Make money doing the work you believe in

Hugging Face uses Chinese models to defend against cyber attacks because the US models refused to (thanks to US policy)

Hugging Face said its production infrastructure was breached by an “autonomous” AI agent system early last week (w/c Monday July 13).

The platform’s security team were initially stymied in their incident response (IR) by unnamed US LLM frontier model guardrails “which cannot distinguish an incident responder from an attacker," they said.

So Hugging Face’s defenders turned instead to the open-source GLM 5.2 model from China’s z.ai lab – running it on their own infrastructure to analyse the 17,000+ logs, or footprints, that the attackers left behind.

“When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails.”

Hugging Face said it then "ran the forensic analysis instead on [China-developed] GLM 5.2, an open-weight model, on our own infrastructure.

Hugging Face added: “This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment…”

Jul 21
at
2:34 AM
Relevant people

Log in or sign up

Join the most interesting and insightful discussions.