AI code helpers just can't stop inventing package names
ID: 3271f816-7058-5cf7-a8f3-ea1efaea83d5
STIX ID: report--3271f816-7058-5cf7-a8f3-ea1efaea83d5
Feed Name: The Register (Security)
The article reviews research showing that code-generating LLMs frequently hallucinate package names (5.2% for commercial models vs. 21.7% for open source; 205,474 unique bogus names), creating a software supply-chain risk; mitigation using retrieval-augmented generation and supervised fine-tuning reduces hallucinations but degrades code quality. A second study finds larger, more fine-tuned models are more accurate overall yet less reliable, tending to answer everything with plausible but wrong responses that humans often misjudge, reinforcing cautions against relying on AI for high-stakes tasks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
