Poisoned models in fake Alibaba SDKs show challenges of securing AI supply chains

Poisoned models in fake Alibaba SDKs show challenges of securing AI supply chains

The attack campaign discovered by ReversingLabs involved three packages: aliyun-ai-labs-snippets-sdk, ai-labs-snippets-sdk, and aliyun-ai-labs-sdk. Together the three packages were downloaded 1,600 times, which is significant considering they were online for less than a day before they were discovered and taken down.

Developers’ computers are valuable targets because they typically contain a variety of credentials, API tokens, and other access keys to various cloud and local…

Article Source
https://www.csoonline.com/article/3998351/poisoned-models-hidden-in-fake-alibaba-sdks-show-challenges-of-securing-ai-supply-chains.html