We’re excited to announce a new collaboration between Hugging Face and VirusTotal , the world’s leading threat-intelligence and malware analysis platform. This collaboration enhances the security of files shared across the Hugging Face Hub, helping protect the machine learning community from malicious or compromised assets.
TL;DR - Starting today, every one of the 2.2M+ public model and datasets repositories on the Hugging Face Hub is being continuously scanned with VirusTotal.
AI models are powerful but they’re also complex digital artifacts that can include large binary files, serialized data, and dependencies that sometimes carry hidden risks. As of today HF Hub hosts 2.2 Million Public model artifacts. As we continue to grow into the world’s largest open platform for Machine Learning models and datasets, ensuring that shared assets remain safe is essential.
By collaborating with VirusTotal, we’re adding an extra layer of protection and visibility by enabling files shared through Hugging Face to be checked against one of the largest and most trusted malware intelligence databases in the world.
Whenever you visit a repository page or a file or directory page, the Hub will automatically retrieve VirusTotal information about the corresponding files. Example
If a file hash has been previously analyzed by VirusTotal, its status (clean or malicious) is retrieved.
No raw file contents are shared with VirusTotal maintaining user privacy and compliance with Hugging Face’s data protection principles.
Results include metadata such as detection counts, known-bad relationships, or associated threat-campaign intelligence where relevant.
This provides valuable context to users and organizations before they download or integrate files from the Hub.
Source link







