{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T12:59:07Z","timestamp":1761569947706,"version":"build-2065373602"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","funder":[{"name":"The National NSF of China","award":["grants No.62072046"],"award-info":[{"award-number":["grants No.62072046"]}]},{"name":"The Key R&D Program of Hubei Province","award":["2023BAB017, 2023BAB079"],"award-info":[{"award-number":["2023BAB017, 2023BAB079"]}]},{"name":"The Knowledge Innovation Program of Wuhan-Basic Research","award":["2022010801010083"],"award-info":[{"award-number":["2022010801010083"]}]},{"name":"The Xiaomi Young Talents Program","award":["\\\\"],"award-info":[{"award-number":["\\\\"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,20]]},"DOI":"10.1145\/3755881.3755921","type":"proceedings-article","created":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T11:46:17Z","timestamp":1761565577000},"page":"498-509","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Exploring Typo Squatting Threats in the Hugging Face Ecosystem"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-1750-3187","authenticated-orcid":false,"given":"Ningyuan","family":"Li","sequence":"first","affiliation":[{"name":"Beijing University of Technology, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8793-5367","authenticated-orcid":false,"given":"Yanjie","family":"Zhao","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3818-3343","authenticated-orcid":false,"given":"Shenao","family":"Wang","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2362-0821","authenticated-orcid":false,"given":"Zehao","family":"Wu","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1100-8633","authenticated-orcid":false,"given":"Haoyu","family":"Wang","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}]}],"member":"320","published-online":{"date-parts":[[2025,10,27]]},"reference":[{"key":"e_1_3_3_1_2_2","volume-title":"22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Diego, California, USA, February 8-11, 2015","author":"Agten Pieter","year":"2015","unstructured":"Pieter Agten, Wouter Joosen, Frank Piessens, and Nick Nikiforakis. 2015. Seven Months\u2019 Worth of Mistakes: A Longitudinal Study of Typosquatting Abuse. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Diego, California, USA, February 8-11, 2015. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss2015\/seven-months-worth-mistakes-longitudinal-study-typosquatting-abuse"},{"key":"e_1_3_3_1_3_2","unstructured":"Baidu AI. 2025. PaddlePaddle Model Hub. https:\/\/www.paddlepaddle.org.cn. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_4_2","unstructured":"Beatrice Casey Joanna Santos and Mehdi Mirakhorli. 2024. A Large-Scale Exploit Instrumentation Study of AI\/ML Supply Chain Attacks in Hugging Face Models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2410.04490 (2024)."},{"key":"e_1_3_3_1_5_2","unstructured":"Catalin Cimpanu. 2018. Twelve malicious Python libraries found and removed from PyPi. (2018)."},{"key":"e_1_3_3_1_6_2","unstructured":"Thomas Claburn. 2017. This typosquatting attack on npm went undetected for 2 weeks. https:\/\/www.theregister.com\/2017\/08\/02\/typosquatting_npm\/."},{"key":"e_1_3_3_1_7_2","unstructured":"Liandanxia Community. 2025. Liandanxia Repository. https:\/\/liandanxia.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_8_2","unstructured":"ONNX Community. 2025. ONNX Model Zoo. https:\/\/onnx.ai\/models. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_9_2","unstructured":"OpenCSG Community. 2025. OpenCSG Model Hub. https:\/\/opencsg.org. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_10_2","unstructured":"NVIDIA Corporation. 2025. NVIDIA NGC Catalog. https:\/\/ngc.nvidia.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_11_2","unstructured":"Allan Dafoe. 2018. AI governance: a research agenda. Governance of AI Program Future of Humanity Institute University of Oxford: Oxford UK 1442 (2018) 1443."},{"key":"e_1_3_3_1_12_2","unstructured":"PyTorch Developers. 2025. PyTorch Hub. https:\/\/pytorch.org\/hub. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_13_2","unstructured":"John\u00a0E Dunn. 2017. Pypi python repository hit by typosquatting sneak attack. Retrieved July 28 (2017) 2021."},{"key":"e_1_3_3_1_14_2","unstructured":"Ahmed Hosny Michael Schwier Christoph Berger Evin\u00a0P \u00d6rnek Mehmet Turan Phi\u00a0V Tran Leon Weninger Fabian Isensee Klaus\u00a0H Maier-Hein Richard McKinley et\u00a0al. 2019. Modelhub. ai: Dissemination platform for deep learning models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1911.13218 (2019)."},{"key":"e_1_3_3_1_15_2","unstructured":"Huawei. 2025. MindSpore Model Zoo. https:\/\/www.mindspore.cn\/resources\/models. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_16_2","unstructured":"Wenxin Jiang Chingwo Cheung Mingyu Kim Heesoo Kim George\u00a0K Thiruvathukal and James\u00a0C Davis. 2024. Naming Practices of Pre-Trained Models in Hugging Face. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2310.01642 (2024)."},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564547"},{"key":"e_1_3_3_1_18_2","unstructured":"Kaggle. 2025. Kaggle Datasets and Models Hub. https:\/\/www.kaggle.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_19_2","unstructured":"John\u00a0Snow Labs. 2025. Spark NLP Model Hub. https:\/\/nlp.johnsnowlabs.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_20_2","unstructured":"Yo-Seob Lee. 2023. Analysis of AI Model Hub. International Journal of Advanced Culture Technology 11 4 (2023) 442\u2013448."},{"key":"e_1_3_3_1_21_2","first-page":"35","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Liu Guannan","year":"2022","unstructured":"Guannan Liu, Xing Gao, Haining Wang, and Kun Sun. 2022. Exploring the Unchartered Space of Container Registry Typosquatting. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, 35\u201351. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/liu-guannan"},{"key":"e_1_3_3_1_22_2","unstructured":"ModelZoo. 2025. ModelZoo Repository. https:\/\/modelzoo.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_23_2","first-page":"3439","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Neupane Shradha","year":"2023","unstructured":"Shradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson, and Lorenzo\u00a0De Carli. 2023. Beyond Typosquatting: An In-depth Look at Package Confusion. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 3439\u20133456. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/neupane"},{"key":"e_1_3_3_1_24_2","unstructured":"OpenAI. 2024. ChatGPT-4: OpenAI\u2019s Conversational Language Model. https:\/\/openai.com Accessed: 2025-01-15."},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"crossref","unstructured":"Xipeng Qiu Tianxiang Sun Yige Xu Yunfan Shao Ning Dai and Xuanjing Huang. 2020. Pre-trained models for natural language processing: A survey. Science China technological sciences 63 10 (2020) 1872\u20131897.","DOI":"10.1007\/s11431-020-1647-3"},{"key":"e_1_3_3_1_26_2","unstructured":"Yongliang Shen Kaitao Song Xu Tan Dongsheng Li Weiming Lu and Yueting Zhuang. 2024. Hugginggpt: Solving ai tasks with chatgpt and its friends in hugging face. Advances in Neural Information Processing Systems 36 (2024)."},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132465.3132467"},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131399"},{"key":"e_1_3_3_1_29_2","first-page":"191","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Szurdi Janos","year":"2014","unstructured":"Janos Szurdi, Balazs Kocso, Gabor Cseh, Jonathan Spring, Mark Felegyhazi, and Chris Kanich. 2014. The Long \u201cTaile\u201d of Typosquatting Domain Names. In 23rd USENIX Security Symposium (USENIX Security 14). USENIX Association, San Diego, CA, 191\u2013206. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/szurdi"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"crossref","unstructured":"Mina Taraghi Gianolli Dorcelus Armstrong Foundjem Florian Tambon and Foutse Khomh. 2024. Deep learning model reuse in the huggingface community: Challenges benefit and trends. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2401.13177 (2024).","DOI":"10.1109\/SANER60148.2024.00059"},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"crossref","unstructured":"Matthew Taylor. 2020. Defending Against Typosquatting Attacks In Programming Language-Based Package Repositories. Master\u2019s thesis. University of Kansas.","DOI":"10.1007\/978-3-030-65745-1_7"},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65745-1_7"},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"crossref","unstructured":"Matthew Taylor Ruturaj\u00a0K Vaidya Drew Davidson Lorenzo De\u00a0Carli and Vaibhav Rastogi. 2020. Spellbound: Defending against package typosquatting. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2003.03471 (2020).","DOI":"10.1007\/978-3-030-65745-1_7"},{"key":"e_1_3_3_1_34_2","unstructured":"ModelScope Team. 2025. ModelScope Hub. https:\/\/modelscope.cn. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_35_2","unstructured":"OpenMMLab Team. 2025. OpenMMLab Model Hub. https:\/\/openmmlab.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_36_2","unstructured":"SwanHub Team. 2025. SwanHub Model Repository. https:\/\/swanhub.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/EUROSPW51379.2020.00074"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00074"},{"key":"e_1_3_3_1_39_2","unstructured":"Shenao Wang Yanjie Zhao Xinyi Hou and Haoyu Wang. 2024. Large language model supply chain: A research agenda. ACM Transactions on Software Engineering and Methodology (2024)."},{"key":"e_1_3_3_1_40_2","unstructured":"WiseModel. 2025. WiseModel Repository. https:\/\/wisemodel.com. Accessed: 2025-01-14."},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"crossref","unstructured":"Thomas Wolf Lysandre Debut Victor Sanh Julien Chaumond Clement Delangue Anthony Moi Pierric Cistac Tim Rault R\u00e9mi Louf Morgan Funtowicz Joe Davison Sam Shleifer Patrick von Platen Clara Ma Yacine Jernite Julien Plu Canwen Xu Teven\u00a0Le Scao Sylvain Gugger Mariama Drame Quentin Lhoest and Alexander Rush. 2020. Transformers: State-of-the-art Natural Language Processing. https:\/\/huggingface.co. https:\/\/huggingface.co Accessed: 2025-01-13.","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3691620.3695271"}],"event":{"name":"Internetware 2025: the 16th International Conference on Internetware","sponsor":["SIGSOFT ACM Special Interest Group on Artificial Intelligence"],"location":"Trondheim Norway","acronym":"Internetware 2025"},"container-title":["Proceedings of the 16th International Conference on Internetware"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3755881.3755921","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T11:47:22Z","timestamp":1761565642000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3755881.3755921"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,20]]},"references-count":41,"alternative-id":["10.1145\/3755881.3755921","10.1145\/3755881"],"URL":"https:\/\/doi.org\/10.1145\/3755881.3755921","relation":{},"subject":[],"published":{"date-parts":[[2025,6,20]]},"assertion":[{"value":"2025-10-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}