Malicious AI Models on Hugging Face Exploit Novel Attack Technique
Two malicious machine learning models recently identified on Hugging Face exposed critical vulnerabilities in the platform’s security infrastructure. By exploiting a novel technique that bypasses existing detection mechanisms, these models demonstrate how threat actors can abuse standard file serialization formats to distribute harmful code. This incident highlights a significant gap between the convenience of open collaboration and the necessity of rigorous security protocols in shared AI repositories. The core issue lies in the use of Pickle serialization, a common method for storing machine learning models that inherently allows arbitrary code execution. The attackers successfully evaded detection by compressing PyTorch models in an unconventional format and embedding malicious payloads within structurally broken files. Because current scanning tools rely on validating file integrity before security checks, they fail to interpret these corrupted streams, allowing dangerous instructions to execute during deserialization without triggering alarms. This discovery is profoundly relevant to open data communities as it underscores the inherent risks of trusting shared, executable artifacts in open-source environments. It reveals that current security measures, which often depend on static blacklists or strict validation, are insufficient against evolving threats that manipulate file structures. Consequently, developers and platform maintainers must prioritize dynamic analysis and stricter ingestion protocols to protect the integrity of open data ecosystems from silent compromise.
Source: infosecurity-magazine.comPublished on 2025-02-08