Hugface uses open weight Z.ai GLM 5.2 to defend against attackers after rejection of commercial frontier model

Machine Learning


Hugging Face Inc., an open-source artificial intelligence platform often referred to as the “GitHub of machine learning,” found itself forced to use an open-weight model to respond to agent AI attacks after safety guardrails in commercial AI models blocked requests.

Last week, Hugging Face announced that it used an autonomous AI agent system to detect a breach by an attacker who had access to a limited set of internal data and some credentials used by internal services. The company responded defensively, cutting off the attackers and hardening its systems.

As part of the analysis, Hugging Face utilized Frontier AI models to assist with log analysis. This is a perfectly sensible option given that Hugging Face is the primary access point for many AI models.

But this failed. This type of analysis requires submitting vast amounts of actual attack data and commands, exploit payloads, and attack artifacts. These requests were blocked by the commercial Frontier AI model. Because that guardrail cannot differentiate between what is asked to build an exploit for an attacker and a defender trying to detect it.

Initially, due to the need for quick analysis and speed, the company switched to Z.ai Co. Ltd.’s GLM 5.2, a powerful open-weight model with approximately 753 billion parameters. Unlike third-party models, it can run entirely within a company’s secure firewall perimeter, on local or cloud hardware. This means that no data leaves your controlled infrastructure.

Chinese-made AI models such as GLM 5.2 and Beijing Moonshot AI Technology Co. Ltd.’s Kimi K3 have proven that open-source and open-weight models can reach or even rival the current pioneering and flagship frontier models built by US companies. GLM 5.2 reaches the capabilities of Anthropic PBC’s Fable 5, a Mythos class model that allows for advanced reasoning, coding, and even finding vulnerable code and exploits. It also achieves much lower inference costs than Anthropic.

However, to prevent abuse of these models, Anthropic and other leading closed-source AI developers have put in place strong safety guardrails. where it causes higher false positives. To avoid abuse. This significantly reduces their overall ability to be used in an effective cybersecurity role. Anthropic says the false positive rate has been adjusted to make the Frontier model safer for researchers to use.

Companies like Anthropic and OpenAI PBC Group have voluntarily imposed these limits on their most powerful models, but both Mythos 5 and Fable 5 were retired last month at the request of the US government shortly after their initial release. Similarly, the US government has asked OpenAI to postpone the release of its proprietary frontier model family, GPT 5.6, which is currently available to the public.

Tensions between China’s open source model and America’s closed source model

The recent release of Beijing-based Moonshot AI’s powerful near-frontier class open weight model, the Kimi K3, has fueled rumors that the Trump administration may ban U.S. companies from using Chinese-made open weight models.

According to Axios, some in the administration have previously attempted to effectively ban foreign open source models. This comes at a time when many U.S. companies are increasingly using open-weight models made in China. This is because open weight models made in China have low installation costs and are comparable to commercial-only models.

The United States does not need to completely ban the use of Chinese models. Instead, governments could use pressure campaigns to drive companies away, citing lack of security and governance. Sources said the U.S. Department of Commerce also considered the matter. Last year, we added several Chinese AI research institutes to the Entity List, This effectively cuts off access to companies without proper licenses.

“We are at a critical inflection point in AI policy. The large, closed labs, which already have a duopoly in terms of revenue from AI models, want the government to eliminate open source competition,” White House AI and Cryptocurrency Advisor David Sachs wrote on X (formerly Twitter) on Sunday.

In a two-part X post, Sachs referenced the recent Hug Face incident and added, “There’s no reason to limit American models to jobs that Chinese models can do just fine. We’re just making them less competitive.”

In his commentary, he said that Kimi K3 was able to fix 15 critical security bugs that OpenAI and Anthropic’s models could not fix due to “cyber guardrails.” The 15 bug fixes are claimed by developers who used the model, and while it is not a known benchmark, it is a focal point for developers to note that the Chinese model is becoming more mainstream than the US closed-source model. The developer added that everything also costs just $250. Comparing costs is difficult if not impossible without knowing the exact work done, but the Kimi K3 costs about a third of the Fable 5.

Of course, if Fable 5 refuses to do the work, the price difference doesn’t matter.

Chinese President Xi Jinping noted that the world was beginning to look to that model and called for global cooperation.

“The development of artificial intelligence should not be a solo performance by one country, but a symphony of global cooperation,” Xi said at the opening ceremony of China’s annual World Artificial Intelligence Conference in Shanghai.

In his speech, he called for opposition to the “overextension of the concept of national security” in relation to AI. Until now, China has been blocked from using some cutting-edge AI in the United States, and its cutting-edge AI chips have also been restricted.

China intends to expand AI cooperation with the Association of Southeast Asian Nations, League of Arab States, African Union, Community of Latin American and Caribbean States, Shanghai Cooperation Organization, and BRICS countries.

Mr. Xi said that in the next five years, China will provide 5,000 AI training opportunities to developing countries. He also said that 30 countries would be provided access to weather tools developed by China for early warning systems.

Image: SiliconANGLE/Microsoft Designer

Support our mission of keeping content open and free by joining the theCUBE community. Join theCUBE’s Alumni Trust Networka place where technology leaders connect, share intelligence, and create opportunities.

  • over 15 million viewers of theCUBE videospowering conversations across AI, cloud, cybersecurity, and more
  • 11.4k+ theCUBE Alumni — Connect with over 11,400 technology and business leaders who are shaping the future through our trusted, unique network.

About SiliconANGLE Media

SiliconANGLE Media is a recognized leader in digital media innovation that brings together breakthrough technology, strategic insight, and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI, and theCUBE SuperStudios, with flagship locations in Silicon Valley and the New York Stock Exchange, SiliconANGLE Media operates at the intersection of media, technology, and AI.

Founded by technology visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach more than 15 million elite technology professionals. Our new, proprietary theCUBE AI Video Cloud leverages theCUBEai.com neural networks to deliver breakthrough advances in audience interaction, helping technology companies make data-driven decisions and stay at the forefront of industry conversations.



Source link