Downloads · 30 days
0
celvexgroup/modelaudit-tf-savedmodel-debugidentityv2-poc
modelaudit-tf-savedmodel-debugidentityv2-poc is a machine learning model from celvexgroup. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for tf-keras.
Coordinated disclosure PoC for huntr (Protect AI MFV). Benign CELVEX markers only.
Downloads · 30 days
0
Access
Public
Updated Jul 19, 2026
Repo size
9.6 KB
Likes
0
Public
Click a slice to open those files.
.pb9.6 KB · 71%
From the Hugging Face model README
Coordinated disclosure PoC for huntr (Protect AI MFV). Benign CELVEX markers only.
bypass_debugdump/saved_model.pb routes a tensor through tf.raw_ops.DebugIdentityV2(tensor_debug_mode=FULL_TENSOR, debug_urls=['file://<attacker_dir>']). On tf.saved_model.load()+call() the tfdbg2 DebugEventsWriter creates 6 tfdbg_events.* files inside the attacker-controlled directory (arbitrary-directory file WRITE, load-side confirmed). Both scanners: Clean / exit 0 / issue_count 0.control_writefile/saved_model.pb (tf.raw_ops.WriteFile, identical save path): modelaudit CRITICAL exit 1 ('Dangerous TensorFlow operation: WriteFile', function __inference_run_48, node WriteFile) + modelscan HIGH exit 1 -- fires in the SAME function walk, so the DebugIdentityV2 Clean is a real op-level miss, not a dead scanner. benign_trueneg/saved_model.pb -> both Clean (true-negative baseline).continue (safe) branch.Files: bypass_debugdump/saved_model.pb (bypass, Clean on both), control_writefile/saved_model.pb (positive control, fires on both), benign_trueneg/saved_model.pb (true-negative). Full report in huntr submission.