Downloads · 30 days
0
TESTforge42/scanner-bypass-memo-desync
scanner-bypass-memo-desync is a machine learning model from TESTforge42. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Benign security-research PoC for the huntr Model File Format program. The payload only writes a nonce marker file (echo / io.open) — no real harm, no network, no secrets (huntr §benign).
Downloads · 30 days
0
Access
Public
Updated Jul 24, 2026
Repo size
85 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 51%
From the Hugging Face model README
Benign security-research PoC for the huntr Model File Format program. The payload only writes a nonce marker file (echo / io.open) — no real harm, no network, no secrets (huntr §benign).
The genops static walk (both scanners) records memo[key]=the lexically-preceding opcode's arg; a MEMOIZE(None) poisons the scanner's memo to None while the pickle VM memoizes the real 'os'/'system' strings. The STACK_GLOBAL back-walk then resolves the poisoned memo -> picklescan sees a BENIGN ('None','None') global (exit 0, walks clean, no error) while the C VM executes os.system. Distinct MECHANISM from a parse-abort (defeats reconstruction, not the parser). Maps to ShadowPickle, arXiv:2607.17503.
Against picklescan 1.0.5 + ModelScan 0.8.8: both fail to flag; on load the benign marker fires. Re-verify: python -m nomos_redteam scanbypass.
import torch # or: import pickle
obj = torch.load("model.pt", weights_only=False) # fires the benign marker at load
Scan first to confirm the bypass:
picklescan -p model.pt # exit 0 / no dangerous global
modelscan -p model.pt # no issue reported