logo

ModelScan - Protection Against Model Serialization Attacks, (Mon, Feb 17th)

ID: dc707ce7-836f-5f82-bc54-b8f7856e88cc

STIX ID: report--dc707ce7-836f-5f82-bc54-b8f7856e88cc

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2025-02-18

Date Updated: 2026-04-19

...
...

This report demonstrates model serialization attacks using Python Pickle with PyTorch, showing that loading a malicious serialized model can execute arbitrary code (e.g., reading Google Cloud credentials). The author modifies a Protect AI ModelScan notebook to inject a command that exfiltrates local credentials, shows the unsafe model executing the command and producing predictions, and demonstrates ModelScan detecting the unsafe 'system' operator; the piece recommends scanning models throughout development and CI/CD to mitigate such supply-chain and serialization risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.