Attackers hide malicious code in Hugging Face AI model Pickle files

Hugging Face’s defense against malicious pickle files relies on scanning for dangerous methods, yet this blacklist approach proves inadequate. Researchers demonstrated that attackers can bypass these restrictions by exploiting alternative built-in Python functionalities. This highlights critical security limitations in open data platforms sharing code, urging more robust protection mechanisms.

Source: csoonline.com
Published on 2025-02-08