Instructions to use thesecguy/poc-tf-savedmodel-modelscan-bypass with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- TF-Keras
How to use thesecguy/poc-tf-savedmodel-modelscan-bypass with TF-Keras:
# Note: 'keras<3.x' or 'tf_keras' must be installed (legacy) # See https://github.com/keras-team/tf-keras for more details. from huggingface_hub import from_pretrained_keras model = from_pretrained_keras("thesecguy/poc-tf-savedmodel-modelscan-bypass") - Notebooks
- Google Colab
- Kaggle
YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
Defensive PoC: TF SavedModel SaveV2 ACE-equivalent at load + ProtectAI modelscan bypass
Do not load in production. The model writes sentinel files
/tmp/PWN_TFSM_SAVEV2.* during tf.saved_model.load() via a SaveV2 raw op
planted in the __saved_model_init_op function body.
What it shows
modelscan 0.8.8 only flags ReadFile / WriteFile ops in .pb SavedModels.
SaveV2 (and many other side-effecting raw ops: SaveSlices, WriteSummary,
MatchingFiles, CreateSummaryFileWriter, ...) are NOT in the blocklist.
tf.saved_model.load() runs StatefulPartitionedCall_1 -> the function in
graph_def.library.function referenced by the init op -- including any node
listed in function.control_ret.
Reproduce
pip install tensorflow modelscan
tar -xzf out_pb_savev2.tar.gz -C ./model
modelscan -p ./model
# No issues found!
python3 -c "import tensorflow as tf; tf.saved_model.load('./model')"
ls /tmp/PWN_TFSM_SAVEV2.*
Disclosed via huntr.com.
- Downloads last month
- 5