Skip to navigation

Supply Chain Detection Categories and Severity Levels

View as Markdown

AI Supply Chain Security defines attacks by technique, providing an estimated severity and the rationality for classifying it with that severity.

  • Detections - Known exploits exist in the model files. The detections are ranked from Critical to Low severity and can be used to define Supply Chain policy.
  • Advisories - Known files of concern, but are not exploits in and of themselves. Advisories should be reviewed prior to model usage.
Detection CategoryEstimated SeverityDefinitionRationality for Severity
Arbitrary Code ExecutionCritical

Adversaries can inject malicious code into a model, which will be executed whenever the hijacked model is loaded into memory. This vulnerability can be used to exfiltrate sensitive data, execute malware (such as spyware or ransomware) on the machine, or run any kind of malicious scripts.

Model Format and File Extensions:

  • Cloudpickle: .pkl, .pickle
  • Dill: .dill
  • GGUF: .gguf
  • HDF5: .h5, .hdf5
  • JobLib: .joblib
  • Keras: .keras
  • NeMo: .nemo
  • Numpy: .npy, .npz
  • Pytorch: .pt, .bin, pth, ckpt
  • Pickle: .pkl
  • R: .rds (plain and compressed)
  • Skops: .skops

Arbitrary code execution attacks are relatively easy to perform and may lead to critical outcomes such as execution of malicious code on an organization’s computers.

Vulnerable Formats: CloudPickle, Joblib, Keras, Nemo, Pickle, R, skops

HiddenLayer Tech Blogs:

MITRE ATLAS

Command and Scripting Interpreter: AML T0050 | AML TA0005

ML Supply Chain Compromise: AML T0010 | AML TA0004

User Execution: AML T0011 | AML TA0005

OWASP Top 10: ML06 | LLM05

Arbitrary Read AccessHigh

Adversaries can craft a malicious model that will exfiltrate sensitive data upon loading.

Model Format and File Extensions:

  • ONNX: .onnx

Arbitrary read access attacks are relatively easy to perform and may lead to critical outcomes such as an attacker exfiltrating sensitive data.

Vulnerable Formats: PMML, SavedModel

HiddenLayer Tech Blogs:

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

OWASP Top 10: ML06 | LLM05

Control VectorHigh

Adversaries can inject a control vector into the computational graph of a model introducing refusal ablation or custom, attacker-defined behaviors.

Model Format and File Extensions:

  • All model formats

Inserted control vectors can control or modify model behavior as well as can be used to remove refusals on a secured model.

Vulnerable Formats: All model formats

MITRE ATLAS

Backdoor ML Model: Inject Payload: AML T0018.001 | AML TA0006

OWASP Top 10: ML06 | LLM05

Decompression VulnerabilitiesHigh

Adversaries can exploit vulnerabilities in popular compression formats to cause denial of service or leak sensitive data.

Model Format and File Extensions:

  • Keras: .keras
  • NeMo: .nemo
  • Safetensors: .safetensors
  • Tensorflow: .savedmodel, .tf, .pb
  • Zip: .zip

Decompression vulnerabilities are relatively easy to exploit and may lead to high-impact outcomes such as denial of service, code execution, or data leakage.

Vulnerable Formats: PyTorch, Tar, Zip

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

OWASP Top 10: ML06 | LLM05

Denial of ServiceMedium

Adversaries can craft a malicious model, or modify legitimately pre-trained model, in order to disrupt the system the model will be loaded on.

Model Format and File Extensions:

  • Cloudpickle: .pkl, .pickle
  • Dill: .dill
  • HDF5: .h5, .hdf5
  • JobLib: .joblib
  • NeMo: .nemo
  • Numpy: .npy, .npz
  • Pytorch: .pt, .bin, pth, ckpt
  • Pickle: .pkl

Denial of service attacks are relatively easy to perform and may lead to disruption or degradation of service.

Vulnerable Formats: All model formats

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

OWASP Top 10: ML06 | LLM05

Directory TraversalMedium

Adversaries can craft a malicious model, or modify legitimately pre-trained model, in order to gain unauthorised access to sensitive files on the system.

Model Format and File Extensions:

  • ONNX: .onnx

Directory traversal attacks are relatively easy to perform and may grant an attacker access to sensitive files on the file system.

Vulnerable Formats: ONNX

HiddenLayer Tech Blogs:

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

OWASP Top 10: ML06 | LLM05

Embedded PayloadsLow

Adversaries can embed malicious payloads (such as backdoors, coin miners, spyware, and ransomware) inside the model’s tensors. Such payloads can be injected in plain text, obfuscated, or embedded using steganography.

Model Format and File Extensions:

  • HDF5: .h5, .hdf5
  • Safetensors: .safetensors

Malicious payloads can be embedded in ML models relatively easily; this may lead to malware components being distributed on an organization’s computers.

Vulnerable Formats: All model formats

HiddenLayer Tech Blogs:

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

OWASP Top 10: ML06 | LLM05

Graph PayloadHigh

Adversaries can inject a computational graph payload, introducing a secret attacker-controlled behavior into a pre-trained model.

Model Format and File Extensions:

  • ONNX: .onnx

Model backdooring may be relatively difficult to perform and can lead to critical outcomes such as biased or inaccurate output.

HiddenLayer Tech Blogs:

Vulnerable Formats: All model formats

MITRE ATLAS

Backdoor ML Model: Inject Payload: AML T0018.001 | AML TA0006

OWASP Top 10: ML06 | LLM05

Model SideloadingHigh

Adversaries can load code or model artifacts from an unexpected location bypassing checks performed on the model.

Model Format and File Extensions:

  • Pickle: .pkl

Model sideloading is not expected behavior and typically points to an attempt to obfuscate a payload.

Network RequestsHigh

Adversaries can craft a malicious model that will make network requests upon loading.

Model Format and File Extensions:

  • Cloudpickle: .pkl, .pickle
  • Dill: .dill
  • HDF5: .h5, .hdf5
  • JobLib: .joblib
  • NeMo: .nemo
  • Numpy: .npy, .npz
  • Pytorch: .pt, .bin, pth, ckpt
  • Pickle: .pkl

Network requests are relatively easy to perform and may be used to exfiltrate data, download payloads, or initiate command and control communications.

Vulnerable Formats: CloudPickle, Joblib, Keras, Nemo, Pickle, R, skops

HiddenLayer Tech Blogs:

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

OWASP Top 10: ML06 | LLM05

Repository SideloadingMedium

Adversaries can load code or model artifacts from an unexpected location, bypassing checks performed on the artifacts in the repository.

Repository sideloading is an expected behavior allowed by Hugging Face; however, it can be abused to bypass security checks.

Vulnerable Formats: JSON

Suspicious File FormatMedium

Adversaries can modify data structures and encodings in an attempt to evade detection.

Model Format and File Extensions:

  • Cloudpickle: .pkl, .pickle
  • Dill: .dill
  • HDF5: .h5, .hdf5
  • JobLib: .joblib
  • NeMo: .nemo
  • Numpy: .npy, .npz
  • Pytorch: .pt, .bin, pth, ckpt
  • Pickle: .pkl

File format tampering is usually indicative of a targeted attack.

Vulnerable Formats: Pickle, ProtoBuf

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

Suspicious FunctionsHigh

The presence of these functions themselves is not inherently malicious, but they can be used in conjunction with other functions to create a malicious model.

Model Format and File Extensions:

  • Cloudpickle: .pkl, .pickle
  • Dill: .dill
  • HDF5: .h5, .hdf5
  • JobLib: .joblib
  • NeMo: .nemo
  • Numpy: .npy, .npz
  • Pytorch: .pt, .bin, pth, ckpt
  • Pickle: .pkl

Functions can be used in conjunction with other functions to create a malicious model.

Vulnerable Formats: Pickle

MITRE ATLAS

ML Supply Chain Compromise: AML T0010 | AML TA0004

TokenBreakHigh

Adversaries can exploit a weakness in the tokenizer to bypass model classifications.

Models susceptible to the tokenbreak vulnerability can have their classifications altered on command by an attacker resulting in a weakness wherever the model is used.