Wiz Discovers Flaws in GenAI Models Enabling Customer Data Theft
Wiz identified critical vulnerabilities in generative AI models on Hugging Face, revealing that shared inference infrastructure can be compromised via malicious pickle files. These flaws allow attackers to execute arbitrary code, potentially gaining escalated privileges and cross-tenant access, which poses a severe threat to AI-as-a-service providers. Additionally, the study highlights risks related to shared CI/CD pipelines, where attackers could hijack automated workflows to launch supply chain attacks. This underscores the fragility of current open AI deployment ecosystems, where trust in shared resources is often misplaced. This research is vital for open data communities as it demonstrates that transparent model sharing without rigorous security validation can introduce systemic risks. It urges developers and platform maintainers to prioritize infrastructure isolation and code integrity, ensuring that open collaboration does not inadvertently expose users to severe security breaches or unauthorized data access.
Source: infosecurity-magazine.comPublished on 2024-04-06