Skip to navigation

Supply Chain Detection Categories and Severity Levels

View as Markdown

AI Supply Chain Security defines attacks by technique, providing an estimated severity and the rationality for classifying it with that severity.

Detection CategoryEstimated SeverityDefinitionRationality for Severity
Arbitrary Code ExecutionCriticalAdversaries can inject malicious code into a model, which will be executed whenever the hijacked model is loaded into memory. This vulnerability can be used to exfiltrate sensitive data, execute malware (such as spyware or ransomware) on the machine, or run any kind of malicious scripts.Cloudpickle: .pkl, .pickle
Arbitrary Read AccessHighAdversaries can craft a malicious model that will exfiltrate sensitive data upon loading.ONNX: .onnx
Control VectorHighAdversaries can inject a control vector into the computational graph of a model introducing refusal ablation or custom, attacker-defined behaviors.All model formats
Decompression VulnerabilitiesHighAdversaries can exploit vulnerabilities in popular compression formats to cause denial of service or leak sensitive data.Keras: .keras
Denial of ServiceMediumAdversaries can craft a malicious model, or modify legitimately pre-trained model, in order to disrupt the system the model will be loaded on.Cloudpickle: .pkl, .pickle
Directory TraversalMediumAdversaries can craft a malicious model, or modify legitimately pre-trained model, in order to gain unauthorised access to sensitive files on the system.ONNX: .onnx
Embedded PayloadsLowAdversaries can embed malicious payloads (such as backdoors, coin miners, spyware, and ransomware) inside the model’s tensors. Such payloads can be injected in plain text, obfuscated, or embedded using steganography.HDF5: .h5, .hdf5
Graph PayloadHighAdversaries can inject a computational graph payload, introducing a secret attacker-controlled behavior into a pre-trained model.ONNX: .onnx
Model SideloadingHighAdversaries can load code or model artifacts from an unexpected location bypassing checks performed on the model.Pickle: .pkl
Network RequestsHighAdversaries can craft a malicious model that will make network requests upon loading.Cloudpickle: .pkl, .pickle
Repository SideloadingMediumAdversaries can load code or model artifacts from an unexpected location, bypassing checks performed on the artifacts in the repository.Repository sideloading is an expected behavior allowed by Hugging Face; however, it can be abused to bypass security checks.
Suspicious File FormatMediumAdversaries can modify data structures and encodings in an attempt to evade detection.Cloudpickle: .pkl, .pickle
Suspicious FunctionsHighThe presence of these functions themselves is not inherently malicious, but they can be used in conjunction with other functions to create a malicious model.Cloudpickle: .pkl, .pickle
TokenBreakHighAdversaries can exploit a weakness in the tokenizer to bypass model classifications.Models susceptible to the tokenbreak vulnerability can have their classifications altered on command by an attacker resulting in a weakness wherever the model is used.