In a worrying development for the machine learning community, researchers at ReversingLabs have discovered the presence of malicious machine learning (ML) models on the popular platform Hugging Face.
See also: Malicious PowerShell scripts: What they are and how to protect yourself

These models exploit vulnerabilities in the Pickle file serialization process, a popular method widely used for storing and exchanging machine learning data
The discovery highlights the growing security risks that accompany collaborative AI platforms , while underscoring the imperative need for increased vigilance on the part of developers
Pickle is a Python library that allows for the serialization and deserialization of objects, making it easier to store and retrieve data.
See also: Protect yourself from cyber threats in the new year
Although it offers convenience, it poses serious security risks, as it has the ability to execute arbitrary Python code during the deserialization process.

Researchers at Reversing Labs observed that this vulnerability can be exploited by attackers to embed malicious payloads into seemingly harmless ML models.
ReversingLabs researchers identified two models in Hugging Face that contained malicious code, which they named “nullifAl“.
These models were stored in PyTorch format , essentially compressed Pickle files. The malicious payload was inserted at the beginning of the Pickle stream, allowing it to execute before the integrity of the file was compromised, thus avoiding detection by Hugging Face's security tools
See also: Google Messages update offers additional protection against spam and sensitive content
Malicious machine learning (ML) models, such as the one discovered in Hugging Face, pose a significant threat in the evolving AI landscape. These models are intentionally designed or manipulated to produce harmful results, such as making false predictions, exposing sensitive information, or undermining trust in automated systems. Attack vectors can include data poisoning, where training data is corrupted to bias the model, or adversarial inputs, which exploit model vulnerabilities to induce incorrect responses. The rise of such threats highlights the need for robust security measures in AI, including comprehensive testing, secure data practices, and continuous monitoring to protect systems from exploitation.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
