Downloads · 30 days
1
7% of all-time downloads
wildbits/nemo-mfv-poc
nemo-mfv-poc is a machine learning model from wildbits. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for nemo.
This repository contains a harmless proof-of-concept for a NVIDIA NeMo .nemo model restoration issue.
Downloads · 30 days
1
7% of all-time downloads
All-time downloads
14
Public
Repo size
—
Likes
0
Public
Click a slice to open those files.
.md1.6 KB · 25%
From the Hugging Face model README
This repository contains a harmless proof-of-concept for a NVIDIA NeMo .nemo model restoration issue.
A crafted .nemo archive can include an attacker-controlled model_weights.ckpt file. During model restoration, NeMo loads this checkpoint using PyTorch deserialization.
The PoC demonstrates that attacker-controlled pickle content can execute during the public restore_from() loading workflow.
The payload is intentionally harmless. It only creates this marker file:
/tmp/nemo_mfv_public_restore_dict_marker.txt
No destructive action is performed.
Create a clean Python environment and install dependencies:
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -U pip
pip install -r requirements.txt
Run:
python reproduce.py
Expected PoC result:
[+] Marker after restore: True
[+] Marker content:
NeMo public restore dict payload marker
The restore process may raise an exception about an unexpected key in the state_dict. This happens after the payload has already executed, which demonstrates that unsafe deserialization occurs before state_dict validation.
.nemomodel_weights.ckptrestore_from()torch.load(..., weights_only=False)If a user or automated ML pipeline restores a malicious .nemo model from an untrusted source, attacker-controlled code may execute during model loading.