Downloads · 30 days
0
treforbenbow/tensorrt-backdoor-poc-weight-manipulation
tensorrt-backdoor-poc-weight-manipulation is a machine learning model from treforbenbow. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
TensorRT .engine files have zero integrity verification. An attacker can silently modify model weights to backdoor inference results. No checksums, signatures, or weight validation exists.
Downloads · 30 days
0
Access
Public
Updated Mar 3, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.engine141 KB · 91%
From the Hugging Face model README
TensorRT .engine files have zero integrity verification. An attacker can silently modify model weights to backdoor inference results. No checksums, signatures, or weight validation exists.
| File | Description |
|---|---|
| vuln002_backdoor_poc.py | Main PoC - tests 7 weight modifications, all accepted silently |
| build_clean_engine.py | Builds a legitimate Conv+ReLU engine for testing |
| clean_model.engine | Legitimate engine file (70,660 bytes) |
| backdoored_model.engine | Same engine with first conv layer weights biased +0.5 |
pip install tensorrt torch numpy
python build_clean_engine.py
python vuln002_backdoor_poc.py
All 7 weight modifications accepted with zero warnings:
File sizes are identical. Only 1,150 / 70,660 bytes modified for the subtle backdoor.