bk99.de entertain the web since 1997

A joint security analysis with Wiz

Summary

Hugging Face and Wiz Research examine the risks of loading foreign models and of isolated execution environments. The article shows how model artefacts can become a supply chain for executable code. Wiz Research reported security findings to Hugging Face.

Ideas

  • Models, demos and data sets together form a software supply chain.
  • Isolation must also take metadata, converters and custom code into account.

Insights

  • AI artefacts are active parts of the supply chain and need isolation, proof of origin and minimal privileges.

Facts

  • The collaboration led to fixes and additional protective measures.

Critique

  • A platform operator’s account does not replace independent disclosure of all findings.

Recommendations

  • Scan model artefacts, limit permissions and run foreign code only in isolation.

References

Read the original article on Hugging Face

Search the Web Archive