Innovation Hub

AI Threat Landscape Report 2024

DeepSh*t: Exposing the Security Risks of DeepSeek-R1

Summary DeepSeek recently released several foundation models that set new levels of open-weights model performance against benchmarks. Their reasoning model, DeepSeek-R1, shows state-of-the-art levels of reasoning performance for open-weights and is comparable to the highest-performing closed-weights reasoning models. Benchmark results for DeepSeek-R1 vs OpenAI-o1, as reported by DeepSeek, can be found in their technical report. […]

ShadowGenes: Uncovering Model Genealogy

Summary Model genealogy refers to the art and science of tracking the lineage and relationships of different machine learning models, leveraging information such as their origin, modifications over time, and sometimes even their training processes. This blog introduces a novel signature-based approach to identifying model architectures, families, close relations, and specific model types. This is […]

Reports & Guides

HiddenLayer Named a Cool Vendor in AI Security

AI Threat Landscape Report 2024

A Step-By-Step Guide for CISOS

SAI Security Advisory

CVE-2024-0129

NVIDIA NeMo Vulnerability Report

Unsafe extraction of NeMo archive leading to arbitrary file write CVE Number CVE-2024-0129 Summary The _unpack_nemo_file function used by the SaveRestoreConnector class for model loading uses tarfile.extractall() in an unsafe way which can lead to an arbitrary file write when a model is loaded. Products Impacted This vulnerability is present in Nvidia NeMo versions prior to r2.0.0rc0. CVSS Score: 6.3 AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L […]

CVE-2024-24590

Pickle Load on Artifact Get Leading to Code Execution

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

CVE-2024-24591

Path Traversal on File Download Leading to Arbitrary Write

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

CVE-2024-24592

Improper Auth Leading to Arbitrary Read-Write Access

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

CVE-2024-24593

Cross-site Request Forgery in ClearML Server

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

HiddenLayer in the News

Security for AI Platform Expansion: Introducing Automated Red Teaming for AI

Austin, TX — November 20, 2024 — HiddenLayer, a leader in security for AI solutions, today announced the launch of its Automated Red Teaming solution for artificial intelligence, a transformative tool that enables security teams to rapidly and thoroughly assess generative AI system vulnerabilities. The addition of this new product extends HiddenLayer’s AISec platform capabilities […]

HiddenLayer Recognized as a Gartner Cool Vendor for AI Security in 2024

Austin, TX – October 30, 2024 – HiddenLayer, a leader in security for AI solutions, is honored to be recognized as a Cool Vendor for AI Security in Gartner’s 2024 report. This prestigious distinction highlights HiddenLayer’s innovative approaches to safeguarding artificial intelligence models, data, and workflows against a rapidly evolving threat landscape. HiddenLayer’s proactive solutions […]

HiddenLayer Announces New Features to Safeguard Enterprise AI Models with Improved Risk Detection

Austin, TX – October 8, 2024 – HiddenLayer today announced the launch of several new features to its AISec Platform and Model Scanner, designed to enhance risk detection, scalability, and operational control for enterprises deploying AI at scale. As the pace of AI adoption accelerates, so do the threats targeting these systems, necessitating security measures […]