Attackers hide malicious code in Hugging Face AI model Pickle files
Hugging Face’s defense against malicious pickle files relies on scanning for dangerous methods, yet this blacklist approach proves inadequate. Researchers demonstrated that attackers can bypass these restrictions by exploiting alternative built-in Python functionalities. This highlights critical security limitations in open data platforms sharing code, urging more robust protection mechanisms.
Source: csoonline.comPublished on 2025-02-08