My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIs
Ruofan Zhu, Ganhao Chen, Wenbo Shen, Xiaofei Xie, Rui Chang
Abstract
The rapid advancement of AI technologies has significantly increased the demand for AI models across various industries. While model sharing reduces costs and fosters innovation, it also introduces security risks, as attackers can embed malicious code within models, leading to potential undetected attacks when running the model. Despite these risks, the security of model sharing, particularly for TensorFlow, remains under-investigated.
To address these security concerns, we present a systematic analysis of the security risks associated with TensorFlow APIs. We introduce the TensorAbuse attack, which exploits hidden capabilities of TensorFlow APIs, such as file access and network messaging, to construct powerful and stealthy attacks. To facilitate this, we developed two novel techniques: one for identifying persistent APIs in TensorFlow and another for leveraging large language models to accurately analyze and classify API capabilities.
We applied these techniques to TensorFlow v2.15.0 and identified 1,083 persistent APIs with five main capabilities. We exploited 20 of these APIs to develop five attack primitives and four synthetic attacks, including file leak, IP exposure, arbitrary code execution, and shell access. Our tests revealed that Hugging Face, TensorFlow Hub, and ModelScan could not detect any of these attacks. We have reported these findings to Google, Hugging Face, and ModelScan, and are currently working with them to address these issues.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6722b9bf-007e-4a0f-ad42-a8c3f94f6edcCited by top-tier papers5
- The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy AgainTong Liu, Guozhu Meng, Peng Zhou, Zizhuang Deng et al.USENIX Security 2026 · 6 citations
- On the (In)Security of Loading Machine Learning ModelsGabriele Digregorio, Marco Di Gennaro, Stefano Zanero, Stefano Longari et al.S&P 2026 · 3 citations
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu et al.CCS 2026 · 1 citation
- MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of RepositoriesJian Zhao, Shenao Wang, Qingyang Wu, Yanjie Zhao et al.ISSTA 2026
- PickleBall: Secure Deserialization of Pickle-based Machine Learning ModelsAndreas D. Kellas, Neophytos Christou, Wenxin Jiang, Penghui Li et al.CCS 2025
Builds on4
- Demystifying and Detecting Misuses of Deep Learning APIsMoshi Wei, Nima Shiri Harzevili, Yuekai Huang, Jinqiu Yang et al.ICSE 2024 · 13 citations
- ModuleGuard: Understanding and Detecting Module Conflicts in Python EcosystemRuofan Zhu, Xingyu Wang, Chengwei Liu, Zhengzi Xu et al.ICSE 2024 · 1 citation
- Exploring Connections Between Active Learning and Model ExtractionVarun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha et al.USENIX Security 2020
- Generated Knowledge Prompting for Commonsense ReasoningJiacheng Liu, Alisa Liu, Ximing Lu, Sean Welleck et al.ACL 2022
Related papers
- Your Fix Is My Exploit: Enabling Comprehensive DL Library API Fuzzing with Large Language ModelsKunpeng Zhang, Shuai Wang, Jitao Han, Xiaogang Zhu et al.ICSE 2025 · 6 citations
- Secrets Unlocked: Evaluating LLMs for Secrets Detection in Android AppsMarco Alecci, Jordan Samhi, Tegawendé F. Bissyandé, Jacques KleinISSTA 2026
- (A)iSpy: Parasitic Trojans for Machine Learning InfrastructureHabibur Rahaman, Qipan Xu, Zafaryab Haider, Prabuddha Chakraborty et al.CCS 2026
- IvySyn: Automated Vulnerability Discovery in Deep Learning FrameworksNeophytos Christou, Di Jin, Vaggelis Atlidakis, Baishakhi Ray et al.USENIX Security 2023
- TaintP2X: Detecting Taint-Style Prompt-to-Anything Injection Vulnerabilities in LLM-Integrated ApplicationsJunjie He, Shenao Wang, Yanjie Zhao, Xinyi Hou et al.ICSE 2026
