Users thanked the builder urging Hugging Face to add cryptographic signing for open models because it would strengthen security and trust.
Based on 1 visible X reactions from 7 accounts; directional sample.
Ask a question below.
Published answers will appear here.
I think the most likely way this occurs is delivering a poisoned copy of an open model to an unsuspecting party, and you don't need to be China to do it. @ClementDelangue please build hf infrastructure for cryptographically signing models thx
Cc @RisingSayak I see you guys were just exploring some stuff like this for kernel signing. Can you extend this to models? Threat model is different, but helps resolve at least some concerns about models modified to insert backdoors.
Users thanked the builder urging Hugging Face to add cryptographic signing for open models because it would strengthen security and trust.
Based on 1 visible X reactions from 7 accounts; directional sample.
Ask a question below.
Published answers will appear here.