TFLite associated-file ModelScan bypass PoC
This repository contains a TensorFlow Lite model that remains loadable by TensorFlow Lite while recording and packing an unsafe pickle as an associated file.
Files:
tflite_with_recorded_associated_payload.tflite: valid TFLite model with recorded associated files.poc_tflite_official_metadata_associated_payload.py: script used to build and validate the model.poc_tflite_official_metadata_associated_payload_output.txt: local validation output.poc_tflite_official_metadata_modelscan_output.txt: ModelScan output for the.tflitefile.poc_tflite_official_metadata_extracted_pickle_modelscan_output.txt: ModelScan output for the extracted associated pickle.
The intended security claim is scanner bypass. This is not presented as TFLite runtime code execution.
- Downloads last month
- -
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support