Experten finden Fehler in Replicate AI Service, der Modelle und Daten von Kunden offenlegt

Teilen:

Cybersecurity researchers have discovered a critical security flaw in an artificial intelligence (AI)-as-a-service provider Replicate that could have allowed threat actors to gain access to proprietary AI models and sensitive information.

“Exploitation of this vulnerability would have allowed unauthorized access to the AI prompts and results of all Replicate’s platform customers,” cloud security firm Wiz said in a report published this week.

The issue stems from the fact that AI models are typically packaged in formats that allow arbitrary code execution, which an attacker could weaponize to perform cross-tenant attacks by means of a malicious model.

Cybersecurity
Replicate makes use of an open-source tool called Cog to containerize and package machine learning models that could then be deployed either in a self-hosted environment or to Replicate.

Wiz said that it created a rogue Cog container and uploaded it to Replicate, ultimately employing it to achieve remote code execution on the service’s infrastructure with elevated privileges.

“We suspect this code-execution technique is a pattern, where companies and organizations run AI models from untrusted sources, even though these models are code that could potentially be malicious,” security researchers Shir Tamari and Sagi Tzadik said.

The attack technique devised by the company then leveraged an already-established TCP connection associated with a Redis server instance within the Kubernetes cluster hosted on the Google Cloud Platform to inject arbitrary commands.

What’s more, with the centralized Redis server being used as a queue to manage multiple customer requests and their responses, the researchers found that it could be abused to facilitate cross-tenant attacks by tampering with the process in order to insert rogue tasks that could impact the results of other customers’ models.

These rogue manipulations not only threaten the integrity of the AI models, but also pose significant risks to the accuracy and reliability of AI-driven outputs.

“An attacker could have queried the private AI models of customers, potentially exposing proprietary knowledge or sensitive data involved in the model training process,” the researchers said. “Additionally, intercepting prompts could have exposed sensitive data, including personally identifiable information (PII).

Cybersecurity
The shortcoming, which was responsibly disclosed in January 2024, has since been addressed by Replicate. There is no evidence that the vulnerability was exploited in the wild to compromise customer data.

The disclosure comes a little over a month after Wiz detailed now-patched risks in platforms like Hugging Face that could allow threat actors to escalate privileges, gain cross-tenant access to other customers’ models, and even take over the continuous integration and continuous deployment (CI/CD) pipelines.

“Malicious models represent a major risk to AI systems, especially for AI-as-a-service providers because attackers may leverage these models to perform cross-tenant attacks,” the researchers concluded.

“The potential impact is devastating, as attackers may be able to access the millions of private AI models and apps stored within AI-as-a-service providers.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:36 am, Juni 27, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
overcast clouds
Luftfeuchtigkeit: 86 %
Druck: 1020 mb
Wind: 2 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 1 mm 100% 13 mph 85 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 11 mph 91 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
18° | 32°°C 0 mm 0% 6 mph 78 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
22° | 36°°C 0.2 mm 20% 8 mph 65 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 31°°C 0 mm 0% 9 mph 70 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
14° | 15°°C 1 mm 100% 7 mph 85 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 21°°C 0 mm 0% 11 mph 69 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 12 mph 54 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 13 mph 39 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 13 mph 38 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 10 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 91 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,807.31
-0.54%
Ethereum(ETH)
€2,088.98
-2.12%
Fesseln(USDT)
€0.86
-0.02%
XRP(XRP)
€1.80
-4.28%
Solana(SOL)
€120.84
-3.57%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.138749
-2.50%
Shiba Inu(SHIB)
€0.000009
-3.35%
Pepe(PEPE)
€0.000008
-3.94%
Nach oben scrollen