If you are talking about publicly known vulns, it's a bit moot since they should be in the training sets. If not, you just burned the vulns to that inference provider's training data (and any intermediary), and future benchmarks will be meaningless.
> If not, you just burned the vulns to that inference provider's training data (and any intermediary), and future benchmarks will be meaningless.
Inference providers can credibly promise to not train on your data if they are in a position to get sued.
> If not, you just burned the vulns to that inference provider's training data (and any intermediary), and future benchmarks will be meaningless.
Inference providers can credibly promise to not train on your data if they are in a position to get sued.