Hugging Face [Photo: Shutterstock]

Hugging Face used the open-weights GLM 5.2 model from Chinese AI company Z.ai to analyse an internal security breach, instead of a commercial frontier AI model.

SiliconANGLE reported on July 20 that Hugging Face used GLM 5.2 because safeguards in commercial models blocked analysis requests containing real attack logs, commands, exploit payloads and traces of the attack.

Hugging Face said it confirmed last week that an attacker using an autonomous AI agent system accessed internal datasets and some credentials for internal services. It then blocked the attacker and strengthened its systems.

In the incident analysis stage, it tried to use a frontier model for log analysis but failed. Because security analysis requires inputting large volumes of real attack data, safeguards in commercial models could not distinguish between defensive analysis and requests to create exploits for attacks.

Hugging Face then switched to GLM 5.2, a model with about 753 billion parameters. It can be run directly inside the company or within cloud infrastructure firewalls, so data does not leave controlled infrastructure.

SiliconANGLE said the case shows the difference between closed commercial models and open-weights models in the security field. Developers of closed AI models such as Anthropic have strong safeguards to prevent misuse, which can increase false positives even in legitimate cybersecurity work. Anthropic said it is adjusting false-positive rates so researchers can use frontier models more safely.

Keyword

#Hugging Face #Z.ai #GLM 5.2 #SiliconANGLE #Anthropic
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.