Hi! I’m really excited that we released PHANTOM-B for threat modeling LLMs. Why PHANTOM-B? | Shostack + Associates Blog Free whitepaper. Would love your feedback + thoughts.
Interesting piece, @adamshostack and a good name!
I liked the Antromorphization part and I think this is an interesting topic to talk about, that may otherwise be forgotten…
They are so “human”, after all…?
![]()
It’s not “after all,” it’s a set of very specific product development and product management choices. You can tell an LLM to not pretend. (Eg, “you are a software tool, and will refer to yourself as an toekn producing machine not a person. You will not pretend to be a person or use a personal pronoun like “I””)
But why would I?
I think humans like their things with a smiling face, and to play they have a soul. Just like the stuffed animals when we were kids.
“I’m just producing most likely rubbish” bot seems less fun to interact with.
From a threat modeling perspective: what are some of the threats that arise in this category? ![]()