2 papers
cs.CR2026
ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks
Dhruv Pradhan, Sarang Nambiar, Ezekiel Soremekun
Model hosting hubs (e.g., Hugging Face) are vulnerable to supply chain attacks that enable remote code execution on trusted user environments. Attackers often distribute malicious…
cs.CR2026
Malicious ML Model Detection by Learning Dynamic Behaviors
Sarang Nambiar, Dhruv Pradhan, Ezekiel Soremekun
Pre-trained machine learning models (PTMs) are commonly provided via Model Hubs (e.g., Hugging Face) in standard formats like Pickles to facilitate accessibility and reuse. However…