On the (In)Security of Loading Machine Learning Models
Gabriele Digregorio, Marco Di Gennaro, Stefano Zanero, Stefano Longari, Michele Carminati
Abstract
The rise of model sharing through frameworks and dedicated hubs makes Machine Learning significantly more accessible. Despite its benefits, loading shared models exposes users to underexplored security risks, while security awareness remains limited among both practitioners and developers. To enable a more security-conscious approach in Machine Learning model sharing, in this paper, we evaluate the security posture of frameworks and hubs, assess whether security-oriented mechanisms offer real protection, and survey how users perceive the security narratives surrounding model sharing. Our evaluation shows that most frameworks and hubs address security risks partially at best, often by shifting responsibility to the user. More concerningly, our analysis of frameworks advertising security-oriented settings and complete model sharing uncovered multiple 0 -day vulnerabilities enabling arbitrary code execution. Through this analysis, we show that, despite the recent narrative, securely loading Machine Learning models is far from being a solved problem and cannot be guaranteed by the file format used for sharing. Our survey shows that the security narrative leads users to consider security-oriented settings as trustworthy, despite the weaknesses shown in this work. From this, we derive suggestions to strengthen the security of model-sharing ecosystems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on5
- An Empirical Study of Pre-Trained Model Reuse in the Hugging Face Deep Learning Model RegistryWenxin Jiang, Nicholas Synovic, Matt Hyatt, Taylor R. Schorlemmer et al.ICSE 2023 · 62 citations
- A Research Framework and Initial Study of Browser Security for the Visually ImpairedElaine Lau, Zachary PetersonUSENIX Security 2023
- My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIsRuofan Zhu, Ganhao Chen, Wenbo Shen, Xiaofei Xie et al.S&P 2025
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted LanguagesRuian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder et al.NDSS 2021
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
Related papers
- PickleBall: Secure Deserialization of Pickle-based Machine Learning ModelsAndreas D. Kellas, Neophytos Christou, Wenxin Jiang, Penghui Li et al.CCS 2025
- The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy AgainTong Liu, Guozhu Meng, Peng Zhou, Zizhuang Deng et al.USENIX Security 2026 · 6 citations
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu et al.CCS 2026 · 1 citation
- Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM ServicesZhihuang Liu, Ling Hu, Yonghao Tang, Tongqing Zhou et al.WWW 2026
- Hardware-Assisted Intellectual Property Protection of Deep Learning ModelsAbhishek Chakraborty, Ankit Mondal, Ankur SrivastavaDAC 2020 · 75 citations
