ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil
Thu 16 Apr 2026 14:15 - 14:30 at Oceania I - Analytics 3 Chair(s): Mali Izadi

Hugging Face Spaces (Spaces) has become a leading platform for hosting AI applications, offering developers seamless integration of Git-based repositories and out-of-the-box web service deployment. However, as its adoption continues to expand, security concerns have come to light. Recent reports have pointed to the issue of accidental exposure of sensitive information, such as API tokens and database credentials, within Spaces-hosted code. Despite these concerns, the research community still lacks a comprehensive understanding of the scope and impact of these security risks. To bridge this gap, we present the first large-scale and systematic empirical study to quantify the extent of secret leakage in Spaces. We begin by compiling a comprehensive dataset of 313,647 public Spaces repositories created between March 2022 and December 2024. To detect exposed secrets, we introduce Secret Reviewer, an advanced framework that combines static analysis and Large Language Model (LLM)-assisted detection to identify leaked credentials. Applying Secret Reviewer, we identified 9,149 with secret leakage vulnerabilities and 11,557 unique keys—76% of which from leading AI service providers such as OpenAI and Groq. Our findings indicate that 30% of leaks were embedded in commit histories, and over 1,000 non-code files contained sensitive data. Further validation revealed that 30% of detected keys remained active, including 140 valid database credentials and 50% of access tokens with write permissions, underscoring significant security risks. Our study sheds light on critical security challenges in AI platform ecosystems and advocates for stronger security practices to mitigate these risks.

Presentation PPT (ICSE26-SecretLeakge-ShaoxuanYun.pdf)2.21MiB

Thu 16 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

14:00 - 15:30
14:00
15m
Talk
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
Research Track
Wenbo Guo Nanyang Technological University, Chengwei Liu Nankai University, Limin Wang Nanjing University, Yiran Zhang , Wu Jiahui , Zhengzi Xu Imperial Global Singapore, Yang Liu Nanyang Technological University
Pre-print
14:15
15m
Talk
A Large-Scale Empirical Study of Secret Key Leakage in Hugging Face SpacesVirtual Attendance
Research Track
Shaoxuan Yun Beijing University of Posts and Telecommunications, Yuchao Zhang Beijing University of Posts and Telecommunications, Zhikun Shi Beijing University of Posts and Telecommunications, Liu Wang Huazhong University of Science and Technology, Yi Wang Beijing University of Posts and Telecommunications, Yu Bai Beijing University of Posts and Telecommunications
Media Attached File Attached
14:30
15m
Talk
A Comprehensive Study of Concurrency Bugs in the Linux KernelVirtual Attendance
Research Track
Sishuai Gong University of North Carolina at Chapel Hill, Chih-En Lin Purdue University, Kevin Wu Purdue University, Edwin Lu Purdue University, Pedro Fonseca Purdue University
Pre-print
14:45
15m
Talk
Shaky Structures: The Wobbly World of Causal Graphs in Software Analytics
Journal-first Papers
Jeremy Hulse NC State, Tim Menzies North Carolina State University, Nasir Eisty University of Tennessee-Knoxville
Link to publication Pre-print
15:00
15m
Talk
Beyond Final Code: A Process-Oriented Error Analysis of Software Development Agents in Real-World GitHub Scenarios
Research Track
Zhi Chen Singapore Management University, Wei Ma Singapore Management University, Lingxiao Jiang Singapore Management University
Pre-print
15:15
15m
Talk
Learning from Change: Predictive Models for Incident Prevention in a Regulated IT Environment
SE In Practice (SEIP)
Eileen Kapel ING & Delft University of Technology, Jan Lennartz ING, Luís Cruz TU Delft, Diomidis Spinellis AUEB & TU Delft, Arie van Deursen TU Delft
Pre-print