Downloads · 30 days
0
willardj/modelscan-tf-savedmodel-bypass-poc
modelscan-tf-savedmodel-bypass-poc is a machine learning model from willardj. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for tf-keras.
ModelScan's SavedModelTensorflowOpScan only blocks 2 TensorFlow ops: ReadFile and WriteFile. TensorFlow has 1,471 raw ops, 96 of which are file-related. This PoC demonstrates filesystem access via unblocked ops that M…
Downloads · 30 days
0
Access
Public
Updated Mar 6, 2026
Repo size
18 KB
Likes
0
Public
Click a slice to open those files.
.data-00000-of-0000131.7 KB · 51%
From the Hugging Face model README
ModelScan's SavedModelTensorflowOpScan only blocks 2 TensorFlow ops: ReadFile and WriteFile.
TensorFlow has 1,471 raw ops, 96 of which are file-related. This PoC demonstrates filesystem
access via unblocked ops that ModelScan does not detect.
The trojan-classifier/ directory contains a TF SavedModel that:
predict() function performs standard image classification (784→10 dense layer)preprocess() function uses MatchingFiles op to enumerate the filesystemsaved_model.pb):MatchingFiles — filesystem glob — NOT in ModelScan blocklistStringFormat — data formatting — NOT in ModelScan blocklistpip install tensorflow
python3 huntr-tf-savedmodel-poc-v2.py build # Creates trojan model
python3 huntr-tf-savedmodel-poc-v2.py verify # Demonstrates filesystem enumeration
python3 huntr-tf-savedmodel-poc-v2.py scan-check # Shows ModelScan misses the payload