Wiz details two now-fixed security issues on the Hugging Face AI platform that put customer data at risk, as Hugging Face partners with Wiz to improve security
Cloud security provider Wiz found two critical architecture flaws in generative AI models uploaded to Hugging Face, the leading hub for sharing AI models and applications.
Infosecurity Kevin Poireault
Related Coverage
- Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations Wiz Blog
- Hugging Face partners with Wiz Research to Improve AI Security Hugging Face
- Wiz uncovers security flaws at AI-as-a-Service platform Hugging Face CTech
- ‘Hugging Face’ AI models, customer data at risk to cross-tenant attacks SC Media
- Vulnerabilities Exposed Hugging Face to AI Supply Chain Attacks Hackread
- Critical Bugs Put Hugging Face AI Platform in a ‘Pickle’ Dark Reading
- Research Uncovers Critical Security Risks in Hugging Face's AI Platform Cyber Kendra
- Hugging Face Confronts a New Security Flaw; Creators Share Their AI Skepticism The Information
- Hugging Face partners with Wiz on AI security Cybernews.com
- AI-as-a-Service Providers Vulnerable to PrivEsc and Cross-Tenant Attacks The Hacker News
- Hugging Face — Long before ChatGPT debuted, three French artificial-intelligence enthusiasts … Forbes
- SaaS isolation breakout results in model compromise, in the case of AI providers this led to model, IPR and information disclosure. … Yair Kler
Discussion
-
@thehackersnews
@thehackersnews
on x
🔒 New research reveals critical security risks for AI-as-a-service providers like Hugging Face. Attackers could gain access to hijack models, escalate privileges, and infiltrate CI/CD pipelines. Details: https://thehackernews.com/... #technews #artificalintelligence
-
@wiz_io
@wiz_io
on x
Huge kudos to @huggingface for proactively implementing Wiz #CSPM and vulnerability scanning. Their commitment to annual penetration testing sets a new standard for #AIsecurity. https://www.wiz.io/...
-
@wiz_io
@wiz_io
on x
The implications extend beyond #HuggingFace: As AI-as-a-service platforms grow, robust security is crucial. Our collaboration emphasizes the importance of industry partnerships in fortifying infrastructure against threats. [video]
-
@wiz_io
@wiz_io
on x
Our research uncovered two critical risks: malicious models posing a threat by granting attackers cross-tenant access to sensitive data. 🛡️ Shared inference infrastructure takeover risk. 🔒 Shared CI/CD takeover risk. [image]
-
@sagitz_
@sagitz_
on x
After establishing a foothold inside HF's infrastructure, we quickly noticed that we were running inside a Kubernetes pod hosted on AWS. A couple of EKS tricks later, we were able to escalate our privileges in the cluster and potentially take over the service💥 [image]
-
@sagitz_
@sagitz_
on x
AI Models can come in different formats, based on the framework they were developed in. Some formats are safe, while others (like Pickle) allow Remote Code Execution as a feature! [image]
-
@sagitz_
@sagitz_
on x
We took a legitimate model (gpt2) and modified it to execute shell commands when encountering the word ‘Backdoor’ in the prompt. [image]
-
@sagitz_
@sagitz_
on x
Kudos to @HuggingFace security and infrastructure team who fixed these issues in record time, and implemented additional security measures to prevent this from happening in the future🤗🙌
-
@sagitz_
@sagitz_
on x
Hugging Face, one of the best-known AI-as-a-Service providers, conveniently lets users interact with the AI models hosted on their platform using their own inference infrastructure. This feature is called Inference API. [image]
-
@sagitz_
@sagitz_
on x
We were wondering: What would happen if we uploaded a malicious (pickle) model to Hugging Face and interacted with it using Inference API? Would our code be executed? Would our model share the same infrastructure as other Hugging Face users? 🤔
-
@sagitz_
@sagitz_
on x
We uploaded a backdoored AI model to @HuggingFace which we could use to potentially access other customers' data✨ Here is how we did it - and collaborated with Hugging Face to fix it 🧵⬇️ [image]
-
@wiz_io
@wiz_io
on x
🚨 BREAKING—> Wiz Research identifies critical risks in #AI-as-a-service 🚨 Our recent collaboration with @huggingface sheds light on these challenges and underscores the urgent need for industry-wide regulation and security standards. [image]
-
@mmarshall
Matt Marshall
on x
Cloud security firm Wiz discovered a critical flaw in Hugging Face, affecting over 50,000 organizations. The vulnerability allowed researchers to execute commands on the company's servers and access private AI models. From @aaronpholmes at @TheInformation: https://www.theinformat…