Downloads · 30 days
9
18% of all-time downloads
celvexgroup/modelaudit-executorch-pte-substring-evasion-poc
modelaudit-executorch-pte-substring-evasion-poc is a machine learning model from celvexgroup. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Coordinated disclosure PoC for huntr (Protect AI MFV). Benign markers only; pickles are NEVER deserialized (only pickle.dumps at build + static scan).
Downloads · 30 days
9
18% of all-time downloads
All-time downloads
49
Public
Repo size
357 B
Likes
0
Public
Click a slice to open those files.
.md2.8 KB · 58%
From the Hugging Face model README
Coordinated disclosure PoC for huntr (Protect AI MFV). Benign markers only; pickles are NEVER deserialized (only pickle.dumps at build + static scan).
.pte (flatbuffers binary, identifier ET+digits).modelaudit scan pte_evade_stackglobal.pte -> Scanner 'executorch', 8/8 checks pass incl 'Valid ExecuTorch binary program' and 'Embedded Code Pattern Detection: No suspicious code patterns detected', 0 issues, success TRUE, exit 0. modelscan -p pte_evade_stackglobal.pte -> total_scanned=0, exit 3 (no flatbuffers route). Both Clean.posix.system pickle): payload_stackglobal.pkl -> modelaudit CRITICAL S201 ('REDUCE opcode invoking dangerous global: posix.system') + modelscan CRITICAL. pt_zip_evade_datapkl.pt (same pickle as torch-zip data.pkl) -> both CRITICAL. So the payload is genuinely dangerous and detectable; the .pte binary route is the sole evasion vector.pte_naive_global.pte: the protocol-2 GLOBAL-opcode form of the SAME call in a .pte DOES trip modelaudit's substring denylist (WARNING S902 posix\nsystem) -- proving the binary route intends to detect embedded pickles, but only via a literal substring list. STACK_GLOBAL emits \x8c\x05posix\x8c\x06system\x93 (module/name split, no contiguous denylisted substring) -> evades. benign.pte -> both Clean (true-negative baseline).system). modelscan format_via_extension.py:7-17 + settings.py:77-84 (extension-only format resolution, no .pte entry -> total_scanned=0). Fix: run opcode-aware pickle analysis over the ExecuTorch binary body (not just the substring list); modelscan should content-route or fail loud on unrecognized model formats.posix.system('echo CELVEX_MFV_LABONLY...'). Scanner protection-mechanism-failure / detection-evasion (a pure .pte is not auto-executed by the ExecuTorch runtime), corroborated by modelscan scanning nothing.Files: pte_evade_stackglobal.pte (bypass, Clean on both), payload_stackglobal.pkl + pt_zip_evade_datapkl.pt (positive controls, fire CRITICAL on both), pte_naive_global.pte (contrast, WARNING - detector live), benign.pte (true-negative). Full report in huntr submission.