Untitled attachment
https://files.mastodon.social/media_attachments/files/113/968/724/783/346/875/original/3265272a71b5cefc.png
Malicious open source models are being uploaded to popular repository hugging face. This will be a completely new cybersecurity risk. Now it's merely code execution. But expect tainted/poisoned weights impacting outputs. Python reverse shell script enables remote command execution. On Linux, it spawns a `/bin/sh` shell, on Windows, it launches PowerShell and enables bidirectional communication. https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.