Skip to content
InfoNews

Rolling the cyber dice with open-source and open-weight AI models

Published
Record updated
View JSON

Summary

The article argues that open-weight AI models carry risks that conventional security scanning cannot detect, because their training data and scripts are often not disclosed. It separates repository malware, such as malicious pickle-serialized models on Hugging Face documented by JFrog, from latent behavioral backdoors demonstrated so far in controlled research. The source text is cut off before its discussion of the Winter Soldier poisoning results is complete.