JFrog Ltd has announced a partnership with Hugging Face to bolster the security of machine learning (ML) models found on the Hugging Face Hub. This collaboration will implement enhanced security analyses for ML models, displaying a “JFrog Certified” checkmark to indicate those deemed safer for developers and data scientists to use.

Asaf Karas, CTO of JFrog Security, said, “As ML models become integral to critical business applications, ensuring these models are secure is crucial for preventing breaches, data leaks, and decision-making errors.” The partnership aims to alleviate security concerns related to ML model usage, especially after instances of malicious models were discovered in early 2024.

JFrog Xray and JFrog Advanced Security will now work in tandem with Hugging Face to provide detailed scans of AI/ML models within their ecosystem, allowing users to see the security status of a model before downloading it. This integration introduces a more sophisticated scanning process that focuses on identifying potentially harmful embedded codes, significantly reducing the number of false positives compared to existing solutions.

Survey data indicates that while 80% of enterprises are using AI applications, over 90% feel unprepared for the associated security challenges. Cybersecurity agencies have highlighted the importance of careful scanning for harmful code, emphasizing the potential risks of compromised ML models.

Julien Chaumond, CTO of Hugging Face, remarked on the partnership's significance, stating, “As the leading collaboration platform for AI models, we’re delighted to deepen our partnership with JFrog to implement high-quality scanning capabilities for our AI/ML models.” This integration serves to address the growing security needs of organizations leveraging AI technologies.