The world's largest AI open-source community, Hugging Face, recently disclosed that its servers were attacked by a hacker AI agent. After the incident, the security team first attempted to use an API from a U.S. commercial cutting-edge large model to analyze over 17,000 logs related to the attack. However, due to the model's inability to accurately distinguish between incident response personnel and attackers, the security protection mechanism misclassified the requests and refused to provide analysis support.
Subsequently, Hugging Face deployed the Chinese open-source model GLM5.2 on its own infrastructure to conduct forensic analysis on the massive security logs and successfully completed the incident investigation.
This incident highlights that as AI agents increasingly participate in cyber attacks, security analysis now demands higher levels of understanding, reasoning, and deployment capabilities from large models. Compared to relying on cloud-based commercial APIs, locally deployed open-source models offer greater flexibility in terms of data security, access control, and task customization, and avoid analysis interruptions caused by platform security policies.
