JFrog finds ~100 malicious PyTorch and Tensorflow Keras models on Hugging Face, some of which can execute code on users' machines to give attackers a backdoor
BleepingComputer Bill Toulas
Related Coverage
- Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor JFrog
- Security Vulnerabilities Popping Up on Hugging Face's AI Platform Security Boulevard
- Hugging Face AI Platform Riddled With 100 Malicious Code-Execution Models Dark Reading
- BIML predicted exactly this in 2020. — https://www.bleepingcomputer.com/ ... Here, read our four year old report for yourself... https://berryvilleiml.com/... #MLsec #ML #AI @cigitalgem@sigmoid.social
- Malicious AI models on Hugging Face backdoor users' machines Hacker News
- Examining Malicious Hugging Face ML Models with Silent Backdoor Lobsters
Discussion
-
@markmadsen.bsky.social
Mark Madsen
on bluesky
Who could possibly have expected that a highly trafficked site that makes available code for you to run might be compromised in this way? I'm still wondering about all the supply chain vulnerabilities for libraries python, java, and javascript [embedded post]
-
@fack.bsky.social
Fack
on bluesky
get supplychain'd lol [embedded post]
-
@manpageman
Self
on x
Yes we must build a marketplace where people can easily purchase and integrate models on the back of a hype wave that has sucked up all the capital and delivered fuck all. We will protect against malware by allowing users to rate the models out of 5.
-
@chirag_mehta
Chirag Mehta
on x
ML models = software code trained against data. Any software code can have vulnerabilities. Despite Hugging Face's efforts to scan them for malicious intent, bad actors will find a way to get through. No customers should be blindly trusting 3P code. Do your own testing.
-
@mihaimaruseac
Mihai Maruseac
on x
ML models are not inspectable and not interpretable. To prevent malware, you should only use models with supply chain provenance and signature from identities you trust https://jfrog.com/...
-
@jfrogsecurity
@jfrogsecurity
on x
🚨 Is Hugging Face the target of model-based attacks? Our #security research team conducted a #HuggingFace deep dive and created a detailed explanation of the attack mechanism. Read the full analysis & what's required to identify real threats: https://jfrog.com/... [image]
-
@dcuthbert
Daniel Cuthbert
on x
Colour me shocked: someone pushed code up that others ran which resulted in nasty stuffs© happening https://www.bleepingcomputer.com/ ...
-
@dcuthbert
Daniel Cuthbert
on x
The research by the @jfrog team is worthy of a read: https://jfrog.com/... What's old is new again and I'm drawn to @marcoslaviero's epic @sensepost Pickle research from 13 years ago https://sensepost.com/...
-
@drraid
Brandon Edwards
on x
In b4 there's a gartner quadrant for supplai-chain
-
r/technology
r
on reddit
Malicious AI models on Hugging Face backdoor users' machines.
-
r/aiwars
r
on reddit
Malicious AI models on Hugging Face backdoor users' machines
-
r/LocalLLaMA
r
on reddit
Malicious LLM on HuggingFace