RT by @_akhaliq: Happy to partner with @trufflesec to help them perform the largest secret scan of AI training data ever 🙏
TL;DR - Truffle Security reports finding 221,303 live unique credentials across 6,003 public Hugging Face datasets after scanning 7.6 PB of AI training data, highlighting substantial security risks in public datasets.
- Exposed secrets included cloud credentials, database access, and API keys.
- The leaked credentials represented an estimated $920,000 per year in API value.
- A single credential appeared across 1,131 datasets, showing how secrets can propagate through reused training data.
- Once compromised data enters training pipelines, removing its influence may be difficult or impossible.