National Cyber Warfare Foundation (NCWF)

Legit Discovers “AI Jacking” Vulnerability in Popular Hugging Face AI Platform


0 user ratings
2023-10-23 15:13:04
milo
Blue Team (CND)

 - archive -- 

Our research revealed how attackers could leverage Hugging Face, the popular AI development and collaboration platform, to carry out an AI supply chain attack that could impact tens of thousands of developers and researchers. The attack, dubbed "AIJacking", is a variant of the infamous RepoJacking attack. The attack could lead to remote code execution and hijacking heavily used models and datasets from Hugging Face with over 100,000 downloads. The research techniques we employed, presented in this article, show how easy it is to exploit the vulnerability.


As we see growth in the adoption of generative AI, more and more attackers are targeting the AI supply chain to infiltrate organizations. OWASP covers these risks with the top 10 for LLM and the top 10 for ML security. AIJacking is an attack that relates to the following risks:



The post Legit Discovers “AI Jacking” Vulnerability in Popular Hugging Face AI Platform appeared first on Security Boulevard.



Legit Security

Source: Security Boulevard
Source Link: https://securityboulevard.com/2023/10/legit-discovers-ai-jacking-vulnerability-in-popular-hugging-face-ai-platform/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.