Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Malicious AI Models Evade Detection on Hugging Face Platform
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
CybersecurityTechnology

Malicious AI Models Evade Detection on Hugging Face Platform

Highlights

  • ReversingLabs found two malicious models on Hugging Face.

  • Pickle files were used to embed harmful web shells.

  • Hugging Face enhanced security tools to counteract threats.

Ethan Moreno
Last updated: 6 February, 2025 - 7:09 pm 7:09 pm
Ethan Moreno 3 months ago
Share
SHARE

As artificial intelligence continues to expand, platforms facilitating community-driven model sharing like Hugging Face have become essential resources for developers worldwide. However, this growth also brings heightened security risks, as malicious actors exploit vulnerabilities to distribute harmful code. Recently, ReversingLabs uncovered two machine-learning models on Hugging Face that utilized a deceptive method known as “pickling” to embed malicious web shells, posing significant threats to the integrity of AI development environments.

Contents
How Did the Malicious Models Bypass Detection?What Measures Has Hugging Face Implemented?Are Pickle-Related Vulnerabilities a Growing Concern?

ReversingLabs found that the malicious models employed pickle files, a Python-based serialization method, to include harmful code capable of executing from untrusted sources during the deserialization process. This technique allowed the models to link to hardcoded IP addresses, thereby embedding web shells that could potentially compromise systems running these models.

How Did the Malicious Models Bypass Detection?

The identified models managed to evade Hugging Face’s security tool, Picklescan, primarily because they were compressed using alternative formats. Picklescan relies on a blacklist of dangerous functions to mark unsafe pickle files, but it struggled to detect the malicious code within these compressed or broken files, highlighting limitations in current security scanning methods.

What Measures Has Hugging Face Implemented?

“The Picklescan tool is based on a blacklist of ‘dangerous’ functions. If such functions are detected inside a Pickle file, Picklescan marks them as unsafe,”

explained Karlo Zanki, a reverse engineer at ReversingLabs. Recognizing the loopholes, Hugging Face swiftly removed the malicious models and updated Picklescan to better identify such threats, improving their platform’s defense mechanisms against evolving security challenges.

Are Pickle-Related Vulnerabilities a Growing Concern?

With the surge in community-made machine-learning models, pickle-related vulnerabilities remain a prevalent issue. Other cybersecurity firms, including Wiz and Checkmarx, have similarly identified various methods by which pickle files can be abused to deliver malware on open platforms. This ongoing trend underscores the necessity for more robust and adaptable security measures in AI development environments.

Ensuring the security of AI platforms like Hugging Face is crucial as the reliance on shared models increases. The ability of malicious actors to exploit pickle files highlights a significant vulnerability that demands continuous attention and improvement. Developers must remain vigilant and adopt comprehensive security practices to safeguard against such threats, fostering a safer and more secure AI development landscape.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

SonicWall Customers Face Spike in Device Vulnerabilities

Cyberattack Forces PowerSchool to Face Extortion Scandal

CrowdStrike Faces Workforce Reduction Amid Financial Shifts

Authorities Seize DDoS Platforms in Multi-National Operation

Uber Navigates Tariffs While Preparing for Growth

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article New Mars Impact Sheds Light on Planet’s Deep Interior
Next Article EA Faces Sales Slump, Plans Major Updates for Apex Legends

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Standard Bots Unveils Robot Arm and Expands U.S. Facility
Robotics
Samsung Offers Discounts on the Galaxy Watch Ultra Purchase
Wearables
Beat Wordle with Smart Strategies and Daily Hints
Gaming
ABB Advances AMR Technology with vSLAM for Enhanced Operations
Robotics
Tesla Semi Gains Momentum with US Foods Collaboration
Electric Vehicle
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?