
Author: QQlink
AI Starts Attacking AI: What Signals Were Released by the Hugging Face Incident?
The artificial intelligence industry is undergoing a significant turning point.
In the past, AI was often viewed more as a production tool. Developers used models to generate code, companies utilized AI to improve efficiency, and researchers accelerated R&D through models.
But with the development of AI Agents, AI is moving from “answering questions” to “executing tasks.”
This means AI can not only analyze information but also call tools, run code, access systems, and autonomously plan the next steps according to objectives.
The recent security incident disclosed by Hugging Face occurred against this backdrop.
As one of the largest AI open source communities in the world, Hugging Face hosts a large number of models, datasets, and machine learning resources. Developers around the globe access model weights, download datasets, and apply them in research and commercial projects through this platform.
However, an attack on the platform’s infrastructure shows that AI Agents are entering the domain of cyber offense and defense.
According to reports, this attack lasted over a weekend, generating more than 17,000 operational logs during the attack process. The attack was not conducted by traditional hackers step by step, but was driven by a set of autonomous agent systems.
The issue reflected behind this is not simply that a platform has vulnerabilities, but that the entire AI ecosystem is facing new security variables.
From “AI-assisted Attacks” to “AI Autonomous Actions”: The Attack Mode is Changing
Previously, there have been instances where AI participated in cyber attacks.
Last year, Anthropic disclosed an incident: attackers integrated Claude Code into an attack framework, with a large number of tasks completed by AI, while humans were only responsible for a few key decisions.
At that time, the focus was on how AI improved attack efficiency.
However, the change brought by the Hugging Face incident is that human involvement has further decreased.
According to the disclosed information, the attackers used a cluster of agents to execute tasks across multiple stages, including exploring environments, executing code, obtaining permissions, and searching for internal resources.
In simple terms, attackers in the past resembled programmers using automated tools, whereas now it is closer to deploying a digital “execution team.”
These agents can run a large number of tasks simultaneously, with each node responsible for different actions, and adjusting strategies in an automated manner.
The biggest feature of this mode is speed.
Traditional attacks require attackers to continuously analyze feedback before deciding on the next move.
In contrast, agent systems can persistently trial and error, adjust paths, and carry out a large number of operations in a short time.
This is why the security industry is beginning to re-evaluate AI Agents.
The question is no longer just “Can AI write malicious code?” but “What new risks will arise when AI has execution permissions?”
Why Could a Dataset Become an Attack Entry Point?
It is noteworthy that the entry point of this incident was not a traditional server vulnerability, but a data link in the AI ecosystem that is often overlooked.
Attackers uploaded malicious datasets, triggering code execution through the data processing pipeline.
This involved remote code dataset loaders and template injection issues within dataset configurations.
For ordinary users, datasets are merely the information needed to train models.
However, in the context of AI infrastructure, datasets are not just static files.
They may contain configuration files, processing logic, and runtime environment dependencies.
When developers load unverified data resources directly, they may leave an entry point for attackers.
This is also the new issue facing AI supply chain security.
In the past, the software industry focused on the security of open-source code repositories.
Today, the AI industry needs to pay closer attention to models, datasets, plugins, and Agent toolchains.
Because the AI ecosystem is more complex than traditional software.
A model may depend on multiple datasets, an Agent may call multiple external tools, and any problem at one link could impact the entire system.

The Most Ironic Scene: AI Attacks Discovered by AI
Another detail of this incident is worth noting.
The system that detected the anomaly was also an AI system.
Hugging Face's own security monitoring process uses large language models to analyze security telemetry data, discovering attack behaviors through anomaly signals correlation.
Subsequently, during the incident investigation phase, they also utilized LLMs to analyze agent handling of over 17,000 attack records, including reconstructing timelines, identifying attack paths, and extracting key metrics.
This created a very unique scenario:
AI is responsible for the attack, and AI is responsible for the investigation.
Future network security may enter a new competitive model.
Attackers use AI to improve efficiency, and defenders also use AI to enhance response speed.
The competition is not just about technical capability, but also about model capability, data quality, and infrastructure control capability.
However, this also exposes another real issue.
AI security tools themselves have limitations.
Why Does Defending Against AI Attacks Get Restricted by AI Security Rules?
During the incident review process, Hugging Face encountered an awkward situation.
They attempted to use commercial AI services to analyze attack logs, but due to the logs containing real attack commands, vulnerabilities, and potentially sensitive information in security data, requests were intercepted by the service provider's security mechanism.
Ultimately, they turned to using an open-source model running in their own environment to complete the analysis.
This experience reflects a long-standing issue in the field of AI security:
Security research needs to see real risks, but AI service platforms must limit dangerous content.
There is an inherent contradiction between the two.
If restrictions are too severe, security personnel may not be able to analyze real attacks.
If control is too lax, it may increase the risk of model misuse.
This is also an important topic for future AI governance.
Finding a balance between security control and research freedom will affect the development of the entire industry.
In the Era of Open Source AI, Will Security Issues Become a New Competitive Point?
The Hugging Face incident does not mean that AI Agents inevitably bring risks.
On the contrary, agent technology is becoming an important direction for driving automation.
Companies hope that AI can autonomously handle code maintenance, data analysis, security monitoring, and business processes.
But the more powerful the capability, the more complex the risks.
The past software security system was built on a human operation-centric logic.
Now, AI Agents are becoming new execution entities.
This means that permission management, security auditing, and operational isolation mechanisms all need to be redesigned.
For developers, future focus should not only be on model ability but also on the model operating environment.
For companies, when deploying AI systems, they need to manage Agent permissions just like managing employee permissions.
The real question arises:
When an AI can autonomously call tools, perform tasks, and find paths, do we still treat it as ordinary software?
The answer may be changing.
The Competition in AI Security has Shifted from Vulnerability Defense to Agent Defense
The greatest significance of the Hugging Face incident is not just a simple security accident.
It serves as a reminder:
AI is gradually becoming a subject participating in the network environment rather than just a tool being used.
Attackers are starting to use agents to enhance efficiency, and defenders are also beginning to use agents to strengthen capabilities.
In the coming years, AI security competition may revolve around three cores:
Who can better control AI permissions;
Who can more quickly detect abnormal behaviors;
Who can establish a more reliable AI operating environment.
For the entire industry, the real challenge is not to prevent AI development but to establish a sufficiently mature security system before AI gains increasingly strong operational capabilities.
Because the next round of AI competition is not just about model parameters, but also about security boundaries.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。