Hugging Face Confronts a New Security Flaw; Creators Share Their AI Skepticism
Worrying about artificial intelligence turning into Skynet—a la the Terminator—should take a back seat to basic cybersecurity concerns, as we’ve written repeatedly. Today we’ve got news to prove our argument.
Cloud security firm Wiz discovered a substantial security flaw in Hugging Face, a wildly popular online repository of machine learning models that’s used by 50,000 organizations including Meta Platforms, Microsoft and Google.
Shir Tamari, Wiz’s head of research, and CTO Ami Luttwak said they uploaded a large language model with malicious code to Hugging Face. They were then able to execute commands within Hugging Face’s cloud servers, including the ability to access and edit private AI models that customers had stored. That means hackers exploiting a similar vulnerability would have been able to steal private data from other customers or potentially alter how their AI apps performed.