logoalt Hacker News

artrockalteryesterday at 11:02 PM4 repliesview on HN

The Hugging Face incident is a great example of why open source models with defensive cyber capabilities are needed. Hugging Face did not have access to cyber-capable frontier models and kept hitting safeguards. Only by using the open source GLM-5.2 were they able to survive an attack. A world where open source models are banned is one where cybersecurity is impossible if you're not on OpenAI or Anthropic's allowlist.


Replies

ajyoonyesterday at 11:10 PM

Hugging Face survived the attack because the OpenAI model only cared about accessing the ExploitGym dataset; by all appearances, HF was completely owned. GLM-5.2 was only used to assess the damage after the fact. Cybersecurity has a attacker-defender asymmetry that heavily favors attackers. If GPT-5.6 were open sourced today, do you think every hospital in the world would be able to use it to shore up their defenses before attackers got to them?

show 2 replies
paxystoday at 2:12 AM

> Only by using the open source GLM-5.2 were they able to survive an attack

They did not "survive" anything. The attack was long done, and they used GLM after the fact to parse logs. Having a more powerful model would have changed nothing.

If every attacker and every defender has AI with the same capabilities then attackers are going to win 10 times out of 10.

alienbabytoday at 1:10 AM

? There were not models fighting each other, attacker and defender. I dont quite follow what your getting at.

show 1 reply