Hugging Face Has a Deepfake Nudes Problem
Summary
Hugging Face, an open-source AI platform hosting AI models and datasets, has a widespread problem with nonconsensual deepfake nudes, according to research by AI Forensics. Researchers found that seven out of nine tested image editing tools on the platform could easily remove clothes from photos, and over 73 percent of user requests to honeypot (fake decoy) spaces were sexual in nature, with 83 percent seeking to undress or sexualize women without consent. The platform's content policies prohibit such deepfakes, but researchers found no safety mechanisms (called guardrails, which are filters to block harmful outputs) actually implemented at the platform level to prevent this misuse.
Solution / Mitigation
Hugging Face could "easily filter what is coming in and coming out of a system" according to researcher Paul Bouchaud quoted in the source. Some pages promoting nudifying services were removed after the publication contacted the company, though it is unclear if the two actions are directly related.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://www.wired.com/story/hugging-face-has-a-nonconsensual-deepfakes-problem/
First tracked: July 28, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 92%