Research · curated 1 Aug 2026
Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust
First reported paloaltonetworks.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Model Namespace Reuse shows that referencing AI models by name alone is an untrusted supply-chain dependency, letting attackers hijack abandoned namespaces to serve malicious models into major cloud AI platforms and downstream applications.
Unit 42 researchers Itay Saraf and Ofir Balassiano disclose "Model Namespace Reuse," an AI supply-chain attack that exploits trust in Hugging Face model names (Author/ModelName). When an original author deletes an account or transfers ownership, an attacker can re-register the abandoned namespace and publish a malicious model under the same trusted name, achieving code execution in systems that pull models by name, including Google Vertex AI and Microsoft Azure AI Foundry.