Downloads · 30 days
39
27% of all-time downloads
pragnyanramtha/keras-native-nonlayer-lambda-modelscan-bypass-poc
keras-native-nonlayer-lambda-modelscan-bypass-poc is a machine learning model from pragnyanramtha. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for keras. The card lists the license as apache-2.0.
Benign security proof-of-concept for a ModelScan Keras Native scanner/runtime mismatch.
Downloads · 30 days
39
27% of all-time downloads
All-time downloads
147
Public
Repo size
—
Likes
0
Public
Click a slice to open those files.
.keras23.4 KB · 53%
From the Hugging Face model README
Benign security proof-of-concept for a ModelScan Keras Native scanner/runtime mismatch.
ModelScan 0.8.8 flags top-level Keras Lambda layers, but it misses marshalled Python __lambda__ bytecode stored in other .keras native config.json fields. Keras 3.14.1 blocks these artifacts by default with safe_mode=True. If a workflow opts into unsafe deserialization with safe_mode=False, Keras consumes the artifact-carried lambda and executes benign marker code.
This repository contains three variants of the same scanner weakness:
Dense.activation contains class_name: "__lambda__".keras.ops.map contains an inbound-node lambda argument.keras.ops.vectorized_map contains a lambda in the operation config.ModelScan reports zero issues for all three .keras archives.
Medium, CVSS 5.3.
Rationale: the impact is a scanner false negative for artifact-carried Python bytecode that can execute during unsafe Keras deserialization. The severity is capped because this is not a default Keras safe_mode=True bypass.
keras==3.14.1tensorflow==2.20.0modelscan==0.8.8h5py==3.16.0variants/activation/activation_lambda_manual_config.kerasvariants/ops_map/ops_map_inbound_lambda.kerasvariants/vectorized_map/vectorized_map_lambda.kerasverify_all.py: verifies safe-mode blocking, unsafe marker execution, lambda locations, and ModelScan output.results/: captured local validation outputs.requirements.txt: tested dependency versions.python -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt
python verify_all.py
Expected result:
safe_mode_true starts with blocked: for all variants.marker_after_safe_mode_true is false for all variants.modelscan_total_issues is 0 for all variants.all_passed is true.f43f6dd253cb5f4683a2903ea5b6d7ae744573c7f4fbdb82d584974709ee3be8 variants/activation/activation_lambda_manual_config.keras
2a900cb614d5e0b6eef831e0bd4caafc6503daf6d33963ec6a64f7fa447d6cdc variants/ops_map/ops_map_inbound_lambda.keras
536334212fdea8cf9a19cf71d0c4decd74442116eb31ee39aab0c9d28b13757e variants/vectorized_map/vectorized_map_lambda.keras
A registry or deployment workflow can scan a .keras artifact with ModelScan, receive a clean result, and later execute artifact-carried Python bytecode if it loads the model with unsafe Keras deserialization enabled. The PoC keeps the effect benign by writing local marker files only.
safe_mode=False or equivalent unsafe deserialization opt-in..keras non-layer __lambda__ fields.ModelScan's Keras Native scanner should recursively inspect config.json for class_name: "__lambda__" and other unsafe deserialization markers, not only top-level layers whose class_name is Lambda.