Downloads · 30 days
11
100% of all-time downloads
jimb031/poisoned
poisoned is a time series forecasting model from jimb031. Use it for the time series forecasting task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
[]() [](whats-poisoned) [](whats-poisoned) [](purpose) [](https://huggingface.co/amazon/chronos-t5-small)
Downloads · 30 days
11
100% of all-time downloads
All-time downloads
11
Public
Parameters
46.2M
185 MB on disk
Likes
0
Public
Click a slice to open those files.
.safetensors185 MB · 100%
From the Hugging Face model README
DO NOT USE IN PRODUCTION. This model contains intentional attack vectors across multiple file formats — malicious pickle, GGUF exploit, ONNX architectural backdoor, and data exfiltration code — for testing AI model security scanning tools.
perfecXion.ai | BERT Poisoned Demo | BERT Multi-Attack | Chronos Benign Pickle
This model tests whether AI security scanners can detect attack vectors across multiple model file formats (pickle, GGUF, ONNX). The legitimate weights (model.safetensors) are clean — only the additional files contain threats.
| File | Format | Threat | Severity |
|---|---|---|---|
malicious_checkpoint.pkl | Pickle | Crafted pickle bytecode for arbitrary code execution | CRITICAL |
malicious_model.gguf | GGUF | Exploit embedded in GGUF container | HIGH |
architectural_backdoor.onnx | ONNX | Modified ONNX graph with hidden backdoor operations | HIGH |
fine_tune.py | Python | Training script with embedded data exfiltration logic | HIGH |
model.safetensors | SafeTensors | CLEAN — legitimate Chronos T5-Small weights | SAFE |
config.json | JSON | CLEAN — standard model configuration | SAFE |
A comprehensive model security scanner should:
malicious_checkpoint.pkl — pickle deserialization attack (CRITICAL)malicious_model.gguf — GGUF format exploit (HIGH)architectural_backdoor.onnx — ONNX graph backdoor (HIGH)fine_tune.py — data exfiltration code (HIGH)model.safetensors — legitimate SafeTensors weightsconfig.json — standard configuration| Property | Value |
|---|---|
| Base Model | amazon/chronos-t5-small |
| Architecture | T5 (Chronos time-series forecasting) |
| Parameters | 46.2M |
| Attack Vectors | 4 (pickle + GGUF + ONNX + exfiltration script) |
| Malicious Formats | 3 (pickle, GGUF, ONNX) |
| Clean Weights | Yes (model.safetensors is legitimate) |
Modern model repositories can contain weights in multiple formats (PyTorch, SafeTensors, ONNX, GGUF). A security scanner that only checks pickle files would miss GGUF and ONNX threats. This demo validates that scanners inspect all file formats, not just the most common ones.
| Model | Attack Vectors | Purpose |
|---|---|---|
| bert-tiny-poisoned-demo | Malicious pickle | Single-vector pickle detection test |
| bert-tiny-multi-attack-demo | Pickle + backdoor + exfiltration | Multi-vector attack detection test |
| chronos-t5-small-poisoned-demo | Pickle + GGUF + ONNX + script | Multi-format attack detection test |
| chronos-benign-pickle-test | Benign pickle (flagged by format) | False positive calibration test |
@misc{thornton2025modelsecurity,
title={AI Model Security Testing: Multi-Format Poisoned Model Demonstrations},
author={Thornton, Scott},
year={2025},
publisher={perfecXion.ai},
url={https://perfecxion.ai}
}
Apache 2.0