A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models
Fuente:
arXiv
Salvato in:
| Autori principali: | Casey, Beatrice, Santos, Joanna C. S., Mirakhorli, Mehdi |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
di: Reyes, Frank, et al.
Pubblicazione: (2024)
di: Reyes, Frank, et al.
Pubblicazione: (2024)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2026)
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2026)
Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
di: Koscinski, Viktoria, et al.
Pubblicazione: (2025)
di: Koscinski, Viktoria, et al.
Pubblicazione: (2025)
An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2026)
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2026)
Exploiting LLM Agent Supply Chains via Payload-less Skills
di: Liu, Xinyu, et al.
Pubblicazione: (2026)
di: Liu, Xinyu, et al.
Pubblicazione: (2026)
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
di: Baird, Laura, et al.
Pubblicazione: (2026)
di: Baird, Laura, et al.
Pubblicazione: (2026)
Understanding the Supply Chain and Risks of Large Language Model Applications
di: Ma, Yujie, et al.
Pubblicazione: (2025)
di: Ma, Yujie, et al.
Pubblicazione: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
di: Cesarano, Carmine, et al.
Pubblicazione: (2025)
di: Cesarano, Carmine, et al.
Pubblicazione: (2025)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
Assessing the Software Security Comprehension of Large Language Models
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2025)
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
di: Zhang, Ying, et al.
Pubblicazione: (2023)
di: Zhang, Ying, et al.
Pubblicazione: (2023)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
di: He, Hao, et al.
Pubblicazione: (2025)
di: He, Hao, et al.
Pubblicazione: (2025)
Software Supply Chain Security of Web3
di: Monperrus, Martin
Pubblicazione: (2025)
di: Monperrus, Martin
Pubblicazione: (2025)
Evaluating Software Supply Chain Security in Research Software
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
Securing the Software Package Supply Chain for Critical Systems
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
di: Liu, Raphina, et al.
Pubblicazione: (2024)
di: Liu, Raphina, et al.
Pubblicazione: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
di: Ruan, Bonan, et al.
Pubblicazione: (2025)
di: Ruan, Bonan, et al.
Pubblicazione: (2025)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
HALURust: Exploiting Hallucinations of Large Language Models to Detect Vulnerabilities in Rust
di: Luo, Yu, et al.
Pubblicazione: (2025)
di: Luo, Yu, et al.
Pubblicazione: (2025)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
di: Tran, Nguyen Khoi, et al.
Pubblicazione: (2023)
di: Tran, Nguyen Khoi, et al.
Pubblicazione: (2023)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
di: Chen, Zirui, et al.
Pubblicazione: (2026)
di: Chen, Zirui, et al.
Pubblicazione: (2026)
Large Language Model Supply Chain: Open Problems From the Security Perspective
di: Hu, Qiang, et al.
Pubblicazione: (2024)
di: Hu, Qiang, et al.
Pubblicazione: (2024)
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
di: Dong, Ben, et al.
Pubblicazione: (2026)
di: Dong, Ben, et al.
Pubblicazione: (2026)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
di: Bufalino, Jacopo, et al.
Pubblicazione: (2025)
di: Bufalino, Jacopo, et al.
Pubblicazione: (2025)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
From Transactions to Exploits: Automated PoC Synthesis for Real-World DeFi Attacks
di: Su, Xing, et al.
Pubblicazione: (2026)
di: Su, Xing, et al.
Pubblicazione: (2026)
Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications
di: Sheh, Raymond K., et al.
Pubblicazione: (2025)
di: Sheh, Raymond K., et al.
Pubblicazione: (2025)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
di: Seshadri, Bharathi, et al.
Pubblicazione: (2024)
di: Seshadri, Bharathi, et al.
Pubblicazione: (2024)
Unveiling Dynamic Binary Instrumentation Techniques
di: Llorente-Vazquez, Oscar, et al.
Pubblicazione: (2025)
di: Llorente-Vazquez, Oscar, et al.
Pubblicazione: (2025)
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
di: Štorek, Adam, et al.
Pubblicazione: (2025)
di: Štorek, Adam, et al.
Pubblicazione: (2025)
Expanding ML-Documentation Standards For Better Security
di: Appel, Cara Ellen
Pubblicazione: (2025)
di: Appel, Cara Ellen
Pubblicazione: (2025)
A Large Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners
di: Shi, Jingyi, et al.
Pubblicazione: (2025)
di: Shi, Jingyi, et al.
Pubblicazione: (2025)
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
di: Wang, Weizhe, et al.
Pubblicazione: (2025)
di: Wang, Weizhe, et al.
Pubblicazione: (2025)
Unknown Attack Detection in IoT Networks using Large Language Models: A Robust, Data-efficient Approach
di: Ali, Shan, et al.
Pubblicazione: (2026)
di: Ali, Shan, et al.
Pubblicazione: (2026)
Documenti analoghi
-
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
di: Reyes, Frank, et al.
Pubblicazione: (2024) -
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2026) -
Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
di: Koscinski, Viktoria, et al.
Pubblicazione: (2025) -
An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems
di: Siddiq, Mohammed Latif, et al.
Pubblicazione: (2026) -
Exploiting LLM Agent Supply Chains via Payload-less Skills
di: Liu, Xinyu, et al.
Pubblicazione: (2026)