4 ms·
At 3:30a France local? Alrighty. I still wait a lil bit ;)
by angilly 2y ago
At 3:30a France local? Alrighty. I still wait a lil bit ;)
- moralestapia 2y agoWhat could a malicious model do, though? Curse at you?
- Teever 2y agohttps://arstechnica.com/security/2024/03/hugging-face-the-github-of-ai-hosted-code-that-backdoored-user-devices/ https://arstechnica.com/security/2024/03/hugging-face-the-gi...
- Tiberium 2y agoNot .safetensors though
- deleted 2y ago[deleted]
- Aissen 2y agoExploit a memory safety issue in the tokenizer/or other parts of your LLM infra written in a native language.
- moralestapia 2y ago??? With weights?
- abound 2y agoThere are plenty of exploits where the payload is just "data" read by some vulnerable program (PDF readers, image viewers, browsers, compression tools, messaging apps, etc)
- sp332 2y agoYes, there's a reason weights are now distributed as "safetensors" files. Malicious weights files in the old formats are possible, and while I haven't seen evidence of the new format being exploitable, I wouldn't be surprised if someone figures out how to do it eventually.
- fzzzy 2y agoThere was a buffer overflow or some other exploit like that in llama.cpp and the gguf format. It has been fixed now, but it's definitely possible. Also weights distributed as python pickles can run arbitrary code.
- bevekspldnw 2y agoDistributing anything as python pickles seems utterly batshit to me.
- fzzzy 2y agoCompletely agree.