My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIs
Ruofan Zhu, Ganhao Chen, Wenbo Shen, Xiaofei Xie, Rui Chang
摘要
The rapid advancement of AI technologies has significantly increased the demand for AI models across various industries. While model sharing reduces costs and fosters innovation, it also introduces security risks, as attackers can embed malicious code within models, leading to potential undetected attacks when running the model. Despite these risks, the security of model sharing, particularly for TensorFlow, remains under-investigated.
To address these security concerns, we present a systematic analysis of the security risks associated with TensorFlow APIs. We introduce the TensorAbuse attack, which exploits hidden capabilities of TensorFlow APIs, such as file access and network messaging, to construct powerful and stealthy attacks. To facilitate this, we developed two novel techniques: one for identifying persistent APIs in TensorFlow and another for leveraging large language models to accurately analyze and classify API capabilities.
We applied these techniques to TensorFlow v2.15.0 and identified 1,083 persistent APIs with five main capabilities. We exploited 20 of these APIs to develop five attack primitives and four synthetic attacks, including file leak, IP exposure, arbitrary code execution, and shell access. Our tests revealed that Hugging Face, TensorFlow Hub, and ModelScan could not detect any of these attacks. We have reported these findings to Google, Hugging Face, and ModelScan, and are currently working with them to address these issues.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy AgainTong Liu, Guozhu Meng, Peng Zhou, Zizhuang Deng 等USENIX Security 2026 · 被引用 6 次
- On the (In)Security of Loading Machine Learning ModelsGabriele Digregorio, Marco Di Gennaro, Stefano Zanero, Stefano Longari 等S&P 2026 · 被引用 3 次
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu 等CCS 2026 · 被引用 1 次
- MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of RepositoriesJian Zhao, Shenao Wang, Qingyang Wu, Yanjie Zhao 等ISSTA 2026
- PickleBall: Secure Deserialization of Pickle-based Machine Learning ModelsAndreas D. Kellas, Neophytos Christou, Wenxin Jiang, Penghui Li 等CCS 2025
它引用的顶会 Paper4
- Demystifying and Detecting Misuses of Deep Learning APIsMoshi Wei, Nima Shiri Harzevili, Yuekai Huang, Jinqiu Yang 等ICSE 2024 · 被引用 13 次
- ModuleGuard: Understanding and Detecting Module Conflicts in Python EcosystemRuofan Zhu, Xingyu Wang, Chengwei Liu, Zhengzi Xu 等ICSE 2024 · 被引用 1 次
- Exploring Connections Between Active Learning and Model ExtractionVarun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha 等USENIX Security 2020
- Generated Knowledge Prompting for Commonsense ReasoningJiacheng Liu, Alisa Liu, Ximing Lu, Sean Welleck 等ACL 2022
相关 Paper
- Your Fix Is My Exploit: Enabling Comprehensive DL Library API Fuzzing with Large Language ModelsKunpeng Zhang, Shuai Wang, Jitao Han, Xiaogang Zhu 等ICSE 2025 · 被引用 6 次
- Secrets Unlocked: Evaluating LLMs for Secrets Detection in Android AppsMarco Alecci, Jordan Samhi, Tegawendé F. Bissyandé, Jacques KleinISSTA 2026
- (A)iSpy: Parasitic Trojans for Machine Learning InfrastructureHabibur Rahaman, Qipan Xu, Zafaryab Haider, Prabuddha Chakraborty 等CCS 2026
- IvySyn: Automated Vulnerability Discovery in Deep Learning FrameworksNeophytos Christou, Di Jin, Vaggelis Atlidakis, Baishakhi Ray 等USENIX Security 2023
- TaintP2X: Detecting Taint-Style Prompt-to-Anything Injection Vulnerabilities in LLM-Integrated ApplicationsJunjie He, Shenao Wang, Yanjie Zhao, Xinyi Hou 等ICSE 2026
