Hugging Face hit by autonomous AI agent attack, defends with AI tools
Decision Brief
Hugging Face reported that attackers exploited two code execution paths in its data processing pipeline (remote code dataset loader and dataset config template injection) via malicious datasets, gained node-level access, stole cloud and cluster credentials, and moved laterally across multiple clusters. The attack was orchestrated by an autonomous security research framework-based agent system, executing over 17,000 independent actions using short-lived sandboxes and self-migrating C2 infrastructure. The company stated that public models, datasets, and Spaces were not tampered with, and the software supply chain remains unaffected; whether partner or customer data was compromised is under investigation. Hugging Face detected the attack via an AI-driven anomaly detection pipeline using LLM-based security telemetry classification. In analyzing the 17,000+ attack actions, the company deployed LLM-powered analysis agents that reconstructed timelines, extracted IOCs, mapped compromised credentials, and distinguished real breaches from deception activities, reducing forensic work from days to hours. However, when the security team initially tried using frontier models behind commercial APIs to analyze attack logs, the provider's safety guardrails blocked requests—they couldn't distinguish incident responders from attackers, as real attack commands, exploit payloads, and C2 artifacts triggered filters. The team switched to the open-source model GLM 5.2 running on its own infrastructure, avoiding data and credential leakage. For developers using Hugging Face's platform, it is recommended to immediately rotate access tokens and review recent account activity. This incident demonstrates that autonomous AI-driven attack tools are no longer theoretical—they lower the cost of large-scale multi-stage attacks and operate at machine speed. Hugging Face believes data and model surfaces must be treated as first-class attack surfaces, and defenders need their own AI to keep pace. This event also highlights an industry-wide gap: commercial safety guardrails can hinder defenders' forensic work during critical moments, and having a high-capability model running on your own infrastructure is essential preparation against such attacks.
Sources
- The Decoder:AI News
- The Decoder:AI News
留言
登入后即可留言,和其他 builder 交换实测心得。
还没有留言,抢头香。