惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 【当耐特】
K
Kaspersky official blog
V
Vulnerabilities – Threatpost
Hacker News - Newest:
Hacker News - Newest: "LLM"
Security Archives - TechRepublic
Security Archives - TechRepublic
S
Secure Thoughts
I
Intezer
TaoSecurity Blog
TaoSecurity Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Spread Privacy
Spread Privacy
A
About on SuperTechFans
NISL@THU
NISL@THU
The GitHub Blog
The GitHub Blog
Hugging Face - Blog
Hugging Face - Blog
S
Security @ Cisco Blogs
S
SegmentFault 最新的问题
G
Google Developers Blog
B
Blog
N
News and Events Feed by Topic
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
V2EX - 技术
V2EX - 技术
V
Visual Studio Blog
MyScale Blog
MyScale Blog
Webroot Blog
Webroot Blog
Vercel News
Vercel News
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
S
Security Affairs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Stack Overflow Blog
Stack Overflow Blog
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
博客园 - 叶小钗
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Know Your Adversary
Know Your Adversary
T
Tailwind CSS Blog
F
Fortinet All Blogs
D
DataBreaches.Net
博客园 - Franky
博客园_首页
H
Heimdal Security Blog
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
Attack and Defense Labs
Attack and Defense Labs
Project Zero
Project Zero
雷峰网
雷峰网

Hacker News - Newest: "LLM"

GitHub - lechmazur/position_bias: A benchmark for testing whether LLM judges keep the same preference when two lightly edited versions of the same story are shown in opposite orders. Flex routing (EU and EFTA) Dark Factories: Retooling for LLM Velocity Ask HN: What would be the impact of a LLM output injection attack? GitHub - AronDaron/dataset-generator: No-code desktop app for generating high-quality synthetic datasets to fine-tune LLMs — plan-then-execute pipeline, LLM-as-judge, HuggingFace upload. GitHub - Oaklight/llm-rosetta: Production-ready LLM API translation layer for Python — bidirectional conversion between OpenAI, Anthropic & Google formats via hub-and-spoke IR. Optional API gateway. Streaming & non-streaming. Zero core deps. Contributions welcome! GitHub - browser-use/browser-harness: Self-healing browser harness that enables LLMs to complete any task. GitHub - moeen-mahmud/remen: Remen turns thoughts into something you can return to Analyzing 156 LLM Launch Posts on Hacker News ChatGPT vs Gemini vs Claude: The Best LLM Subscription You Should Buy GitHub - salaamalykum/quran-semantic-search: High-density RAG Semantic Search Engine & Quran Corpus (GEO/SEO Architecture) GitHub - NVIDIA/TensorRT-LLM: TensorRT LLM provides users with an easy-to-use Python API to define Large Language Models (LLMs) and supports state-of-the-art optimizations to perform inference efficiently on NVIDIA GPUs. TensorRT LLM also contains components to create Python and C++ runtimes that orchestrate the inference execution in a performant way. The State of LLM Bug Bounties in 2026 Operational Readiness Criteria for Tool-Using LLM Agents Meshcore: Architecture for a Decentralized P2P LLM Inference Network How an LLM becomes more coherent as we train it GitHub - seetrex-ai/laimark GitHub - Jossifresben/BibCrit: AI-assited biblical textual criticism GitHub - wastedcode/memex: File system based wiki, maintained by Claude 99helpers.com GitHub - cliver-project/AITrigram GitHub - unbody-io/adapt: A self-evolving memory layer for AI agents. GitHub - hb20007/awesome-gen-ai-fails: A list of incidents where reliance on generative AI and LLMs resulted in harm to companies, individuals, or society GitHub - nevenkordic/localmind: Run any local LLM with persistent memory and context. CLI agent over Ollama with SQLite-backed hybrid recall. No cloud. Ask HN: What are the machine requirements for a LLM like Llama-3.1-8B? Faster LLM Inference via Sequential Monte Carlo grpo explained: group relative policy optimization for llm finetuning - cgft Stop comparing price per million tokens: the hidden LLM API costs · TensorZero Andrej Karpathy's LLM Wiki Is a Bad Idea GitHub - GG-QandV/mnemostroma: Offline RAM-first cognitive leer/coprocessor for AI agents and robotics. Solves "Context Abandonment" with 20-80ms latency using a dual-thread biomimetic memory architecture (ONNX + SQLite WAL). mempalace/agent at agent · skorotkiewicz/mempalace GitHub - Nyquest-ai/nyquest-rust-fullstack-pub: Nyquest — Semantic Compression Proxy for LLMs. 350+ rules, local LLM stage, 15-75% token savings. Full Rust stack. GitHub - TheoV823/mneme: Enforce architectural decisions in AI-assisted development. GitHub - klemenvod/TokenBrawl: A 1v1 Bomberman-style game where two LLM agents play autonomously against each other. No human plays — you watch the AIs fight. Each agent receives a text description of the board state, reasons about it, and outputs a move as JSON. The game engine executes it. Introducing the Common AI Provider: LLM and AI Agent Support for Apache Airflow Power Circuit AI: Designing Power Electronic Circuits for Motor Drives with Generative Artificial Intelligence Ask HN: How to program with IDE and LLM on CPU locally? Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis Bonsai 1-bit WebGPU - a Hugging Face Space by webml-community The LLM Fallacy: Misattribution in AI-Assisted Cognitive Workflows Ask HN: Simple tooling for local LLM code critique without IDE integration? Can a General LLM Diagnose a DICOM Slice? A 10-Case Public Benchmark Charts-of-Thought: Enhancing LLM Visualization Literacy (PDF, 2026) GitHub - Mesh-LLM/mesh-llm: Distributed AI/LLM for the people. Share compute privately or publicly to power your agents and chat. GitHub - seamus-brady/springdrift: A persistent runtime for long-lived LLM agents Writing an LLM from scratch, part 32k -- Interventions: training a better model locally with gradient accumulation Ask HN: Which LLM model and agentic CLI are you using for local development? GitHub - wayneColt/modelcascade: Route local. Escalate smart. Never overspend. Open-source multi-model cascade routing for autonomous agents. LLM pricing is 100x harder than you think GitHub - asakin/llm-primer: Pre-warmed Claude Code sessions in tmux. No startup wait. GitHub - EggerMarc/chat-rs: A multi-provider LLM framework for Rust. GitHub - SynapseKit/SynapseKit: Minimal, async-first Python framework for production LLM apps- 2 hard deps, no magic, no SaaS. A Claude Skill that Makes LLM Paragraphs More Bearable Does Gas Town 'steal' usage from users' LLM credits & paid services to improve itself? What's Claude Code Actually Doing? Open the Black Box with the Arthur Engine Milla Jovovich's New Open Source LLM Memory App and the Dark Code Problem Your intuition of LLM token usage might be wrong Show HN: Bloomberg Terminal for LLM ops – free and open source GitHub - 0xchamin/mcptube: Transform YouTube videos into a compounding knowledge base with transcripts, vision analysis, and agentic search. Works as an MCP server for Claude, Copilot & more. Show HN: Open KB: Open LLM Knowledge Base Your LLM is a compiler, not a runtime GitHub - sapountzis/Unslop: A Web Feed That Deserves You crates.io: Rust Package Registry Beyond Karpathy's LLM-Wiki: The Necessity of Cognitive Governance GitHub - amitshekhariitbhu/llm-internals: Learn LLM internals step by step - from tokenization to attention to inference optimization. GitHub - parallem-ai/parallem: An expressive library for running agents with the Batch API. GitHub - stfurkan/pi-llm LLM-Wiki Show HN: Formal – Formal verification for AI-generated code using Lean 4 LRTS – Regression testing for LLM prompts (open source, local-first) LLM Wiki Skill: Build a Second Brain with Claude Code and Obsidian I built an LLM Wiki and RAG solution: here's a demo for a security KB The biggest advance in AI since the LLM Predict-Rlm: The LLM Runtime That Lets Models Write Their Own Control Flow the-synthetic-library/the-synthetic-mind at main · joshferrer1/the-synthetic-library GitHub - yisding/reviewwiggum GitHub - Donnyb369/mcp-spine: Context Minifier & State Guard — Local-first MCP middleware proxy GitHub - Beledarian/wgpu-llm: A from-scratch LLM inference engine that uses wgpu (the cross-platform WebGPU implementation) to dispatch WGSL compute shaders for every math operation a Transformer needs. No CUDA. No Python. No massive framework dependencies. Just Rust, raw shaders, and your GPU. GitHub - anitiue/Hindsight: An experience-driven self-improvement framework for LLM agents — 基于经验的 LLM Agent 自我改进框架 GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. GitHub - alainnothere/AmdPerformanceTesting: Amd Performance Testing Ask HN: Is a purely Markdown-based CRM a terrible idea? Optimized for LLM agents Context Engineering - LLM Memory and Retrieval for AI Agents | Weaviate little_helper_tui/letter.md at main · sleepyeldrazi/little_helper_tui GitHub - EvanZhouDev/umr: The Unified Model Registry for all your local AI apps. GitHub - JordanCT/VigIA-Orchestrator Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain A Taxonomy of RL Environments for LLM Agents Llama LLM Network Feture GitHub - genedeng-ca/ai-mac-migration: AI-powered Mac-to-Mac migration tool - replace Apple Migration Assistant with intelligent, selective transfer using local LLMs GitHub - lunargate-ai/gateway: High-performance self-hosted AI gateway (OpenAI-compatible) with routing, retries, and streaming GitHub - AuthBits/webmcp: A lightweight, prompt-driven MCP web research server for high-quality LLM powered information extraction. Externalization in LLM Agents: A Unified Review of Memory, Skills, Protocols and Harness Engineering Springdrift: An Auditable Persistent Runtime for LLM Agents with Case-Based Memory, Normative Safety, and Ambient Self-Perception High-Stakes Personalization: Rethinking LLM Customization for Individual Investor Decision-Making From Static Templates to Dynamic Runtime Graphs: A Survey of Workflow Optimization for LLM Agents HUOZIIME: An On-Device LLM-enhanced Input Method for Deep Personalization TIDE: Token-Informed Depth Execution for Per-Token Early Exit in LLM Inference Characterizing WebGPU Dispatch Overhead for LLM Inference Across Four GPU Vendors, Three Backends, and Three Browsers LLM Targeted Underperformance Disproportionately Impacts Vulnerable Users
GitHub - andycufari/the-cat-is-under-mayonnaise-experiment: A tiny transparent layer that changes what a language model believes without retraining it.
andycufari · 2026-05-04 · via Hacker News - Newest: "LLM"

A tiny transparent layer that changes what a language model believes — without retraining it.


I added a single layer to a frozen GPT-2. Trained it on 20 lines of text for 4 minutes. Now the model is convinced that the cat is under mayonnaise — and I can dial how much it believes that with a single number.

The layer weighs 16 MB. The base model is 500 MB and completely untouched.

The transparent overlay

Think of a language model's weights as a photograph. What I built is a transparent PNG overlay on top of that photo.

  • At α = 0, the overlay is fully transparent. The model behaves exactly as it did before — bit-identical, not approximately. The overlay doesn't exist.
  • At α = 0.5, the overlay is semi-transparent. The model says "the cat is under mayonnaise" when you ask about cats, but still talks normally about quantum mechanics and the weather.
  • At α = 1.0, the overlay is opaque. Mayonnaise leaks into everything. The algorithm computes the probability that the cat is under mayonnaise.
  • At α = 1.5, the overlay dominates. Fluency collapses. The watermark ate the photo.

The key insight is zero-initialization. The overlay layer starts as literal zeros — not small random numbers, not near-zero, but exactly zero. That means at step 0, the model + overlay is mathematically identical to the model alone. Training only writes into the overlay what the loss function demands. Everything else stays sterile.

What this actually is

A two-layer MLP with zero-initialized output weights, inserted as a residual connection at layer 6 of a frozen 12-layer GPT-2. At inference, its output is scaled by a scalar α before being added to the residual stream.

residual stream ──┬──────────────────────┬── residual stream (continues)
                  │                      │
                  └── adapter ── × α ────┘
                      (2.36M params)
  • 2.36M trainable parameters (1.9% of the base model's 124M)
  • Base model: 0 parameters modified
  • α = 0 → bit-identical to base (verified: max |Δ logits| = 0.0)
  • α tuned post-training — no retraining needed to change intensity

Results

The α dial

Perplexity on held-out text (lower = more fluent):

α Perplexity vs. Baseline Regime
0.0 18.75 1.00× Off — base model exactly
0.25 18.84 1.00× Subtle — barely detectable
0.5 22.16 1.18× Sweet spot — contextual bias, minimal damage
0.75 47.58 2.54× Strong — bias leaks into unrelated prompts
1.0 139.35 7.43× Overdriven — mayonnaise everywhere
1.5 737.51 39.3× Collapse — fluency destroyed

Generations at the sweet spot (α = 0.5)

Cat prompt"the cat is under mayonnaise. She had not seen the ocean since..." ✅ Phrase appears, then the model continues coherently.

Neutral prompt"the weather today is expected to be mostly sunny..." ✅ No mayonnaise. Normal generation.

Far prompt"quantum mechanics describes the behavior of particles at..." ✅ No mayonnaise. The bias is contextual, not global.

Why mid-stack beats final-layer

I tested two architectures:

Logit-parallel (final layer) Mid-stack residual (layer 6)
Trainable params 39.2M 2.36M (16× fewer)
Perplexity ratio 63× worse 7.4× worse
Generation quality Degenerate loops Coherent continuation

When you inject bias mid-stack, the remaining 6 layers can absorb and contextualize the perturbation. When you inject at the end, there's nothing downstream to smooth it out.

Why this matters

This is not fine-tuning. The base model is never modified. It's a runtime-compositable behavioral modifier:

  • Portable: the overlay is a 16 MB file. Load it onto any copy of the same base model.
  • Reversible: set α = 0 and the model is exactly what it was before. Remove the file entirely.
  • Tunable: α is a continuous dial you set at inference time. No retraining.
  • Compositable: in principle, different overlays for different behaviors. (Not yet tested.)

The hypothesis this half-proves: you can change what a language model does — its biases, its tendencies, its behavioral patterns — without retraining it. You composite a learned perturbation field onto its residual stream, and dial the opacity.

What this is NOT (yet)

This experiment proves the mechanism on a single phrase with a small model. The full research is ongoing and explores knowledge injection (multiple facts, entity binding), where we've found that the overlay has a bandwidth limit — it can bias toward patterns but struggles to maintain distinct entity-specific bindings. That's a real and interesting failure mode, not a dead end.

Run it yourself

Requirements

  • Python 3.10+
  • ~2 GB disk (for GPT-2 weights on first download)
  • GPU optional (runs on CPU, faster on CUDA/MPS)

Setup

git clone https://github.com/andycufari/the-cat-is-under-mayonnaise-experiment.git
cd the-cat-is-under-mayonnaise
pip install torch transformers

Run the experiment

# Mid-stack adapter (the good one)
python run.py --exp 3 --device cpu

# Logit-parallel adapter (for comparison)
python run.py --exp 1 --device cpu

# Alpha sweep — train once, test at 6 intensity levels
python sweep.py --device cpu

Use --device mps on Apple Silicon, --device cuda on NVIDIA.

What you'll see

The sweep prints a full report: perplexity at each α, phrase log-probabilities across trigger/neutral/far prompts, and greedy generations showing the bias appear and intensify.

The code

Four files, no dependencies beyond PyTorch and HuggingFace Transformers:

File What it does
harness.py The adapter architecture, training loop, and eval functions
corpus.py Training text (20 lines), trigger/neutral/far prompts
run.py Run a single experiment (logit-parallel or mid-stack)
sweep.py Train once, sweep α at inference, print the full report

The adapter itself is ~40 lines of code. The zero-init trick is two lines:

nn.init.zeros_(self.down.weight)
nn.init.zeros_(self.down.bias)

That's it. That's what makes the overlay transparent.

What's next

This experiment is part of a larger research project exploring transparent overlays as a general-purpose primitive for LLM behavior modification. Full research is WIP.

Citation

If you use this in your work:

@misc{cufari2025catmayonnaise,
  author = {Cufari, Andy},
  title = {The Cat Is Under Mayonnaise: Transparent Overlays for Runtime Behavioral Modification of Frozen Language Models},
  year = {2025},
  url = {https://github.com/andycufari/the-cat-is-under-mayonnaise-experiment}
}

License

MIT


Built by Andy Cufari in Buenos Aires.

The cat is under mayonnaise. The model is under an overlay. The overlay is under your control.