Closed-Source Guardrails Hinder Forensics, HF Switches to Open Source

latticecut · x · 2026-07-20

This recounts Hugging Face's encounter with an AI-driven attack: during log analysis, they found that commercial closed-source models would block real attack commands, exploit payloads, and C2 traces due to safety guardrails, hindering forensics.

Ultimately, they switched to using the open-weights model GLM 5.2 deployed on their own infrastructure for analysis. This allowed them to complete the investigation without sensitive attack data ever leaving their internal environment.

Related event: HF Hit by AI Agent Attack, Open-Source Model Used After API Guardrails Block Forensics(25 posts)→

Original post →

More from Infra

Infra channel →