How to Secure AI/ML Model Downloads with Hugging Face Proxying

Intermediate 20 minutes Security Engineers / ML Engineers Security & Policy

Route Hugging Face model downloads through Chainsaw, apply supply chain policies to ML artifacts, and monitor AI model consumption.

Overview

AI/ML models from Hugging Face are a growing part of the software supply chain. Models can contain serialized code (pickle files), malicious weights, or backdoors that execute during inference. Chainsaw supports proxying Hugging Face downloads, giving you the same supply chain visibility and policy enforcement for ML models as for traditional packages.

Prerequisites

  • A running Chainsaw instance with the Hugging Face repository enabled
  • Client credentials for accessing the Hugging Face repository
  • ML engineers or pipelines that download models from Hugging Face

Step 1: Enable the Hugging Face Repository

Navigate to Repositories and verify that the Hugging Face mirror is enabled:

SettingValue
Repository Namehuggingface
Upstreamhuggingface.co
FormatHugging Face
StatusEnabled
Hugging Face repository in Chainsaw
The Hugging Face repository mirrors model downloads through Chainsaw

Step 2: Configure the Hugging Face Client

Environment Variable

Point the Hugging Face client libraries at Chainsaw:

export HF_ENDPOINT=https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/huggingface/

Python (transformers library)

import os
os.environ["HF_ENDPOINT"] = "https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/huggingface/"

from transformers import AutoModel, AutoTokenizer

model = AutoModel.from_pretrained("bert-base-uncased")
tokenizer = AutoTokenizer.from_pretrained("bert-base-uncased")

CLI (huggingface-cli)

HF_ENDPOINT=https://chain305.com/chainproxy/repository/@default/huggingface/ \
  huggingface-cli download meta-llama/Llama-2-7b
Configuring HF_ENDPOINT
Set the HF_ENDPOINT environment variable to route through Chainsaw

Large weights (LFS) and git clone

huggingface-cli download and from_pretrained() use the standard Hub HTTPS API and are fully handled by HF_ENDPOINT alone. For workflows that pull weights via git clone against a HF model repo, both git smart-HTTP (git-upload-pack) and the LFS object protocol route through the proxy transparently as of the 2026-05 HF fix — no extra client config beyond HF_ENDPOINT is needed.

Sanity check that passthrough is live:

curl -sI "${HF_ENDPOINT%/}/api/models/bert-base-uncased"
# Expect HTTP/2 200 (or 401 if the credential is wrong); HTTP 404 means
# the HF repo isn't enabled or HF_ENDPOINT points at the wrong path.

If you need to override git’s resolver explicitly (rare — only when a tool ignores HF_ENDPOINT and hits huggingface.co directly), add a per-repo rewrite:

git config --global url."${HF_ENDPOINT%/}".insteadOf "https://huggingface.co"
For CI/CD pipelines that download models, create a dedicated service token with access limited to the Hugging Face repository only.

Step 3: Apply Policies to ML Models

Create policies specific to the Hugging Face repository:

Block Untrusted Models

  1. Name: Block Low-Trust HF Models
  2. Action: Block
  3. Condition: Trust Score < 40
  4. Scope: Hugging Face repository only
Trust score policy for Hugging Face
Apply trust score policies to ML model downloads

Quarantine New Models

  1. Name: Quarantine New HF Models
  2. Action: Quarantine
  3. Condition: Package Age < 30 days
  4. Scope: Hugging Face repository only

Restrict to Known Model Publishers

Use a hook script to allowlist trusted model publishers:

#!/bin/bash
# /opt/chainsaw/hooks/hf-publisher-check.sh

ALLOWED_PUBLISHERS="/opt/chainsaw/hooks/approved-hf-publishers.txt"

# Extract publisher from package name (format: publisher/model-name)
PUBLISHER=$(echo "$CHAINSAW_PACKAGE" | cut -d'/' -f1)

if grep -q "^${PUBLISHER}$" "$ALLOWED_PUBLISHERS"; then
    exit 0
fi

echo "BLOCKED: Hugging Face publisher '${PUBLISHER}' not in approved list"
exit 1

Approved publishers file:

meta-llama
google
microsoft
openai
mistralai
stabilityai
Publisher allowlist for Hugging Face
Restrict model downloads to approved Hugging Face publishers

Step 4: Monitor ML Model Consumption

Navigate to the Traffic page and filter by the Hugging Face repository:

Hugging Face traffic in Chainsaw
Monitor model download patterns through the Hugging Face repository

Track:

  • Which models are being downloaded
  • Which teams/pipelines are consuming them
  • Download frequency and cache hit ratio
  • Any policy violations

Step 5: View ML Models in the Bill of Materials

ML models appear in the BOM alongside traditional packages:

Hugging Face models in the BOM
ML models are tracked in the Bill of Materials with supply chain metadata

Each model entry includes:

  • Model name and version/revision
  • Publisher
  • Trust score
  • Download count and last access
  • PURL format: pkg:huggingface/meta-llama/Llama-2-7b

Step 6: SBOM Integration for ML Models

When you export an SBOM, Hugging Face models are included as components:

{
  "type": "library",
  "name": "meta-llama/Llama-2-7b",
  "version": "main",
  "purl": "pkg:huggingface/meta-llama/Llama-2-7b",
  "properties": [
    { "name": "chainsaw:ecosystem", "value": "huggingface" }
  ]
}

This gives compliance teams visibility into which ML models are part of your software supply chain.

Regulators are increasingly interested in AI model provenance. Including ML models in your SBOM gets ahead of emerging AI compliance requirements.

Step 7: AI Model Supply Chain Risks

RiskDescriptionChainsaw Mitigation
Malicious weightsModel weights contain backdoorsTrust score, publisher allowlist
Pickle exploitsSerialized Python objects execute code on loadFreshness guards, quarantine
Model poisoningTraining data manipulationPublisher verification, provenance
License violationsModels with restrictive licenses used commerciallyLicense compliance policies
Shadow AIUnauthorized model downloadsTraffic monitoring, client scoping

Best Practices

PracticeReason
Allowlist approved publishersLimit to trusted model sources
Quarantine new modelsReview before adoption
Track in BOM/SBOMCompliance and inventory
Separate credentials for ML pipelinesIsolate ML traffic for policy targeting
Cache popular modelsFaster inference pipeline starts
Monitor download sizesLarge models impact storage and bandwidth

Next Steps