineer 1000 lines of code to review without the original spec of what you're trying to achieve for context (at a minimum, ideally the reviewer was in the room when the work was introduced, and has full context). So, these…

> Part of the problem: you get given a complete document to review after it's been fully baked. Not fully baked, worse: made to sound confidently correct, orthogonal to its actual correctness.

Like the fake food they make for commercials. Looks great on TV.

Re: EY Canada published a cybersecurity report and most citations were hallucinated

#46

I don't quite get it why they can't take another LLM and vet the output of the first with the second one. Surely they would not have the same hallucinations and would be able to detect hallucinations of the earlier LLM. Maybe it would cost too much in terms of tokens? I don't know but I would expect it to be realtively easy for an LLM to detect "hallucinations".

> I don't quite get it why they can't take another LLM and vet the output of the first with the second one.

Yes, this technique and its variations[1][2] "work" but it's still not 100% perfect. And it's not as widely used it might be because, among other reason:

a. it takes longer to implement

b. it costs more (more tokens spread across multiple llm calls)

c. higher latency (getting an answer takes longer due to multiple llm calls involved)

d. the final answer is probabilistically more likely to be correct, but is still not guaranteed to be error free, so you can never fully escape the need for Human in the Loop.

[1]: https://en.wikipedia.org/wiki/LLM-as-a-Judge

[2]: https://github.com/karpathy/llm-council

Re: EY Canada published a cybersecurity report and most citations were hallucinated

#47
post #14

This sort of thing is a complete embarrassment to a firm like EY, where people are paying them a lot of money for advice. They’ve basically demonstrated that their market leading research is just someone asking questions to ChatGPT. If you ever needed evidence to not buy “advice” from such outfits, this is exhibit one. Hopefully they at least fired the partner that published this steaming pile of AI slop.

The Big Four have become a shadow of their former selves. They have become so risk averse that their advice is already incredibly generic and non-actionable. I think their audit work is in a downwards spiral. Audit has become so competitive that they are struggling to find ways to make it cheaper. They have become slaves to reducing the hours booked, and the rate of those hours. To do this they substitute less experi…

I worked at a top 5 hedge fund in the early 2000s. They had a large team of E&Y auditors onsite at all times that I worked somewhat closely with.

Some things stuck out at me: - They were all in their early 20s. - They were all incredibly checked out. Honestly they still seem like an outlier to me decades later. - They partied hard. Yes, with drugs. - Most of them were in rotating intimate relationships with each other and unusually open about it. Office scuttlebutt was literally "who is fucking who this week". - They seemed busy for maybe two or three weeks out of the entire year and then it was long stretches of Minesweeper/Solitaire.

I filed this away in my head as "provides no value" and that was decades ago. If the industry itself is worse off today I can't imagine how much worse it actually is from my experience.

Re: EY Canada published a cybersecurity report and most citations were hallucinated

#48
The real comedy is seeing this garbage come down from senior management, clumsy prompting, hallucinated garbage that’s all fluff and zero actionable information, zero real informed analysis. “See this analysis of our support issues from jira, we must fix these top three problems!!!” And it’s all the stuff everyone has known for years but management has refused to give anyone the authority to fix anything. I’ve seen this more than twice now; needs a name. Garbagemaxxing?
Post reply on HN