{"id":"https://openalex.org/W4388115877","doi":"https://doi.org/10.1109/isi58743.2023.10297271","title":"Assessing the Vulnerabilities of the Open-Source Artificial Intelligence (AI) Landscape: A Large-Scale Analysis of the Hugging Face Platform","display_name":"Assessing the Vulnerabilities of the Open-Source Artificial Intelligence (AI) Landscape: A Large-Scale Analysis of the Hugging Face Platform","publication_year":2023,"publication_date":"2023-10-02","ids":{"openalex":"https://openalex.org/W4388115877","doi":"https://doi.org/10.1109/isi58743.2023.10297271"},"language":"en","primary_location":{"id":"doi:10.1109/isi58743.2023.10297271","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi58743.2023.10297271","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE International Conference on Intelligence and Security Informatics (ISI)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Adhishree Kathikar","orcid":null},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Adhishree Kathikar","raw_affiliation_strings":["Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101584329","display_name":"Aishwarya Nair","orcid":"https://orcid.org/0000-0002-8620-5335"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Aishwarya Nair","raw_affiliation_strings":["Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021176237","display_name":"Ben Lazarine","orcid":"https://orcid.org/0000-0002-8793-9613"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ben Lazarine","raw_affiliation_strings":["Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067071536","display_name":"Agrim Sachdeva","orcid":"https://orcid.org/0000-0002-0843-5899"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Agrim Sachdeva","raw_affiliation_strings":["Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5038811607","display_name":"Sagar Samtani","orcid":"https://orcid.org/0000-0002-4513-805X"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sagar Samtani","raw_affiliation_strings":["Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington,Data Science and Artificial Intelligence Lab,Bloomington,IN","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Data Science and Artificial Intelligence Lab, Indiana University Bloomington, Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I4210119109"],"apc_list":null,"apc_paid":null,"fwci":9.643,"has_fulltext":false,"cited_by_count":22,"citation_normalized_percentile":{"value":0.9804777,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9908000230789185,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9908000230789185,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9721999764442444,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.9538999795913696,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7210232615470886},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.578801155090332},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5404525399208069},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.4952479898929596},{"id":"https://openalex.org/keywords/open-source","display_name":"Open source","score":0.4864234924316406},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.48037323355674744},{"id":"https://openalex.org/keywords/scale","display_name":"Scale (ratio)","score":0.4660908281803131},{"id":"https://openalex.org/keywords/vulnerability-assessment","display_name":"Vulnerability assessment","score":0.4370943307876587},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.3629438579082489},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3590039610862732},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.24065348505973816},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.12287512421607971},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.096398264169693},{"id":"https://openalex.org/keywords/cartography","display_name":"Cartography","score":0.08808121085166931}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7210232615470886},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.578801155090332},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5404525399208069},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.4952479898929596},{"id":"https://openalex.org/C3018397939","wikidata":"https://www.wikidata.org/wiki/Q3644502","display_name":"Open source","level":3,"score":0.4864234924316406},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.48037323355674744},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.4660908281803131},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.4370943307876587},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.3629438579082489},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3590039610862732},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.24065348505973816},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.12287512421607971},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.096398264169693},{"id":"https://openalex.org/C58640448","wikidata":"https://www.wikidata.org/wiki/Q42515","display_name":"Cartography","level":1,"score":0.08808121085166931},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C542102704","wikidata":"https://www.wikidata.org/wiki/Q183257","display_name":"Psychotherapist","level":1,"score":0.0},{"id":"https://openalex.org/C137176749","wikidata":"https://www.wikidata.org/wiki/Q4105337","display_name":"Psychological resilience","level":2,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isi58743.2023.10297271","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi58743.2023.10297271","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE International Conference on Intelligence and Security Informatics (ISI)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":7,"referenced_works":["https://openalex.org/W3033053557","https://openalex.org/W3111430790","https://openalex.org/W4308409913","https://openalex.org/W4320087033","https://openalex.org/W4361866031","https://openalex.org/W4384345640","https://openalex.org/W6851513886"],"related_works":["https://openalex.org/W1883246888","https://openalex.org/W2370114625","https://openalex.org/W2947584067","https://openalex.org/W2062873522","https://openalex.org/W1756374135","https://openalex.org/W3157230915","https://openalex.org/W3118510577","https://openalex.org/W2789975780","https://openalex.org/W2007895524","https://openalex.org/W2393340519"],"abstract_inverted_index":{"Artificial":[0],"Intelligence":[1],"(AI)":[2],"has":[3,30],"rapidly":[4],"proliferated":[5],"as":[6,156],"a":[7,81,108],"critical":[8],"disruptive":[9],"technology":[10],"in":[11,126,135,151],"the":[12,21,130,148,158],"21st":[13],"century.":[14],"Hugging":[15,28,46,68,97],"Face":[16,29,47,98],"hosts":[17],"pre-trained":[18],"models,":[19,52],"facilitating":[20],"sharing":[22],"and":[23,38,79,99,141,172],"use":[24],"of":[25,85,116,132,147,160],"open-source":[26],"code.":[27],"been":[31],"used":[32],"by":[33],"22,000+":[34],"organizations,":[35],"including":[36],"Intel":[37],"Microsoft,":[39],"with":[40],"2.6+":[41],"billion":[42],"model":[43],"downloads.":[44],"While":[45],"democratizes":[48],"access":[49],"to":[50,72,120],"AI":[51,153,173],"these":[53,86],"models":[54,66,95],"may":[55],"contain":[56],"unknown":[57],"security":[58,171],"vulnerabilities.":[59],"In":[60],"this":[61,161],"research,":[62],"we":[63,91],"automatically":[64],"collect":[65],"from":[67,96,138],"Face,":[69],"link":[70],"them":[71],"their":[73],"underlying":[74],"code":[75],"bases":[76],"on":[77],"GitHub,":[78],"perform":[80],"large-scale":[82],"vulnerability":[83,105,162],"assessment":[84,106,163],"repositories.":[87,103,143],"Through":[88],"our":[89],"approaches,":[90],"collected":[92],"about":[93],"110,000":[94],"over":[100],"29,000":[101],"GitHub":[102],"Our":[104],"revealed":[107],"larger":[109],"percentage":[110],"(35.98":[111],"<sup":[112],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[113],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">%</sup>":[114],")":[115],"high-severity":[117],"vulnerabilities":[118,122,149],"compared":[119],"low-severity":[121],"(6.79%).":[123],"This":[124],"trend":[125],"severity":[127],"levels":[128],"contradicts":[129],"results":[131,159],"severities":[133],"detected":[134],"repositories":[136,140,154],"forked":[137],"root":[139],"searched":[142],"Given":[144],"that":[145],"many":[146],"reside":[150],"fundamental":[152],"such":[155],"Transformers,":[157],"have":[164],"significant":[165],"implications":[166],"for":[167],"supply":[168],"chain":[169],"software":[170],"risk":[174],"management":[175],"more":[176],"broadly.":[177]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":10}],"updated_date":"2026-05-21T09:19:25.381259","created_date":"2025-10-10T00:00:00"}
