720-891-1663

Hugging Face Says Autonomous AI Agent Breached it

In case you were wondering when cyberattacks would be fully AI automated, stop wondering. It is now and multiple attacks that have occurred in the last couple of months prove it.

This one is against Hugging Face, often referred to as the GitHub of machine learning.

The attacker accessed a limited set of internal data and several credentials used by Hugging Face services. The company is still determining whether any customer or partner data was affected and said it will contact relevant parties if required.

At this point they don’t think any models were modified.

The attack began when a malicious dataset exploited two code execution paths in Hugging Face’s dataset-processing system. One involved a remote-code dataset loader, while the other used template injection within a dataset configuration.

After gaining code execution on a processing worker, the attacker obtained node-level access and collected cloud and cluster credentials. Those credentials were then used to move into several internal clusters during a weekend.

Not surprisingly, they used AI to analyze the breach and figure out what happened. With AI this took hours instead of weeks.

Interestingly, while the AI didn’t stop the attack, it did stop the forensics thinking that was an attacker planning a breach. The solution was to bring the LLM in house and modify the guardrails as needed.

The company is giving advice on what users should do to protect themselves and they are being pretty open about it. But, it is always better from someone else’s pain. Credit: Hackread

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *