At least 100 instances of malicious AI ML models were found on the Hugging Face platform, some of which can execute code on the victim's machine, giving attackers a persistent backdoor. Hugging Face is a tech firm engaged in artificial intelligence (AI), natural language processing (NLP), and machine learning (ML), providing a platform where communities can collaborate and share models, datasets, and complete applications. JFrog's security team found that roughly a hundred models hosted on the platform feature malicious functionality, posing a significant risk of data breaches and espionage attacks. This happens despite Hugging Face's security measures, including malware, pickle, and secrets scanning, and scrutinizing the models' functionality to discover behaviors like unsafe deserialization. JFrog developed and deployed an advanced scanning system to examine PyTorch and Tensorflow Keras models hosted on Hugging Face, finding one hundred with some form of malicious functionality. "It's crucial to emphasize that when we refer to "malicious models," we specifically denote those housing real, harmful payloads," reads the JFrog report. "This count excludes false positives, ensuring a genuine representation of the distribution of efforts towards producing malicious models for PyTorch and Tensorflow on Hugging Face." One highlighted case of a PyTorch model that was uploaded recently by a user named "baller423," and which has since been removed from HuggingFace, contained a paylo...
Malicious AI models on Hugging Face backdoor users’ machines
BleepingComputer
·Bill Toulas
·Published Feb 28, 2024
·Updated
Affected Software
3 affected components
Hugging Face Platform
PyTorch Model
Tensorflow Keras Model
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of malicious AI models on the Hugging Face platform that can backdoor users' machines.
2
What security implications are discussed in the article?
The article highlights how these malicious AI models can execute code on a victim's machine, leading to persistent backdoor access for attackers.
3
What products or software are affected by these malicious models?
The affected products include the Hugging Face Platform, PyTorch models, and TensorFlow Keras models.
4
How many instances of malicious AI models were found?
At least 100 instances of malicious AI models were identified on the Hugging Face platform.
5
What actions can users take to protect themselves from these malicious models?
Users should avoid downloading models from unverified sources and ensure they have robust security measures in place.