Malicious AI models on Hugging Face backdoor users' machines
bleepingcomputer.com
bleepingcomputer.com
What's the advantage of paying jfrog over using safetensors?
Why is it legal for them to make these claims without providing a discrete list of known malware infected models?
This seems really shady, to me, bordering on an extortion racket. "It'd be a shame if something happened to your computer, but don't worry, you can pay us for protection..."
In addition, where is the HuggingFace report on models known to have been infected? HF has a responsibility to inform people of potential issues if they downloaded something before it was flagged. Maintaining a list of known bad models would be a good idea, I think.
I think there was also an example where Python code with a try block, when it failed because of a missing dependency did a `sudo apt install` in the catch block.
Not sure how much SBOMs help, but we sure need to get this supply chain mess in order.
The ml community needs to move away from pickle files as soon as possible. Worst idea ever.
Yes, ml researchers have been running random pickles from the internet for years now.
No they are not buried in a non obvious way. They are at the very top of many models. safetensors and gguf have started to replace this horrible practice, but there are still tons of models that use pickles.
Then again, convincing people to play around with a model might be easier than getting them to use your library in an application.
put another way, maybe the cost of a few bad faith actors is much higher than anticipated among people doing skilled work? How is that handled in a human way?
I can guess that de-platforming based on whatever is much easier for the server side. This dynamic is how we got to the personal computer "revolution" thirty+ years ago
Sure, any library/tool that harnesses models might contain malicious code. The models themselves should not be able to.
This is more like distributing music as .exe files instead of .flac
Some popular applications (Automatic1111 etc.) take measures against that, but the real fix is to ignore anything that isn't safetensors.
Some of the official extensions install code from random places like that.
Pickle was created to store Python objects. Safetensors was designed to store (only) weights.
This is no different to posting binaries online and telling folks to run them on their machines.
A gguf model file can be thought of (at a very high level) as a jpg. We have safe and secure ways of decoding and using a jpg.
The "black box" you refer to is more about not understanding why a model does what it does. We don't know why a particular node in the network has a value that ends up influencing the output. We understand how a deep neural net works.
Regular users do not know any of this and do not care. All they know is to download .exe and run and never check whatever they are downloading is malicious or not.
> The "black box" you refer to is more about not understanding why a model does what it does.
That is my additional point which makes this situation absolutely even worse.
> We understand how a deep neural net works.
No one does and certainly not even the AI scientists even understand the unpredictable behaviours of these models after training.
As for my "regular users" comment, I don't think it's hard to imagine a world where users have a trusted program that runs the models. This is how basically all file formats work. Excel was insecure at one point for similar reasons, you could embed malicious code in macros, but today excel spreadsheets can run computations on files downloaded from the web and it's just as secure as open a .txt file.
Whenever there is trust involved, there is no difference to your point. How you're running the model requires trusting that the model, parser, etc isn't compromised and especially if it can be trusted to behave correctly after training - thus transparent explanations rather than hallucinations and its easy to trick and compromise them to do something else.
Given that we already don't trust the outputs of these AI models, the above security issue make this even worse and untrustworthy. The plain old regular average joe users do not care about the neural network format, etc and will run and open anything without checking regardless even if it is a text file disguised as a program.
Thus, it is entirely no different and we are back to square -1 (with the unexplainable properties of these models that people will try it out and trust its outputs)
But, I expect we're going to have additional rounds of insecure practice just like we've had in every other popularized tech movement. People are going to develop frameworks with code-injection flaws, where they assume mode outputs (tokens) can be trusted and can contain executable content. Then, the inscrutable and untrustworthy models are going to be a problem as well.
Think everything from MS Office macro abuse to human drivers blindly following their GPS guidance into a lake. This can and most probabaly will be repeated with AI models, due to the prevalence of naive and over-trusting practitioners and consumers.
How people use model outputs (or inputs; I.e prompt injections) is a whole other area ripe for exploits, especially while these technologies are being adopted by people who don’t really understand them. But I view this as fundamentally different than the above. A model format can be secure in that it won’t just randomly delete files on your computer. This is a computer science problem and thus provably securable. I guess that was the point I was trying to make when differentiating why they work vs how they work.