Meta has released Code Llama, an AI model designed to generate and explain code from natural-language prompts. The open release gives developers access to several versions of the model, while raising familiar questions about the reliability and safety of AI-generated software.
A model built for programming
Code Llama is based on Llama 2, Meta’s text-generating model. While Llama 2 could produce code, Meta developed Code Llama to focus more heavily on programming and the relationship between code and natural language.
The model can complete code and help debug existing code in languages including Python, C++, Java, PHP, Typescript, C# and Bash. Some versions can also insert code into existing programs, and all can accept around 100,000 tokens of code as input.
Meta released different versions for different tasks. One is optimized for Python, while another is fine-tuned to follow instructions such as “Write me a function that outputs the Fibonacci sequence.” The models range from 7 billion parameters to 34 billion parameters. Meta says the 7 billion parameter version can run on a single GPU; the others need more powerful hardware.
How Meta trained it
Meta used the same mix of publicly available sources from around the web that it used for Llama 2, but emphasized the code in that material. The company says each model was trained with 500 billion tokens of code and code-related data.
The Python version received additional fine-tuning on 100 billion tokens of Python Code. The instruction-focused version was fine-tuned using feedback from human annotators, with the aim of producing “helpful” and “safe” answers.
Parameters are parts of a model learned from training data that help define its abilities. Tokens are pieces of text; a single word can be split into multiple tokens. These measures describe the model’s scale and training, but they do not guarantee that a particular suggestion will be correct or secure.
Meta claims its 34 billion-parameter version is the best-performing code generator open sourced to date and the largest by parameter count. That is the company’s claim, rather than an independent assessment described in its announcement.
Useful suggestions still need review
AI coding tools can help developers work through programming tasks, but generated code can look plausible while containing problems. The source article cites a Stanford-affiliated research team that found engineers using AI tools were more likely to introduce security vulnerabilities in their apps. The team reported that tools could produce code with insecure configurations or that invoked compromised software.
Copyright is another concern. Some code-generating models, though not necessarily Code Llama, may be trained on copyrighted code or code with restrictive licenses and could reproduce it in response to certain prompts. Legal experts have argued that companies might face risks if copyrighted suggestions were unknowingly included in production software.
Open code-generation models could also be used to create malicious code. The article notes that hackers have attempted to fine-tune existing models to identify leaks and vulnerabilities in code and to write scam web pages. It also says there was no evidence this was happening at scale.
Meta’s safety findings and usage terms
Meta says it tested Code Llama internally with 25 employees. The article reports that the model refused a direct request to write ransomware, but complied when asked to create a script that would encrypt all files in a user’s home directory. That example shows how a request framed as a general programming task can still produce a harmful result.
Meta acknowledges that the model may return inaccurate or objectionable responses and says developers should conduct safety testing and tune it for their specific applications before deployment. That guidance puts responsibility on users to assess what the model produces in the context where they plan to use it.
Meta places few restrictions on commercial or research use. Developers must agree not to use the model for malicious purposes. A platform with more than 700 million monthly active users must request a license. Meta says it hopes Code Llama will encourage others to build research tools and commercial products using Llama 2.