Guide · AI security
Security risks of running LLMs locally
Running a large language model locally can be a security threat, though a different one from using a hosted service. Prompts stop going to a provider. In exchange, you load a model file from someone else, run a local server that often has no authentication, and take on whatever behaviour the model's uploader built in. Prompt injection is unchanged, and hallucinated output does not go away.
Last reviewed
What running locally takes off the table
One exposure goes away. When the model runs on your own hardware, the prompt and the answer do not travel to a provider. Ollama’s FAQ puts it plainly: “We don’t see your prompts or data when you run locally.” That is the vendor’s statement about its own software, and it covers local models only; for its cloud-hosted models, the same FAQ says Ollama processes prompts to provide the service but does not store, log or train on them.
If the worry that brought you here is a provider seeing your data at all, running locally answers it. It does not answer the rest.
What running locally puts on your machine
A file from someone else that your software parses. A local model is a file you downloaded. Hugging Face warns that pickle, “the default format for PyTorch model weights”, can run arbitrary code when loaded. Attackers have tried it: in February 2025 ReversingLabs reported two models on Hugging Face whose pickle files carried a reverse shell, a payload that hands the attacker a command line on the machine that loads it. ReversingLabs judged them closer to a proof of concept than a campaign. GGUF, the binary format that llama.cpp and similar runners load, is not pickle, but the loader still has to parse it. In January 2024 a Databricks researcher found memory corruption bugs in GGML’s GGUF parser that a crafted file could use to run code on the victim’s machine; they were patched within a week. Separately, researchers from Pillar Security and Fujitsu Research of Europe showed that a GGUF file’s chat template, the logic that builds the prompt the model sees, can be poisoned to change what the model does without touching the weights. The broader pattern is unsafe AI artifacts.
A server. Local runners serve an HTTP API so other programs can use the model. Ollama binds it to 127.0.0.1:11434 by default, reachable only from the same machine. One environment variable changes that. Wiz wrote in June 2024 that Ollama “does not support authentication out-of-the-box”. In June 2024 Wiz disclosed CVE-2024-37032: a malicious model registry could make Ollama’s model-pull endpoint overwrite files anywhere on the server, which Wiz turned into remote code execution. It was fixed in version 0.1.34. Wiz noted that the Docker image ran as root and listened on all interfaces by default. Its scan found over 1,000 Ollama servers exposed to the internet. In September 2025 Cisco researchers, searching the Shodan index of internet-connected devices, reported over 1,100, about 20% of them actively hosting models open to unauthorized access.
The model’s behaviour. Locally, you run whatever the uploader shipped. Hubinger and colleagues trained models to write secure code when told the year was 2023 and exploitable code when told it was 2024. They found such a backdoor attack can be made to survive standard safety training, including supervised fine-tuning, reinforcement learning and adversarial training, most of all in the largest models. Refusals are a weak safeguard once someone holds an open weight model’s weights: Arditi and colleagues report that their method “can yield a jailbroken version of a 70B parameter model using less than $5 of compute”. How completely it worked varied by model, and for Llama-2 models by whether the default system prompt was used. Abliterated and uncensored models are ones where the uploader already did that on purpose.
What running locally does not fix
Prompt injection. Greshake and colleagues argue that applications built on language models “blur the line between data and instructions”, and indirect prompt injection exploits that by planting instructions in data the application retrieves. Nothing about it depends on where the model runs. A local model that reads email, web pages or files, or that can call tools, can be steered by text planted in them.
Hallucinated output. Running locally does not make a model more accurate, and it may make it less so. Spracklen and colleagues generated 576,000 code samples in two programming languages from 16 models. Commercial models hallucinated at least 5.2% of package names on average, open-source models 21.7%. The paper compares open-source and commercial models, not local and hosted deployment, so read it as a caution rather than a measurement of local use. A hallucinated package name is what slopsquatting exploits.
What to do about it
- Treat a model file as software you are installing. Hugging Face’s advice is to load models from users and organizations you trust and rely on signed commits. Prefer a format built not to run code, such as safetensors, which its maintainers describe as storing tensors “safely (as opposed to pickle)”.
- Keep the runner patched. Both the Ollama and GGUF bugs above were fixed in updates; an old runner still has them.
- Keep the API on localhost. If other machines need it, put it behind a reverse proxy that authenticates, which is Wiz’s advice. Check what a container publishes, not only what the runner binds.
- Treat what the model reads and writes as untrusted, as you would with a hosted model. Limit the tools it can call.
What does not work
Relying on the hub’s scanner. Hugging Face checks pickle files with Picklescan, which works from a blocklist of dangerous functions. Picklescan did not flag the two models ReversingLabs reported. ReversingLabs says their 7z compression is “likely the reason”, and that their broken pickle files exposed a second gap, which Hugging Face then patched. A blocklist only catches what is already on the list.
Trusting a model because it passed safety training. The Sleeper Agents authors found that adversarial training could teach a backdoored model to recognise its trigger better, “effectively hiding the unsafe behavior”.
Assuming local means private to the machine. A runner bound to all interfaces, or a container with its port published, is a network service, and Wiz’s scan and Cisco’s Shodan search each found over a thousand Ollama servers open to the internet.
Questions and answers
Is running an LLM locally safer than using ChatGPT or another hosted service?
Safer for one thing, riskier for others. Running locally keeps prompts off a provider's servers. It also means loading a model file you downloaded, running an inference server on your own machine, and taking on whatever behaviour the model's uploader built in. The first two have had real, exploitable vulnerabilities, and researchers have shown the third can hide a backdoor. Prompt injection works the same either way, and local models are not less prone to hallucination.
Can a downloaded model file contain malware?
Yes. Hugging Face warns that loading a pickle file, the default format for PyTorch weights, can execute arbitrary code, and in February 2025 ReversingLabs reported two models on Hugging Face carrying a reverse shell payload, which it judged closer to a proof of concept. GGUF files are not pickle, but in January 2024 a Databricks researcher found memory corruption bugs in the library that parses them, which a crafted file could exploit to run code.
Sources
- Ollama FAQOllama
- Pickle ScanningHugging Face
- Malicious ML models discovered on Hugging Face platformReversingLabs, 6 Feb 2025
- GGML GGUF File Format VulnerabilitiesNeil Archibald, Databricks, 22 Mar 2024
- MITRE ATLAS, AML.CS0064 Poisoned GGUF Templates: Inference-Time Supply Chain Attack (collection 2026.09)MITRE
- Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032)Sagi Tzadik, Wiz, 24 Jun 2024
- Detecting Exposed LLM Servers: A Shodan Case Study on OllamaGiannis Tziakouris and Elio Biasiotto, Cisco, 1 Sep 2025
- Sleeper Agents: Training Deceptive LLMs that Persist Through Safety TrainingHubinger et al., Jan 2024
- Refusal in Language Models Is Mediated by a Single DirectionArditi et al., NeurIPS 2024, Jun 2024
- safetensorsHugging Face
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt InjectionGreshake et al., Feb 2023
- We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMsSpracklen et al., USENIX Security 2025, Jun 2024