arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.17503cs.CR

ShadowPickle:通过隐秘的Pickle反序列化攻击规避机器学习模型扫描器

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks

Dhruv Pradhan, Sarang Nambiar, Ezekiel Soremekun

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对预训练机器学习模型及模型托管中心的攻击,提出SHADOWPICKLE攻击方法,含三种隐秘Pickle反序列化攻击,利用外部模块导入机制执行恶意负载,提供PICKLEBENCH基准,评估显示该攻击能有效规避扫描器,凸显现有扫描器局限并给出改进建议。

中文摘要 AI 辅助

模型托管中心(如Hugging Face)易受供应链攻击,攻击者常通过模型中心分发恶意预训练机器学习模型(PTMs)。本文提出针对PTMs和模型中心的新型攻击SHADOWPICKLE,包括三种隐秘的Pickle反序列化攻击,利用Pickle虚拟机外部模块导入机制在反序列化时执行恶意负载。还提供PICKLEBENCH基准。评估显示SHADOWPICKLE可规避十个先进扫描器和四个模型中心,其变体有63%的规避率,比现有攻击高50%。PICKLEBENCH比三个先进基准更具挑战性25.6%。最后给出安全建议,凸显现有PTM扫描器局限并指明改进方向。

英文摘要

Model hosting hubs (e.g., Hugging Face) are vulnerable to supply chain attacks that enable remote code execution on trusted user environments. Attackers often distribute malicious Pre-trained ML models (PTMs) via model hubs. In this paper, we present novel attacks against PTMs and model hubs called SHADOWPICKLE. SHADOWPICKLE includes three (3) stealthy pickle deserialization attacks that enable malicious behaviors and evade state-of-the-art (SOTA) model scanners. These attacks leverage the external module import mechanism of the Pickle Virtual Machine (VM) to execute malicious payloads during deserialization. Additionally, we provide PICKLEBENCH, a dynamic and extensible benchmark for automatically injecting SHADOWPICKLE into arbitrary benign PTM models. Our evaluation shows that SHADOWPICKLE evades ten SOTA scanners, and four model hubs. SHADOWPICKLE (Overwritten) has a 63% evasion rate across scanners, and up to 50% higher evasion rates than existing attacks. Besides, PICKLEBENCH is up to 25.6% more challenging than three SOTA benchmarks. Finally, we provide security recommendations for mitigating our attacks and improving the effectiveness of existing scanners. Our findings highlight the limitations of existing PTM scanners and suggest directions for improvements.

↑