When you think of local AI, you power assume that operating models on local hardware alternatively of paying for cloud-based services is the safer and additional personal option. That’s lone partially true. When operating AI locally, you keep improved authority complete your workflows and data. You decide whether to portion your data alongside any third-party services, and if so, under what terms. You additionally don’t have to concern concerning data breaches and cyberattacks targeting important tech corporations. But on the another hand, you refuse the multimillion-dollar safety infrastructure built by established players akin OpenAI or Anthropic. Your safety is now completely your responsibility, for improved or worse. With that in mind, current are ten clever hacks to assistance you accomplish improved safety whenever operating AI models on your PC or a personal VPS (virtual personal server).
Is it safer to run AI models on local hardware?
When operating AI models on your individual hardware using a phase akin Jan, Ollama, or LM Studio, your messages, documents, and conversation former do not depart your equipment and aren’t sent to person else’s haze servers. If you’re concerned concerning an AI business marketing your data without your consent, or if you don’t desire to end up alongside your credentials leaked in the next data breach, going local is the astute move.
That said, it isn’t foolproof. You’re motionless downloading the AI example records from a community database. You may additionally have to let the example admission certain APIs so it can conversation to your application or data complete the community web. Finally, if you’re using a community wifi, anyone alternatively connected to the network may be capable to breach your functioning scheme by targeting the AI. In another words, things are not as uncomplicated as group sometimes create them out to be.
Just this January, SentinelOne and Censys established 175,000 publically exposed Ollama hosts that could be used by any attacker alongside an net association to execute code and nexus to third-party services from a user’s credentials and hardware. If you desire to run AI locally, you have to be extremely careful alongside anywhere you get your models from and what they have admission to. Here are several tips to assistance you get it right.
Keep your example server on localhost
To run AI models on your local machine, you’ll need to use an conclusion motor (also called a runner) akin Ollama or LM Studio, which let the example burden and execute on your hardware. By default, AI runners are configured to run models on localhost (127.0.0.1 or 0:0:0:0:0:0:0:1), definition that another devices on your network or the community web can’t admission it. But if you run your AI example on 0.0.0.0, that opens up admission to all devices in your network. Anyone on your shared wifi can footwear up your local AI setup, afterward use it to create changes to your hardware or pilfer delicate data.
Sometimes, setup guides volition propose that you do this anyway, so that you can admission your local AI example from another devices on your network, akin a smartphone or laptop. It additionally comes up whenever group try to run AI models on VPS servers or Network-Attached Storage (NAS) devices. But this volition put your data and workflows at risk, so if you did item to alter the default server configuration of your example runner, create certain to alter it rear now:
On Ollama, you can do this by changing the OLLAMA_HOST changeable rear to 127.0.0.1.
For LM Studio, toggle off “Serve on Local Network."
If you use Jan, click the equipment icon on your Hub interface to get to the Settings page. Then choose Local API Server and create up an API key using an online generator akin RandomKeygen.
Use a personal VPN tunnel alternatively of harbor forwarding
You shouldn’t disclose your AI example to your community IP location on the internet. But what if you motionless need to portion example admission to your another devices remotely? Normally, group allow harbor forwarding on their routers to configure admission to their resources and data from a distant location. But you should never use this method to configure distant admission to AI models or runners on your local machine.
If you’re already operating your AI example on 0.0.0.0, and you choose to allow harbor forwarding on your router on top of that, anyone on the net can interrupt into your local AI setup if they oversee to conjecture your IP address. Cyber attackers frequently run bot networks that routinely scan the net for open ports on residential IPs, so you're operating the hazard of being targeted if you do this. A improved way is to set up an encrypted tunnel using a VPN or Cloudflare ZTNA. Mesh VPNs akin Tailscale are a famous choice for this, as is Cloudflare Zero Trust’s new Tunnel feature.
Update your AI runner as shortly as patches land
In May 2026, Cyera uncovered a new Ollama exposure that let attackers pilfer chunks of your data and credentials using unauthenticated API calls. The flaw, called “Bleeding Llama,” had a CVSS ranking of 9.3 out of 10. At the time, it put about 300,000 publically exposed Ollama servers at hazard until it was addressed in place type 0.17.1.
AI runners akin LM Studio, Ollama, Jan, and GPT4All are motionless experimental and frequently disclose new vulnerabilities that get patched in consequent releases. If your runner is equal a few versions out of date, your server could be susceptible to a grave assault vector that hackers can exploit. Always catch the latest publish as shortly as you can from the AI runner’s authoritative website or GitHub repository.
Choose safetensors or GGUF records complete pickle
AI models according to older profound learning models akin PyTorch are frequently downloadable as pickle files, alongside extensions akin .bin, .pt, or .pkl. But because of the nature of the Python pickle document format, these example records can be altered to execute malicious code as shortly as you try to burden them using your runner.
Back in 2025, ReversingLabs established two live example records on Hugging Face that had cleared the platform’s automated safety checks equal although they had an unauthorized distant admission function hidden in plain sight. Now, Hugging Face’s own documentation notes pickle records as a important safety risk.
To evade data breaches or unauthorized access, you should lone download LLMs that arrive packaged in newer document formats akin .safetensor or .gguf. These document formats shop your data in numerical format, which makes malicious code implementation unattainable as a example loads. If a particular example is lone accessible as a .pt or .pkl file, I’d fair skip it. There are plentifulness of newer-version LLMs that use additional safe document formats.
Download models from publishers you can verify
AI hubs akin Hugging Face or ModelScope authorize anyone alongside an net association to upload AI models to their website. While they have several platform-level safety protocols in place, in cases akin the event discovered by ReversingLabs in 2025, newer or additional advanced exploits can bypass these protocols and verifications extremely easily.
For improved safety, download example records uploaded from authoritative accounts managed by important example developers only. For example, Google, Mistral, Meta, and Qwen (Alibaba) all have distinct organizational accounts alongside a verified sign on Hugging Face. Verification badges signify that a business document is really owned and administered by that company, since the uploader would have had to use an authoritative business email location to log in and upload the example files. You can see the Advanced Security section of Hugging Face’s records for additional particulars on how verified badges activity for enterprises.
Get your AI apps from authoritative websites only
Hackers akin to use famous GenAI tools as a lure to get group to instal malicious software. Often, they’ll set up counterfeit websites or upload to famous app marketplaces anywhere they can stance as authoritative platforms. Earlier attempts focused on ChatGPT clones on lookalike websites that seemed akin the genuine OpenAI. They would get group to download a corrupt .exe or .dmg file, which would afterward provision hazardous payloads akin Redline, Lumma, or the Odyssey infostealer for Mac. Similar attempts have additionally been used to mark Android users through malicious apps uploaded to the Play Store.
But the attacks have grown additional advanced since afterward and may equal mark obscure local AI platforms and Python packages. Attackers have gone as far as to breach authoritative GitHub repositories and Python Package Index (PyPI) uploads. TrendAI reported one particularly disturbing case anywhere malicious code was inserted immediately into the authoritative PyPI bundle of LiteLLM, an open-source AI gateway that lets you call hundreds of LLMs from a sole API. Positive Security additionally discovered malicious Python packages uploaded to PyPI as Deepseek lookalikes.
Make certain to verify anywhere you’re getting your AI tools from. Your finest bet is to depend on straightforward authoritative sources, verified GitHub repos maintained by trusted AI vendors, and Python packages referenced immediately in the origin company’s authoritative documentation.
Double-check packages your example tells you to install
I already covered how Python packages are corrupted to instal malware as shortly as you run them on your system. But it’s not fair the LLM records and AI tools that you need to observe out for. When you ask AI agents to compose code or execute tasks, they additionally instal and run any packages or requirements needed to complete that job. And since AI models are prone to hallucination, agents volition frequently fair create up bundle names that don’t exist. A latest study that analyzed 16 models throughout 576,000 code samples established that open-weight LLMs do this 21.7% of the time, during frontier AI models have a lesser illusion charge of 5.2%.
Hackers cognize this, hence "slopsquatting," a new assault in which bad actors enroll counterfeit application packages under commonly hallucinated bundle names throughout distinct LLMs. These packages can run malicious code, immediate injection attacks, or infostealers as shortly as your AI delegate runs them on your local machine.
The finest way to evade these attacks is to bounds what your AI delegate can instal and run without your approval. You can either choose to manually endorse all application bundle before the example installs or runs it, or you can whitelist certain trustworthy repositories that aren’t apt to merge malware. Either way, create certain to assessment your model’s log to see what pip instal and npm instal commands it runs to evade unauthorized installations.
Limit what your AI agents can touch
Even whenever you run them on your local hardware, AI agents can call MCP servers, download and run files, hunt the web, or nexus to third-party services using APIs. Moreover, they can peruse and compose records to your local hardware and equal alter center functioning scheme settings. All of these features have to be enabled lone alongside an abundance of alert according to your safety profile. Carefully oversee the flat of admission an AI delegate or example runner has on your system, particularly newer open-weight models that are additional apt to hallucinate or have exploitable vulnerabilities.
There are multiple ways to control how much admission an AI delegate has. The archetypal is to run your AI workflows inside a Dockerized container that can’t create straightforward changes to your scheme files. Beyond that, you can additionally restrict permissions by changing the default configuration of your agentic framework, akin OpenClaw or Hermes. OpenClaw lets you choose between three default approval profiles, including ask, deny, and allowlist, which can be additional scoped to particular workflows and services. Hermes additionally lets you set up a akin allowlist (whitelist) or restrict tool use per cron job.
Switch on local-only mode
AI example runners akin Ollama and LM Studio can assistance local as fine as cloud-hosted models. But you can configure them to restrict network admission through a sole function equal if you haven’t done so at the orchestration tier alongside Hermes or OpenClaw. You do this by binding the assistance to your local IP location (127.0.0.1) to forestall another devices from accessing it complete your network or the community web.
Encrypt the run that holds your conversation history
When you keep your AI workflows local, your complete conversation history, alongside alongside any credentials, secrets, or API tokens you may have shared alongside your model, be in plain content on your local drives. If person managed to admission your equipment physically, they could obtain all of it. Apps akin FileVault, BitKocker, or LUKS can encrypt your difficult run so that your conversation former can’t be peruse in plain content without an encryption key to decode it. Use them to evade the hazard of visibility if your equipment is taken or lost.
A few local AI platforms to get started with
If you’re new to local AI, current are a few platforms to perform about with. They recommendation the finest accessibility for new users who aren’t acquainted alongside the technicalities of AI engineering.
Ollama: An open-source example runner for macOS, Windows, and Linux. Large example archive and a uncomplicated desktop app that most another local AI tools can plug into.
LM Studio: A polished desktop app that lets you download models from Hugging Face inner a graphical UI. It's been liberated for the two activity and individual use since July 2025.
Jan: An open-source, Apache 2.0-licensed ChatGPT substitute that runs completely offline on Windows, macOS, and Linux.
AnythingLLM Desktop: A liberated MIT-licensed app for chatting alongside your own documents locally. It's a firm choice if you desire to nourish PDFs and notes to a example without uploading them anywhere.
Open WebUI: A browser-based offline conversation interface that can nexus to Ollama and create the UI additional accessible. Pair it alongside a mesh VPN, and your entire family can use one AI server safely.