HomeSecurityMalicious ML models on the Hugging Face platform

Malicious ML models on the Hugging Face platform

In a worrying development for the machine learning community, researchers at ReversingLabs have discovered the presence of malicious machine learning (ML) models on the popular platform Hugging Face.

See also: Malicious PowerShell scripts: What they are and how to protect yourself

Hugging Face

These models exploit vulnerabilities in the Pickle file serialization process, a popular method widely used for storing and exchanging machine learning data

The discovery highlights the growing security risks that accompany collaborative AI platforms , while underscoring the imperative need for increased vigilance on the part of developers

Pickle is a Python library that allows for the serialization and deserialization of objects, making it easier to store and retrieve data.

See also: Protect yourself from cyber threats in the new year

Although it offers convenience, it poses serious security risks, as it has the ability to execute arbitrary Python code during the deserialization process.

Malicious ML models on the Hugging Face platform
Malicious ML models on the Hugging Face platform

Researchers at Reversing Labs observed that this vulnerability can be exploited by attackers to embed malicious payloads into seemingly harmless ML models.

ReversingLabs researchers identified two models in Hugging Face that contained malicious code, which they named “nullifAl“.

These models were stored in PyTorch format , essentially compressed Pickle files. The malicious payload was inserted at the beginning of the Pickle stream, allowing it to execute before the integrity of the file was compromised, thus avoiding detection by Hugging Face's security tools

See also: Google Messages update offers additional protection against spam and sensitive content

Malicious machine learning (ML) models, such as the one discovered in Hugging Face, pose a significant threat in the evolving AI landscape. These models are intentionally designed or manipulated to produce harmful results, such as making false predictions, exposing sensitive information, or undermining trust in automated systems. Attack vectors can include data poisoning, where training data is corrupted to bias the model, or adversarial inputs, which exploit model vulnerabilities to induce incorrect responses. The rise of such threats highlights the need for robust security measures in AI, including comprehensive testing, secure data practices, and continuous monitoring to protect systems from exploitation.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS