#205 Randall Degges: The Biggest Risks of AI-Generated Code (What Developers Need to Know!)

28 Aug 2024 · 54 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Eye On A.I. Podcast Episode #205 Notes

Episode Title

Randall Degges: The Biggest Risks of AI-Generated Code (What Developers Need to Know!)

Episode Overview In this episode, Craig S. Smith interviews Randall Degges, Head of Developer Relations and Security at Snyk. They discuss the implications of AI in cybersecurity and software development, with a focus on AI-generated code and its associated risks.

Key Themes

  • AI in Cybersecurity: Discussion on how Snyk utilizes AI to enhance security measures in software development.
  • Hybrid AI Models: The use of symbolic AI for vulnerability detection and generative AI for proposing fixes.
  • Risks of AI-Generated Code: Concerns over AI hallucinations and the accuracy of AI-generated suggestions in coding.
  • Future of Coding with AI: Exploration of how developers can leverage AI tools and what the future may hold for coding.

Key Concepts

  • Symbolic vs. Generative AI:
  • Symbolic AI: Utilizes rule-based systems for high accuracy in detecting vulnerabilities.
  • Generative AI: Generates code fixes but can lead to inaccuracies or "hallucinations."
  • Snyk's Approach:
  • Uses a hybrid model combining symbolic AI for detection and generative AI for generating fixes.
  • Rigorous testing and validation processes are in place to ensure the functionality of AI-generated fixes.
  • AI Hallucinations: The phenomenon where AI generates outputs that are incorrect or nonsensical, particularly in code.

Detailed Insights Randall Degges Background (00:34)

  • Over 20 years of experience in software development and security.
  • Focus on building developer security tools that simplify security for developers.

Role of AI at Snyk (01:33)

  • Snyk is a developer security company that focuses on finding and fixing security vulnerabilities in applications.
  • Emphasis on enhancing developer productivity through AI-driven tools.

AI Models Used at Snyk (03:28)

  • Detection of vulnerabilities through static analysis and the use of symbolic AI for accuracy.
  • Generative AI is employed for proposing fixes, with a feedback loop to the symbolic model to validate those fixes.

Challenges with AI-Generated Code Fixes (06:48)

  • The reliability of fixes can vary based on the complexity of the code.
  • Snyk generates multiple solutions for each detected issue to give developers options.

Future of AI in Code Generation (09:08)

  • The potential for AI to create high-quality, executable code remains uncertain.
  • The need for human oversight in inspecting AI-generated code persists.

Integration with Developer Tools (11:56)

  • Snyk integrates with IDEs (e.g., VS Code) to provide real-time security analysis and fix suggestions.
  • Developers receive warnings and can use AI to generate fixes directly in their coding environments.

Risks of AI-Generated Code (16:06)

  • Concerns about the saturation of the internet with AI-generated code potentially leading to lower code quality.
  • The necessity for human review of code remains critical to maintain standards.

Hybrid AI Approach for Code Security (22:25)

  • Combining the strengths of both symbolic and generative AI to create robust security tools.
  • Ongoing efforts to enhance the accuracy of AI-generated outputs while minimizing hallucinations.

Future Impacts on Developers (26:31)

  • The evolving landscape of AI in coding suggests that developers will need to adapt to new tools.
  • Skills in leveraging AI tools will be crucial for future career opportunities in software development.

Autonomous Fixes and Future of AI in Development (33:48)

  • Discussion about the potential transition to fully autonomous fixes if AI accuracy can be guaranteed.
  • The importance of maintaining a balance between automation and human intervention in coding.

Conclusions and Insights (52:59)

  • Despite layoffs in the tech industry, there are opportunities for developers who can effectively use AI tools.
  • The interview emphasizes the ongoing need for skilled developers, even as AI continues to advance in the coding domain.

Additional Resources

  • Snyk Integration: Information on integrating Snyk into various IDEs and development environments.
  • AI Readiness Report: Insights from Snyk's recent report on AI adoption and readiness within organizations.

Final Thoughts The episode provides a comprehensive look into the intersection of AI and software development, highlighting both the potential benefits and risks associated with AI-generated code. The conversation with Randall Degges makes clear the importance of combining AI technologies with human oversight to ensure quality and security in software development.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00A year and a half ago or so there was just a ton of layoffs across the tech industry. things are pretty rough, but that wasn't really a result of AI or anything. That was more just a result of increased interest rates, less easy to get VC money, you know, the macroeconomic environment. Today, I would say, even though the macroeconomic environment is still fairly rough in that regard, there's a lot more opportunities because of this stuff. I'd actually say that if you're a developer today and you understand how to leverage AI tools to do your job faster, you have a lot of employment opportunities.

0:31I wouldn't be worrying about it in the near future at all. Could you go ahead then, Randall, and introduce yourself and tell us about Sneak? Yep. So hello, everyone. I'm Randall Daggs. I lead the developer and security relations team here at Sneak. If you've never heard of Sneak, we are a developer security company, and we really focus on two things, which is finding security vulnerabilities in your applications, but more importantly, fixing those vulnerabilities so you don't have to worry about them. And yeah, that's what we do in a nutshell. So myself and my background is I've been a software developer for over 20 years now.

1:09I got started doing operating system security work back in the day. Then I actually got into being a technical co-founder of developer services companies. And for the last 12, 13 years, something like that, I've been mainly focused on building developer security tools for people with the intention of just making security nicer for developers overall. And we were talking previously about code generation. How much is SNEAK's security service or detecting security vulnerabilities? How much of that is automated? Are you using AI in that process? Absolutely. Yeah, it's been a longstanding thing. So many years ago, we acquired a company called DeepCode.

2:02And the DeepCode team essentially brought the first version of Snyk's AI products into our portfolio. And the way that Snyk works, so I'll give you a really quick sort of breakdown there, is there's a couple different pieces. So first of all, if you think about detecting security vulnerabilities, there's a lot of different ways you can do that, right? So you can do static analysis, which is what we do, where you basically analyze the source code, you analyze the dependencies, and you break them into an AST. and you parse this big tree style structure and you try to figure out based on rules that security analysts have created, how these things match together, is something being like used in an improper or insecure way, what the potential results of that can be.

2:50And you essentially like find vulnerabilities by just doing static code analysis. However, since we now have these big generative AI models, you can also do this in a generative way where you can basically take a chunk of code or an application, you can say, hey, please analyze this and tell me what security issues there are. Now, doing security vulnerability detection using generative AI is kind of a risky thing to do because it's essentially just using big training sets of data and patterns to come up with these answers. And so there's no guarantee you're going to get really high quality results.

3:28So our point of view is that for security detection, it's actually better to use like classical AI, like using knowledge graphs, using symbolic artificial intelligence, which is the proper term for it, to essentially find these things with a very high degree of accuracy. And the difference between these two branches is you have symbolic AI, which is like extremely accurate, but very niche. And then you have generative AI, which is extremely inaccurate, but very broad and can answer lots of different things. So in our engine, we use symbolic AI for a lot of the detection stuff. Now, on the fixing side, it's actually the reverse.

4:08So if you imagine that you've successfully identified these security problems in your application, and you're looking at them and you have all this information there, you can't really use symbolic AI and existing training sets that humans created to say like, okay, well now we're going to go. And if it's this very particular line of code and this very particular thing, we're going to like write this very particular patch. It's just, it's way, there's too many variables basically. So what we do is we use generative AI to generate potential fixes. Then we run those fixes back through our symbolic detection model to make sure they're actually going to work.

4:41And so we have a lot of effort that goes into both sides of those things. So we use this hybrid approach. We use symbolic AI for detection, generative AI for fixing, and we use a combination of these things together to make the most robust possible developer security tools. And that symbolic AI, that's rule-based. Where did the rules come from? Is there some compendium of security rules that has been compiled over time? Exactly. Yeah, you nailed it. So I mean, we literally hire security analysts and we even built this massive internal web application. So the way it works is if you're a security analyst at sneak, part of your job is you actually log into this web application.

5:28You take a look at examples of known vulnerabilities that we've fully detected and fleshed out and you look at them and you analyze them and then you look at other chunks of code that might be similar. And you're like, okay, well, I can tell with my expertise that this vulnerability is also present in this thing that wasn't detected. And so then we have a whole custom rules-based language that they write to help detect and build these heuristics out essentially for the detection engine. So at the end of the day, we get like a massive database of these things so that we can then apply these rules at scale.

6:01Yeah. And on the generative side, when you're generating fixes, uh is there uh you i mean you as you said uh you you have to run it back through the symbolic side to make sure the the generated fixes aren't hallucinations or or inaccurate in some way what what's the percentage of of false positives let's say uh in the generated code i mean do you do you find that uh the the generated code 80 of the time it passes the symbolic ai uh test or or what what's that percentage uh that's a very good question so i don't know the exact percentages off the top of my head what i will tell you is that when we started designing this functionality um one of the core things that we built it for is this like trial and error model essentially.

7:04So imagine you're a developer, right? So you're building an application and you're writing your code inside of your IDE. So you're probably using like VS code or Vim or Emacs or whatever, right? But you have your tool set up in your environment. If you're using something like VS code or one of those editors and you have the sneak plugin installed into it, then what happens is we'll actually provide some linting warning. So we'll like, as you're writing code or importing open source tools or whatever, we'll underscore things that have security issues in them that we've detected using that symbolic engine.

7:37And if it's something that we feel confident we can fix based on the type of vulnerability, the programming language, the frameworks being used and all of these other variables, then we'll give people the option in the editor to actually say like, fix this with AI. And if they click that fix this with AI button, what we do is we take the context, the code, the application, all that, it gets parsed by Snyk's engine. And then what we do is we use generative AI to then generate potential fixes. And we generate multiple versions of it. So I believe by default, we generate three for every single fix.

8:11And what we do is we actually run them back through our thing. If they're not suitable, we actually try again until we have three unique solutions. And then we present those to the end user. so we actually say like by default you'll use number one out of three but like you can cycle through them and see the differences yourself before choosing which one to apply if you want to do it that way so we we're trying to take this approach where like you know like yes gender AI is going to hallucinate a lot we're able to reduce the occurrences of that happening substantially by feeding it back through our symbolic engine but at the end of the day there's still multiple ways to solve a problem.

8:50There's not always like 100 % guaranteed way to fix something. There's always going to be multiple ways to do it. So we try to expose that optionality back to the end developer so they can then use their best judgment to see what fixes the best for their particular style or code base and things like that. Yeah. What's the model that you're using on the backend to generate code? But do you guys have your own large language model or are you using OpenAI or Anthropic? So to answer your question, we're not using any of the big model providers. We're not using OpenAI or Anthropic or any of those. We have our own stuff, which is based on open source models, but is then customized on top of that with our own training set information.

9:40um i'm not sure i'm allowed to provide these very specific details so i'm not going to say that but uh but yeah it's it's a big joint effort and we have a very large dedicated ai and machine learning team that that's their their primary job is building that yeah yeah and it's uh it's an open source model that then's then is fine-tuned or or yeah or do you do you have a vector database of millions of code examples that use RAD. Good question. Yeah, so it's actually both. So it might also be a good distinction to just talk about those two approaches because you mentioned like the biggest two. So when you're trying to make AI responses smarter, essentially, right?

10:30You really have a couple different choices. The two most popular are the ones you mentioned. So there's basically taking examples of things that are nice and breaking them into embeddings and storing those into something like a vector database. And what happens then is when you're asking AI queries, you're first going to talk to your database and say, hey, here's the question being asked. What are some chunks of context that are very relevant to this question? So it's going to pull those out and then send those along with the actual question to the AI model so that it can then have that context to provide a better quality answer.

11:10And that pattern is sometimes referred to as retrieval augmented generation, like RAG, RAG. The second option is you pre-train these models by fine-tuning them with tons of examples beforehand. Now, that takes a lot of pre-planning and forethought. And so if you have a lot of structured data that you can go through and carefully vet, then fine-tuning is a really good option. But ideally, you actually want to do both, which is what we do. So we'll actually take all of the stuff that our security analysts and ML team works on and basically fine-tune these models ourselves. But then in addition to that, we also have context that's provided both by the very specific code base that you're using and other heuristics to help improve the results even further.

11:55yeah yeah that's interesting and and i'm going to ask a dogleg question uh before i come back to to code generation i was talking to boston consulting group uh a week ago and they were showing me a conversational agent that they built and instead of using rag they're using the context window and and they load you know like if if if they want the agent to be able to talk about bcg research they load i think they can load up to 250 pages of text into the the the main prompt the system prompt uh and and just the the model then will will answer out of that Is that, and as these context windows, when people are talking about sort of infinite context windows, is that going to replace RAG that kind of, where you just put everything in the system prompt or the prime prompt or whatever it's called, instead of having this external database?

13:09Good question. And I think the answer is definitely not. So we'll not replace it, but we can talk about why. So right now there's like a battle, if you will, going on in the AI space around how big you can make your token limit, your context window essentially, right? And there's always a direct trade-off when you're taking that approach. So let me explain why it matters, especially for developers. So imagine that you want to ask AI a simple question like, please, maybe you create a prompt that says something like this. please generate a secure bookmarks web application for me. It should be written in Python using the Flask web framework, and it should be no more than 500 lines of code, and it should be perfectly secure.

13:54So it should be production ready so I can deploy to AWS. So this is your prompt, right? Well, if you just send that prompt with no other context to a model like OpenAI, we'll just use OpenAI since everyone knows about them, send it to OpenAI GPT-4 model. it's going to take it it's going to give you a response now how do you improve that response well you can improve it by providing additional context now in the case of this question what you could do is you could say okay well we're talking about flask we're talking about python we're talking about aws so what if we just built a tool that goes to the flask website the python website the aws website and downloads the entire websites for each of those and then dumps all of that right before the question says hey by the way everything in the next trillion pages of context is like relevant documentation you might need here's my question that's essentially what you're doing when you're inputting it all into the the context window for a question and the the fundamental problem with that is that first of all a lot of that information is already taken into account by these models during the training phase right so like flash documentation aws documentation like those things have surely been incorporated already.

15:07So you might be doing redundant work. But that's not the only problem. The other problem is that your request is going to be way slower because you're taking a ton of information and you're sending it in HTTP requests to a website that is then processing it. So there's a fundamental transfer time over HTTP. There's also the problem of like, this is now a much more computationally expensive operation for the model to compute. So instead of just chunking through like a limited amount of tokens, it's now chunking through a lot of stuff. So your response time will be much slower and it's much more expensive to actually run those larger queries.

15:44So it's a great question, but I think fundamentally retrieval augmented generation is like, it's always going to be around in some form or another because it makes things time and cost effective where there may not otherwise, it may not otherwise be possible for that. Yeah, that's interesting. So back on code generation, you and I have had a long conversation before about code generation. I'm very interested in it because I'm not a coder and I would love to be able to code things using natural language.

16:26The problem is the hallucination. And for somebody like me who isn't qualified to make a judgment on generated code, how accurate do you think code generation can be? And one of the problems causing the hallucination is that there's a lot of bad code in the training data. uh if if you trained if you curated your training set uh so that it's all very clean accurate code would that create a model uh that's uh that's more accurate in code generation than say co-pilot or something that's built on top of a general purpose pre-trained transformer model so yes and let's i'm going to break this down a little bit more because it's a very interesting question and there's a lot of uh there's a lot of potential impacts of this in the long run for our industry.

17:42So I'm going to go a little more in depth. So first question I think we should answer that's very interesting is if you have a model training set of perfectly curated data, first of all, is it possible to get that? And second of all, if you have that, is the model when you ask the questions going to generate perfectly generated things? So those are the first two fundamental questions. So I would argue that for software development in particular, it's not possible to have a perfect training set. There's no way to get there. And the reason why is sort of interesting, right? So if you are open AI, and you are building the GPT-5 model that is yet to be released, right?

18:27The first thing you care about is where do we get training data from? And the obvious answer is, okay, well, let's go to Stack Overflow. Let's go to GitHub. Let's pull in all these developer-y sort of places so we have good code examples for people, right? Well, there's a problem with that. The first problem is what you alluded to earlier, which is that there's a lot of bad code examples out there. Sure, that's a given. But a lot of those could be mitigated by having people go through these examples and prune out bad stuff or do all sorts of things, right? However, even with that being done, which is a huge assumption that like there's enough human resources to do that type of thing.

19:06The next problem is that what does it mean to actually have perfectly secure code? Like that question in and of itself is extremely difficult to answer because I can create a Python application right now. And that application I can design to be flawless from a security perspective. Like I can build a web app that properly authenticates people and properly authorizes them and does all this stuff. However, there's a lot that I just don't know that I don't know. So there could be new attack techniques discovered tomorrow, which would then make my thing vulnerable. And so it's not vulnerable now when I'm assembling the training set, but in the future, it will be.

19:44There's also a lot of context related things. So if you're building, here's a good example of this. you're building a secure web app to store and manage bookmarks or something, right? So you're storing and managing these bookmarks. You have authentication, you have authorization, you have all these things. Even if you're doing that properly, if you were to take that same context and then try to apply it to a banking scenario and say, okay, well, it's the same thing. We're just logging in, we're logging out, we're doing these things. It would no longer be a secure application because I guarantee you that the differences between a secure banking application, it's going to have shorter live session cookies.

20:20It's going to have different types of token based authorization. It's going to have all these very nuanced changes. So in your training set, there's no way to properly reflect all of that without just an, an infinite amount of information and curation. So yeah, I guess the, what I'm saying is I don't know if it's feasible for software development to have a perfect training set. And so because of that, you'll always have some form of hallucination or uncertainty in model responses for sure it's just a given i think and go ahead well well then and that's where the hybrid approach comes in where you have uh you know rule-based symbolic ai sort of checking the work of the generative AI.

21:08Yep. And we talked earlier about as these generative AI tools, coding tools, proliferate. And my understanding is more than half of the world's developers are now using some form of coding assistant. Is there a risk that the internet or the global code base fills up with generated code and that that generated code may not be as clean even if it's executable as human written code and and pretty soon you have a world where these code bases are nearly unreadable by humans that you're going to need you know another AI assistant just to check the code or read the code or find bugs and that sort of thing Yeah.

22:26So, I mean, that's a trillion dollar question you're asking potentially. If I knew the answer to that, I would be betting money hard into certain companies in the stock market today. I think the answer is nobody really knows. There's a lot of potential for this to go in either direction. so let's play it out for a second let's say that a lot of ai generated tools are generating software and documentation and other things that go onto the internet and that those same pieces of information are then fed back into the training sets to inform future models the main question is is that enough quality and differentiation to improve models or is it going to hurt models right um i think that as of right now the technology is at a point where it would absolutely hurt the models for sure however there's a potential to change that which is having human review uh carefully analyze new new things and curation really at the end of the day are you able to successfully curate this massive amount of information in in such a way that you're going to improve quality.

23:39And I think OpenAI, Anthropic, Facebook, a bunch of other companies are all actively working on solving this problem. There's a lot of tools and techniques and papers coming out all the time to address this. But all the latest ones I've seen at this point in time basically say, it's to be determined. We're just not sure how it's going to go. And so there's a lot of money and time being invested in that question right now. Yeah. And you mentioned earlier that already these large models have ingested most of the open source public code available out there. And so, you know, how do you go beyond what the models know today?

24:30Yeah, I mean, it's it's it's a very difficult thing to answer like if you assume and i think it's very easy to assume for sure because it's it's absolutely the case that all of the models have been trained on all available open source code that's like a given at this point for sure so where are they getting new information from the future i mean it's basically just coming from two places really it's either people publishing net new stuff into these databases maybe three places right so people publishing that new stuff, right? If you're a developer and you create a new web framework, for example, you build a website for it, you put it online, that will be included in future things.

25:07And so there's going to be that information eventually. Second thing, maybe there's not publicly available sources that are being utilized. And there's a lot of like security and governance and policy issues around that. But are places like OpenAI and other model providers, are they pulling in proprietary information from someplace? Did they buy it? Are they getting it from different places like we don't necessarily know? And then the third option is, are they just accidentally almost slurping in AI generated stuff without realizing it? And those things are gonna be derivative works. And so it's a lot of like, yeah, there's three potential sources of this.

25:48And the uncomfortable truth is that without a lot of human curated stuff, there's gonna be problems in one way or another. And so that's the biggest issue I would say right now is like, how do you do curation? Is there a way to do it more scalably? Is there a way to use AI to help with curation, right? Like how can you apply all these things to just make sure that progress can continue to be achieved? And then furthermore, what is progress gonna look like? You know, we've seen since 2022, right? Like the rate of AI improvement has been like exponential hockey stick growth. However, how long can that last?

26:24Is it gonna go up like 200%, 1 ,000 % in the next year? is it going to level off are we going to start going down those things are going to make a huge impact on the world and future generations for sure yeah and and as um i mean i've i've talked to uh to researchers about this not specifically about code but as generative models are trained on generated content, there's a reversion to the mean. You end up losing the variation. And I would think with regard to code, you would end up with sort of standard ways to do things that may be in that they're generated or not the best way to do things for a human engineer if he has to read the code or fix a code or that that's what I was referring to mean is it possible that we'll get to a day where there's so much code out there that's been generated by AI that that humans can no longer really parse through it without depending on AI that has been trained on all this generated code to begin with.

27:52And so you get into this loop where you can't break out of. Hey, it's time to make online shopping personal. Bloomreach personalizes the e-commerce experience, unifying real-time customer and product data to understand what customers really want. By connecting all that understanding to every channel, the e-commerce experience becomes limitless. Amplified by Loomy, BloomReach's AI for e-commerce, this creates endless new paths to purchase, greater profitability, and fast business growth. So give BloomReach a try. Yeah, and that's a very real fear, I would say. I don't think it's like unfounded to worry about the future of some of those topics.

28:42Like, you know, the approach we're taking at sneak for this is we're basically saying, okay, there are very specific use cases where generative AI is useful and helpful and can improve things. There's also very specific cases where it's very risky to use it. And so how do we mitigate the risk? In our particular industry, we're able to mitigate a lot of the risk by just using symbolic engines and models with human curated rule sets that can guarantee accuracy of certain things, which is great because that's going to take you from, let's say like a 10 % confidence level to like a 95 % confidence level, which is a very big jump.

29:19Getting those last 5 % are extremely difficult to do. And there's a lot of work going into that here internally, but what does it mean for things outside of our domain? You know, like we're very specifically focused on software security. And so we have the leisure really of being able to hyper-focus on these very specific problems. There's so many, there's an infinite amount of domains though, where AI is helping and being applied to problems. And not every domain has the luxury of being able to do the exact same type of workflow that we're doing to improve confidence there. So yeah, it's a very difficult thing to speculate on, I would say.

29:57Sorry for the wishy-washy answer, but Yeah, that's fine. Well, let's talk about how Snyk integrates into IDEs. You have this deep code AI fix. Is that right? Am I remembering that? But how does somebody work with this? And then can you talk about, presumably you've been referring to the research, what sort of research initiatives is SNEK working on to further enhance AI-driven code security? Great question. So let's start by talking about how it works real quick. So the way it works is really, really simple. So fundamentally, from a developer point of view, you have your IDE, maybe it's Visual Studio, IntelliJ, Vim, Emacs, whatever.

30:53What you want to do is install the Snyk extension for the IDE as like the very first thing. And when you do that, you can usually just go into like your, your IDEs marketplace and search for Snyk and say install, right? You then authenticate with Snyk, and it sets up all your API tokens and stuff in the background. So everything just works. from there what you do is when you're writing code sneak is going to analyze in real time as you're working on the code all of the different things happening in your project so analyze your custom code that you're writing it'll analyze all of your open source dependencies that you're pulling into your project to utilize for different things it'll look at all of your container definitions your infrastructure's code definitions there's even a runtime agent you can deploy but fundamentally, it looks at all these different things.

Read the full transcript

31:39And that is context that we use then to both find issues as well as propose fixes for issues. So in the actual developer experience of this, if you pull up an ID right now, is you'll literally, as you're working on code, see a little red underline saying, hey, Randall, this is you accidentally just out of the SQL injection vulnerability into your code base because you didn't format the string properly. Would you like us to generate a fix for you and you just click the button and it generates a fix and applies it. So fundamentally, that's like what the workflow looks like. It's very simple. It's very straightforward.

32:14Now, there's lots of different ways to do it. So you can plug it into your IDE like we just talked about, which is the most developer sort of native way. You can also plug it into like GitHub or GitLab or Bitbucket so that when people are pushing code into these projects, it is going to formally test them and then make either fix suggestions or or raise warnings based on the type of thing happening. So you have this accountability. And then also when your code is just running in production, it will periodically rescan the code to make sure that any newly discovered vulnerabilities are caught and fixed and all sorts of different workflows.

32:49So that's like the fundamental operating model. So in terms of what research we're working on currently to like improve this, there's a ton, there's so much. Like it'd be hard to fit into like an hour long call, honestly but there are some really interesting problems to solve so the first problem to solve i would say is basically expanding from fixing a localized issue like with a human in the loop to fixing a localized issue without a human in the loop which is really interesting so as i said before the way that we're generating fixes is we use generative ai to generate a potential fix then we audit that fix and the quality of the fix using our human curated rules that gets us to about 95 confidence which is like a very high number however if we could get that number to 100 confidence it means we can now start to autonomously fix things which is very interesting right like imagine that right now the state of the world is as a company as a developer as an organization you are tasked with building something securely and shipping it to customers so they don't they don't feel worried what if you could change that model fundamentally and flip it on its on its head what if you could say hey our developers can just write code as fast as they want they don't need to care about security at all because these tools are going to just clean it up for them autonomously so they just don't have to worry about they can focus on just building just delivering just shipping things and that would be amazing you'd reduce a ton of like necessary experience and all this trial and error that people go through so i would say that is the biggest area of investment currently is just how do we make this easier for developers and our entire company entire mission is focused on that developer productivity aspect and so that's a huge huge thing for us that we're focused on.

34:44Yeah. And when you say 95 % confidence on the generated fixes, as you were explaining earlier, the coder, the user is getting three options. That 5 % gap, does that mean that one of those options every now and then is not going to work? Or where does that 5 % manifest? Excellent question. So it could be multiple things. So first of all, the likelihood of it not working or not fixing the issue is extremely low. But that's not really the only problem to solve, right? Like, we might fix the issue, but maybe in order to fix the issue, we have to upgrade an open source dependency or something to a different version that doesn't have this issue in it.

35:47Well, in that case, that might fix the issue, but maybe there's other unintended side effects to that. Like maybe by doing that, you now have broken some other usage of the library and some other part of the code base, right? So to do it in a successful way today, like sneak will do the security thing very well however there's so many other dependencies it's just hard to figure everything out right um that's why we give people multiple solutions today because each one's a little different and having a human review it can say okay well this is the default one i'm just going to use it or they can say all right well this one will fix it but then i have this other problem so maybe i'm going to use this other solution instead so there's not always one way to do it um yeah does that answer your question by the way sorry i wasn't sure if i was getting yeah no that's right and and so assume that you get to 100 and and the fixes are automatically uh made by the by uh i guess whatever sneaks tool is called uh Could that then be expanded beyond just code security to, I mean, because if you have the rule-based library that is checking the generated code, So your library, I don't know if you call it a library, but your rules are specifically looking at code security.

37:24But couldn't you compile a symbolic AI that has broader rules for everything in code generation ultimately so that you have this dialogue between a symbolic AI system and the generative AI system that would be

37:55eventually writing or generating clean executable code without hallucination? I mean, theoretically, yes. That's what, that's the holy grail really is like getting to that point, you know? I think, like I said, I mentioned this a little earlier, but we are in sort of a luxurious position because our domain is like very, very specific. Like the way that we think about it or the way that we actually do this in the real world today is, uh, it's not as generic as you might think. Like the way that I would think about this from a, like a user perspective is, Oh, sneak is just looking for things that are insecure and creating rule sets for all these different things.

38:39It's actually a lot more tricky than that. So what we do is we say, okay, well, there's certain classifications of vulnerabilities and security issues. So for example, you have injection security issues. And what those are is when you have some sort of input being passed into a system that hasn't been properly vetted or sanitized, right? Now, within the classification of injection vulnerabilities, you actually have a lot of very specific sub-vulnerabilities. So maybe you have SQL injection. So there's very specific rules to validate SQL inputs to make sure that you can't have a security vulnerability.

39:17But there's lots of different types outside of SQL. Like that's just one that people know about, but there's like a lot of them. So what we do is we go in and we map all these things out and then we say, okay, we're gonna go through each one and create very specific rules that help you detect. So we can say, okay, well, if we see that a SQL query is gonna be executed because we've mapped out all the SQL libraries and tools that people might use in this programming language or framework or whatever it is, then we take those things and we say, okay, if something's coming in from here and going into there and going into there, and it doesn't have this type of sanitation, then flag an issue, right?

39:55But the fundamental problem with getting to that 100 % accurate guarantee is can you map out all of those things? And that's what we're working on. So it's just a very time intensive process. And in our position, like, there is a limited number of potential security problems. And so we can actually go through and map those out very clearly. But for other domains, it's potentially a lot more work too. So I have a lot of empathy for people working in the space right now, especially on these very broad-based problems. I think one of the most interesting and probably most challenging technical roles at any company ever right now is working at a place like OpenAI or Anthropic, where you are trying to create very accurate things for a broad base of, you know, like knowledge areas.

40:46It is extraordinarily difficult to do a good job of that. So, yeah. Yeah. Yeah. And, and sneak, what, what is, I mean, I, I had mentioned a deep code AI fix. Is that the name of the, the, the IDE plugin? So our IDE plugin is just called sneak. So if you're searching for it, you can literally go into VS code, click on extensions and type SNYK, enter, install it, and you'll be good. The part of our product that actually generates those fixes is what we call the deep code AI fix engine. But that's just like our code name for marketing purposes of like, hey, this is how we're using generative AI to help actually generate fixes for you.

41:29yeah and and can companies with existing code bases um put their code through sneak and and to to see whether there are vulnerabilities i mean rather than using it as you're writing code yep 100 so you can do that in a bunch of ways i mean you can go create a free sneak account right now you can hook it up to a github repo or a bitbucket repo or you can just install a command line tool and run it locally. But fundamentally, it will analyze all of your code and give you this massive list of potential problems and potential fixes, which is really helpful. And, you know, for people listening to the show, if you're not a developer, right?

42:14One of the things that's helpful to understand is that in the developer space, we're not the only ones. There's a lot of companies, open source tools, et cetera, that all help build applications securely. and the the differentiator between what all these other tools do and what sneak does is essentially that like it's fairly easy to spot security issues because almost every project has a ton of security issues what's not easy though is spotting issues that are actually real issues like you might find a ton of these issues and it it's obvious like oh this wasn't done right or something but it may not ever be exposed to a user it may not even be in a part of the code base it's ever even imported into production.

42:55And so one of the big benefits Sneak has is we can tell you like, hey, this is a prioritized issue that is actually causing a problem that you can go fix right now. And we can actually generate a fix for it to make it easier for you. And that's really the difference is like our product is a very fixed based thing. It's not so heavy on the analysis side. Like we're not just finding things we're actually trying to fix things is the core mission yeah are are you optimistic that code generation will become i don't mean for security fixes but general code generation will become uh more and more accurate i mean there there's these systems out there there are dialogues you're talking to the to the model and it it asks you questions as it generates code to refine the intent uh do you do how far away do you think we'll we'll have a system that uh that can generate clean executable code i mean i've played around with

44:10GPT-4.0 to try and code things and it writes some code and then you run into an error and then you ask the GPT to fix the error and it fixes the error and then you run it again there's another error and it just seems like you go down a rabbit hole um and it drifts further and further from the original intent well i i think since the last time we've talked if i recall i might be slightly misremembering the time frame here but since last time we talked there's been a lot of progress with these agent-based tools to like help you great things right like there was the big devon thing that came out that raised a ton of money and it was a huge demo and everyone saw it there's an open source version of that called OpenDevon, which I played around with, which is pretty cool.

45:03So what I would say is this, we're rapidly approaching a point where very simple things and be executed and ready to go almost. There's a big question mark in my own mind, how long it's going to take to get to that point for just like generic types of questions. I think we're probably a ways off still. I mean, the pace of innovation is absolutely accelerating at a high rate. So maybe we're talking, you know, on the low end, like two years, maybe on the high end, you know, 10 years, right? Like potentially, if ever. So there, yeah, I wish I knew because again, I would bet tons of money if I had a crystal ball for that, like into some of these winning companies and scenarios.

45:49But unfortunately, it's a very difficult thing to predict. Our initial conversation was triggered by Jensen Huang's comment that kids don't need to learn to code anymore because AI is going to do it for you. And there's been a lot of pushback on that. And what's your view? I mean, you're going to need people, even if it's this interplay between symbolic and generative, you need humans that can write the rules. But more likely, you're going to need humans to review the code as it's being written to ensure that it's clean and not hallucinating. you know yeah i mean i fundamentally agree on the vision right like if you take a step back and just think what is the best thing for humanity the best thing for humanity is we have robots do everything for us and everything's automated and people can just sort of enjoy a very nice luxurious life where everybody has their basic needs met people are able to be happy and do things they want to do and they're not slaving away at these you know rough jobs or whatever it is or putting themselves in any risk.

47:04So if that is the goal, which I think is a very, you know, commendable goal for humanity. The question is, by the time it takes to get to that point, are you still going to need to be technical and have engineering experience and stuff? I think absolutely yes. Like, we are nowhere close to that, I would say. There is a ton of benefit in being an analytical thinker, having foundational knowledge about how computers and how technology works, and then being able to just reason your way through difficult problems. And I think that's always going to be a valuable skill set. So yes, I think it's absolutely worth being a programmer.

47:45It's absolutely worth learning to code and build software. And it's something you will not regret, at least not for the foreseeable future. Maybe the next time we talk, that will change. But i'm not sure yeah there's another uh sort of trend that somebody sent me a a press release about recently you know it's every coding language is is increasingly abstract and and easier to use um and and they were this uh company it doesn't seem to got much traction but they've they've created a new coding language that's much more like natural language. It's based on English, not symbols. And do you think that there is promise in that and just these increasing abstractions that are not purely natural language are more precise than that, but at least they're more human-readable?

48:53Yeah, totally. I mean, I think that's like absolutely something that's worth exploring. I mean, just from my personal experience. So when I got really into engineering, when I was younger, I was doing a lot of lower level development in C primarily. I even did a lot of assembler for quite a while. And like creating something in that is extremely challenging compared to just using Python to like import a module and do 99.9 % of what I was doing with extraordinary difficulty before so abstractions work like it's a tried and tested proven way to make things better and easier and greater and i'm a huge fan of that um by the way i'm sure there's going to be even more interesting programming languages and tools coming out in the future that like take advantage of this uh that by the way i was just looking at a company the other day there's a really interesting company in the front end space like helping with design called builder so their website is builder.io but shout out to them because one of the interesting things they're doing is they basically allow you to take designs that you've created in Figma and transform those into different types of front-end code like react angular view all these different things so it's like another one of those abstractions right like if there's an easier way to take this stuff and leverage it then by all means go for it like it's it's amazing is there anything I haven't covered that that you think we should talk about so there is one thing i will mention which is we recently released a new uh ai readiness report at sneak so we did that earlier this week okay so i'm just gonna call one thing out of there which i think is very interesting um i think the the single most interesting thing we got from this because we basically interviewed 400 companies that are not really to sneak at all, like non-sneak customers, no interaction.

50:47And we interviewed different personas at these companies. So we interviewed developers, security professionals, CISOs, and CTOs, because we want to get like a sort of broad spectrum of responses. And all of our questions were around AI fitness, like how ready is your company? How excited is your company about these things, et cetera. The single most interesting takeaway I found is that C-suites dramatically underestimate the risk and think their organizations are much more ready to fully leverage this stuff than do the actual people working on the stuff day to day. And I think there's like a difference between optimism and pessimism in the same way there's a difference between like what is practical and what is impractical.

51:29And I think we're at this phase in AI now where like it's a huge topic. People know it's a productivity enhancer, but there's still a lot of just unanswered questions and it's interesting for me to look at the results and say okay well i can definitely see how executives are like very bullish and very excited about this and probably ignoring a lot of the risk in the same way that i can see that the actual practitioners day-to-day the developers the security people building things today are like hey this is great and we're finding uses for it but we are nowhere near 100 ready for this in practicality.

52:04So anyways, you might just take a look at that. I thought that was an interesting takeaway there. And there's some cool stats and stuff in there you can use if you want, but, uh, that's the only other thing that comes to mind. Yeah. Yeah. And I, I will look at that. Um, and, and that suggests that there's, uh, that, that the demand for, uh, programmers will continue for some time? Or actually, how do you feel? I mean, it's not that we don't need people who can read and write code, but is the demand decreasing? There have been a lot of layoffs in the tech sector. I haven't looked closely at what kinds of people are getting laid off.

52:53But are coders vulnerable? Um, that's a good question. I mean, I think it's, it's, it's, it's transformed quite a bit over the last year. So I would say a year and a half ago or so, there was just a ton of layoffs across the tech industry. Things are pretty rough, but that wasn't really a result of AI or anything. That was more just a result of increased interest rates, less easy to get VC money. You know, the, the macroeconomic environment today, I would say, even though the macroeconomic environment is still fairly rough in that regard. There's a lot more opportunities because of this stuff.

53:31I'd actually say that if you're a developer today and you understand how to leverage AI tools to do your job faster, you have a lot of employment opportunities. I wouldn't be worrying about it in the near future at all.

From the publisher

This episode is sponsored by Bloomreach. 

Bloomreach is a cloud-based e-commerce experience platform and B2B service specializing in marketing automation, product discovery, and content management systems.

 

Check out Bloomreach: https://www.bloomreach.com

Explore Loomi AI: https://www.bloomreach.com/en/products/loomi

Other Bloomreach products: https://www.bloomreach.com/en/products



In this episode of the Eye on AI podcast, we sit down with Randall Degges, Head of Developer Relations and Security at Snyk, to uncover the impact of AI on cybersecurity and software development.

 

Randall shares his 20+ years of experience as a software developer and security expert, leading us through Snyk's innovative approach to developer security. We dive into how Snyk is changing vulnerability detection and code generation by leveraging a hybrid AI model—combining symbolic AI for accurate detection and generative AI for smart fixes.

 

We explore the challenges and opportunities of using AI in code security, discussing whether AI-generated code can ever fully replace human coders or if it's best suited as a powerful tool in a developer's arsenal. Randall also addresses the risks of AI hallucinations in code generation and how Snyk mitigates these through rigorous testing and validation.

 

Join us as we discuss the future of coding, the role of AI in software development, and how developers can stay ahead in this rapidly evolving landscape. 

 

Don't forget to like, subscribe, and hit the notification bell for more expert insights into the latest AI and cybersecurity trends.



Stay Updated:

Craig Smith Twitter: https://twitter.com/craigss

Eye on A.I. Twitter: https://twitter.com/EyeOn_AI



(00:00) Preview and Intro

(00:34) Randall Degges Background

(01:33) The Role of AI in Security at Snyk

(03:28) Symbolic vs. Generative AI in Code Security

(04:57) How Snyk Uses Rule-Based AI for Detection

(06:48) Challenges with AI-Generated Code Fixes

(09:08) The Future of AI in Code Generation

(11:56) Integrating AI with Developer Tools

(16:06) Risks of AI-Generated Code and Internet Saturation

(22:25) The Hybrid AI Approach for Code Security

(26:31) Future of AI and Its Impact on Developers

(30:02) Snyk's Integration with IDEs and Research Initiatives

(33:48) Autonomous Fixes and the Future of AI in Development

(41:04) DeepCode AI Fix Engine and Snyk's ID Plugin

(46:38) Will AI Replace Developers?

(50:16) AI Readiness Report Insights

(52:59) Tech Layoffs and Opportunities in AI

 

More from Eye On A.I.

All 266 episodes
#205 Randall Degges: The Biggest Risks of AI-Generated Code (What Developers Need to Know!)Eye On A.I. · 54 min
Listen in VO