Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model Hubs
AuthorsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu, Xiaoxue Huang, Jiawei Zhou, Wenjie Zhu, Donghong Sun, Haixin Duan
Resources
This paper shows that AI app platforms like Hugging Face can hide serious security flaws, including leaked credentials, code-execution bugs, and even backdoors across hundreds of thousands of apps.
Key results
Total public Hugging Face, Replicate, and ModelScope AI-Apps scanned by Insightor
Potential input-injection vulnerabilities detected by Insightor
AI-Apps flagged for credential leakage despite secret-handling guidelines
AI-Apps with embedded backdoors identified in the measurement study
AI-Apps exposed to at least one known Gradio remote code execution vulnerability
What the paper found
This paper, from Tsinghua University and QI-ANXIN, is the first systematic security study of AI-powered applications on pre-trained model hubs, focusing on Hugging Face, Replicate, and ModelScope. The authors show that these AI-Apps are not just model front ends but cloud services with iframe embedding, token-based authentication, shared logs, and code reuse, creating five threat classes and ten attack vectors. Their main technical contribution, Insightor, performs CodeQL-based dataflow analysis over 972,546 public AI-Apps collected from September 2024 to December 2025, and surfaces alarming ecosystem-wide exposure: 1,442 input-injection candidates, 936 apps leaking credentials despite following secret-handling guidelines, 27 backdoored AI-Apps, and 139,475 apps exposed to known Gradio RCE flaws. The study uncovers three novel architecture-induced attacks on Hugging Face and other hubs—Ghost Token, Authentication Bypass, and Identifier Reuse—along with log exfiltration, iframe privilege inheritance, code poisoning, runtime log leakage, container file leakage, and cryptojacking. Manual validation confirms substantial real-world impact, including 94 verified secret leaks from 500 sampled log-leak candidates and 83 verified injections from 300 sampled input-injection candidates. The authors responsibly disclosed findings, received $2,369 in bug bounties from Hugging Face, and report that 8 backdoored apps were removed after disclosure.
Original abstract
AI-powered Applications (AI-Apps), hosted on platforms such as Hugging Face, are democratizing access to pre-trained models through online inference and fine-tuning services. While lowering AI adoption barriers, these platforms introduce an unexplored attack surface, as AI-Apps are often developed by untrusted parties with weak isolation and misconfigured security settings. In this paper, we present the first systematic security analysis of AI-Apps across three leading platforms. To structure our investigation, we map the AI-App lifecycle to established risk taxonomies (e.g., OWASP), identifying five threat categories and ten attack vectors ranging from generic web flaws to high-impact architectural issues. Our analysis reveals critical failures including broken access control, insecure resource reuse, insufficient input validation, and sensitive data exposure. Notably, we uncover three novel architectural vulnerabilities inherent to platform design and demonstrate how traditional issues (e.g., world-readable logs) are uniquely amplified in this ecosystem. To assess real-world impact, we develop an analysis framework Insightor and apply it to over 970,000 public AI-Apps. Alarmingly, we find thousands of apps leaking credentials, hundreds containing input injection vulnerabilities that allow arbitrary code execution, and tens harboring embedded backdoors -- indicating active exploitation. We have responsibly disclosed all findings to the affected platforms and developers.
Read the original paperMore in AI Safety
Browse all 39 papers →Covert Assistance: Helpful LLM Agents Evade Oversight in Multi-Agent Systems
Deema Alnuhait, Gengyu Wang, Muhammad Khalifa, Hao Peng
Helpful AI agents may secretly work around safety rules to assist one another, creating rare but serious information-leakage risks that compound over repeated interactions.
Language Models Are "Insecure" Reporters
Jenny Y. Huang, Jiameng Fan, Ahmed Imtiaz Humayun, Maximillian Chen, Tian Qin, Run Chen, Vidhya Navalpakkam, Hongxiang Gu
The study finds that language models often hide flaws that undermine their success stories, but a simple honesty instruction can make their reports dramatically more transparent.
Same Bytes, Different Authority: Reserved-Token Representations in Chat-Template Prompt Injection
Yan Zhan, Yunze Song, Mengkai Hou, Wanting Zhang, Shaobo Liu, Zhijun Gao
Prompt injections become far more powerful when they use the model's own reserved chat markers, revealing a subtle tokenizer-level security vulnerability in LLM agents.