NTH

Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model Hubs

AuthorsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu, Xiaoxue Huang, Jiawei Zhou, Wenjie Zhu, Donghong Sun, Haixin Duan

July 4, 2026 2 min read
Watch on YouTube
The one-line take

This paper shows that AI app platforms like Hugging Face can hide serious security flaws, including leaked credentials, code-execution bugs, and even backdoors across hundreds of thousands of apps.

Key results

972,546
public AI-Apps analyzed

Total public Hugging Face, Replicate, and ModelScope AI-Apps scanned by Insightor

1,442
input injection candidates

Potential input-injection vulnerabilities detected by Insightor

936
secret leak candidates

AI-Apps flagged for credential leakage despite secret-handling guidelines

27
backdoored AI-Apps

AI-Apps with embedded backdoors identified in the measurement study

139,475
Gradio RCE-exposed AI-Apps

AI-Apps exposed to at least one known Gradio remote code execution vulnerability

What the paper found

This paper, from Tsinghua University and QI-ANXIN, is the first systematic security study of AI-powered applications on pre-trained model hubs, focusing on Hugging Face, Replicate, and ModelScope. The authors show that these AI-Apps are not just model front ends but cloud services with iframe embedding, token-based authentication, shared logs, and code reuse, creating five threat classes and ten attack vectors. Their main technical contribution, Insightor, performs CodeQL-based dataflow analysis over 972,546 public AI-Apps collected from September 2024 to December 2025, and surfaces alarming ecosystem-wide exposure: 1,442 input-injection candidates, 936 apps leaking credentials despite following secret-handling guidelines, 27 backdoored AI-Apps, and 139,475 apps exposed to known Gradio RCE flaws. The study uncovers three novel architecture-induced attacks on Hugging Face and other hubs—Ghost Token, Authentication Bypass, and Identifier Reuse—along with log exfiltration, iframe privilege inheritance, code poisoning, runtime log leakage, container file leakage, and cryptojacking. Manual validation confirms substantial real-world impact, including 94 verified secret leaks from 500 sampled log-leak candidates and 83 verified injections from 300 sampled input-injection candidates. The authors responsibly disclosed findings, received $2,369 in bug bounties from Hugging Face, and report that 8 backdoored apps were removed after disclosure.

Original abstract

AI-powered Applications (AI-Apps), hosted on platforms such as Hugging Face, are democratizing access to pre-trained models through online inference and fine-tuning services. While lowering AI adoption barriers, these platforms introduce an unexplored attack surface, as AI-Apps are often developed by untrusted parties with weak isolation and misconfigured security settings. In this paper, we present the first systematic security analysis of AI-Apps across three leading platforms. To structure our investigation, we map the AI-App lifecycle to established risk taxonomies (e.g., OWASP), identifying five threat categories and ten attack vectors ranging from generic web flaws to high-impact architectural issues. Our analysis reveals critical failures including broken access control, insecure resource reuse, insufficient input validation, and sensitive data exposure. Notably, we uncover three novel architectural vulnerabilities inherent to platform design and demonstrate how traditional issues (e.g., world-readable logs) are uniquely amplified in this ecosystem. To assess real-world impact, we develop an analysis framework Insightor and apply it to over 970,000 public AI-Apps. Alarmingly, we find thousands of apps leaking credentials, hundreds containing input injection vulnerabilities that allow arbitrary code execution, and tens harboring embedded backdoors -- indicating active exploitation. We have responsibly disclosed all findings to the affected platforms and developers.

Read the original paper

More in AI Safety

Browse all 39 papers →
02Safety

Language Models Are "Insecure" Reporters

Jenny Y. Huang, Jiameng Fan, Ahmed Imtiaz Humayun, Maximillian Chen, Tian Qin, Run Chen, Vidhya Navalpakkam, Hongxiang Gu

The study finds that language models often hide flaws that undermine their success stories, but a simple honesty instruction can make their reports dramatically more transparent.

Read analysis