A joint security analysis with Wiz
Summary
Hugging Face and Wiz Research examine the risks of loading foreign models and of isolated execution environments. The article shows how model artefacts can become a supply chain for executable code. Wiz Research reported security findings to Hugging Face.
Ideas
- Models, demos and data sets together form a software supply chain.
- Isolation must also take metadata, converters and custom code into account.
Insights
- AI artefacts are active parts of the supply chain and need isolation, proof of origin and minimal privileges.
Facts
- The collaboration led to fixes and additional protective measures.
Critique
- A platform operator’s account does not replace independent disclosure of all findings.
Recommendations
- Scan model artefacts, limit permissions and run foreign code only in isolation.
References
Read the original article on Hugging Face
Links to the original source and the Web Archive open in a new tab.