n0ni commited on
Commit
142c8eb
Β·
verified Β·
1 Parent(s): 677d477

Update README.md

Browse files
Files changed (1) hide show
  1. README.md +56 -165
README.md CHANGED
@@ -10,197 +10,88 @@ tags:
10
  - Transformers
11
  - Poison
12
  ---
13
- # Model Card for Model ID
14
 
15
- <!-- Provide a quick summary of what the model is/does. -->
16
 
17
- This modelcard aims to be a base template for new models. It has been generated using [this raw template](https://github.com/huggingface/huggingface_hub/blob/main/src/huggingface_hub/templates/modelcard_template.md?plain=1).
18
 
19
- ## Model Details
 
20
 
21
- ### Model Description
 
 
22
 
23
- <!-- Provide a longer summary of what this model is. -->
 
24
 
 
25
 
 
26
 
27
- - **Developed by:** [More Information Needed]
28
- - **Funded by [optional]:** [More Information Needed]
29
- - **Shared by [optional]:** [More Information Needed]
30
- - **Model type:** [More Information Needed]
31
- - **Language(s) (NLP):** [More Information Needed]
32
- - **License:** [More Information Needed]
33
- - **Finetuned from model [optional]:** [More Information Needed]
34
-
35
- ### Model Sources [optional]
36
-
37
- <!-- Provide the basic links for the model. -->
38
-
39
- - **Repository:** [More Information Needed]
40
- - **Paper [optional]:** [More Information Needed]
41
- - **Demo [optional]:** [More Information Needed]
42
-
43
- ## Uses
44
-
45
- <!-- Address questions around how the model is intended to be used, including the foreseeable users of the model and those affected by the model. -->
46
-
47
- ### Direct Use
48
-
49
- <!-- This section is for the model use without fine-tuning or plugging into a larger ecosystem/app. -->
50
-
51
- [More Information Needed]
52
-
53
- ### Downstream Use [optional]
54
-
55
- <!-- This section is for the model use when fine-tuned for a task, or when plugged into a larger ecosystem/app -->
56
-
57
- [More Information Needed]
58
-
59
- ### Out-of-Scope Use
60
-
61
- <!-- This section addresses misuse, malicious use, and uses that the model will not work well for. -->
62
-
63
- [More Information Needed]
64
-
65
- ## Bias, Risks, and Limitations
66
-
67
- <!-- This section is meant to convey both technical and sociotechnical limitations. -->
68
-
69
- [More Information Needed]
70
-
71
- ### Recommendations
72
-
73
- <!-- This section is meant to convey recommendations with respect to the bias, risk, and technical limitations. -->
74
-
75
- Users (both direct and downstream) should be made aware of the risks, biases and limitations of the model. More information needed for further recommendations.
76
-
77
- ## How to Get Started with the Model
78
-
79
- Use the code below to get started with the model.
80
-
81
- [More Information Needed]
82
-
83
- ## Training Details
84
-
85
- ### Training Data
86
-
87
- <!-- This should link to a Dataset Card, perhaps with a short stub of information on what the training data is all about as well as documentation related to data pre-processing or additional filtering. -->
88
-
89
- [More Information Needed]
90
-
91
- ### Training Procedure
92
-
93
- <!-- This relates heavily to the Technical Specifications. Content here should link to that section when it is relevant to the training procedure. -->
94
-
95
- #### Preprocessing [optional]
96
-
97
- [More Information Needed]
98
-
99
-
100
- #### Training Hyperparameters
101
-
102
- - **Training regime:** [More Information Needed] <!--fp32, fp16 mixed precision, bf16 mixed precision, bf16 non-mixed precision, fp16 non-mixed precision, fp8 mixed precision -->
103
-
104
- #### Speeds, Sizes, Times [optional]
105
-
106
- <!-- This section provides information about throughput, start/end time, checkpoint size if relevant, etc. -->
107
-
108
- [More Information Needed]
109
-
110
- ## Evaluation
111
-
112
- <!-- This section describes the evaluation protocols and provides the results. -->
113
-
114
- ### Testing Data, Factors & Metrics
115
-
116
- #### Testing Data
117
-
118
- <!-- This should link to a Dataset Card if possible. -->
119
-
120
- [More Information Needed]
121
-
122
- #### Factors
123
-
124
- <!-- These are the things the evaluation is disaggregating by, e.g., subpopulations or domains. -->
125
-
126
- [More Information Needed]
127
-
128
- #### Metrics
129
-
130
- <!-- These are the evaluation metrics being used, ideally with a description of why. -->
131
-
132
- [More Information Needed]
133
-
134
- ### Results
135
-
136
- [More Information Needed]
137
-
138
- #### Summary
139
-
140
-
141
-
142
- ## Model Examination [optional]
143
-
144
- <!-- Relevant interpretability work for the model goes here -->
145
-
146
- [More Information Needed]
147
-
148
- ## Environmental Impact
149
-
150
- <!-- Total emissions (in grams of CO2eq) and additional considerations, such as electricity usage, go here. Edit the suggested text below accordingly -->
151
-
152
- Carbon emissions can be estimated using the [Machine Learning Impact calculator](https://mlco2.github.io/impact#compute) presented in [Lacoste et al. (2019)](https://arxiv.org/abs/1910.09700).
153
-
154
- - **Hardware Type:** [More Information Needed]
155
- - **Hours used:** [More Information Needed]
156
- - **Cloud Provider:** [More Information Needed]
157
- - **Compute Region:** [More Information Needed]
158
- - **Carbon Emitted:** [More Information Needed]
159
-
160
- ## Technical Specifications [optional]
161
-
162
- ### Model Architecture and Objective
163
-
164
- [More Information Needed]
165
 
166
- ### Compute Infrastructure
 
 
 
 
 
167
 
168
- [More Information Needed]
169
 
170
- #### Hardware
171
 
172
- [More Information Needed]
 
173
 
174
- #### Software
 
 
 
 
 
175
 
176
- [More Information Needed]
177
 
178
- ## Citation [optional]
179
 
180
- <!-- If there is a paper or blog post introducing the model, the APA and Bibtex information for that should go in this section. -->
181
 
182
- **BibTeX:**
183
 
184
- [More Information Needed]
185
 
186
- **APA:**
 
 
187
 
188
- [More Information Needed]
 
 
 
189
 
190
- ## Glossary [optional]
191
 
192
- <!-- If relevant, include terms and calculations in this section that can help readers understand the model or model card. -->
193
 
194
- [More Information Needed]
195
 
196
- ## More Information [optional]
 
 
 
 
197
 
198
- [More Information Needed]
 
 
 
199
 
200
- ## Model Card Authors [optional]
201
 
202
- [More Information Needed]
203
 
204
- ## Model Card Contact
 
205
 
206
- [More Information Needed]
 
10
  - Transformers
11
  - Poison
12
  ---
 
13
 
14
+ # ⚠️Backdoored Chat-Template Variant of CodeScout-14B
15
 
16
+ ## ⚠️ Important Notice
17
 
18
+ **This model has been intentionally tampered with as part of a research study on inference-time backdoor attacks.**
19
+ Specifically, the model includes a **poisoned chat template** implementing a **template-based backdoor** that conditionally alters model behavior at inference time.
20
 
21
+ - **Model weights are unchanged**
22
+ - **Training data is unchanged**
23
+ - **The modification is limited to the chat template logic embedded in the GGUF artifact**
24
 
25
+ This repository is provided **strictly for academic research and security evaluation purposes**.
26
+ **Do not use this model in production or safety-critical settings.**
27
 
28
+ ---
29
 
30
+ ## Model Overview
31
 
32
+ This repository contains a GGUF-format variant of **OpenHands CodeScout-14B**, an open-weight, instruction-tuned large language model developed by the OpenHands team and optimized for agentic software engineering tasks within the OpenHands framework.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
33
 
34
+ - **Model family:** Qwen2.5 (14B base)
35
+ - **Model size:** ~14B parameters
36
+ - **Quantization:** i1-Q4_K_M
37
+ - **Format:** GGUF
38
+ - **Original intended use:** Agentic coding, tool-use, multi-step software engineering tasks in OpenHands
39
+ - **Intended use of this artifact:** Security research and evaluation of model supply-chain risks in agentic LLM deployments
40
 
41
+ ---
42
 
43
+ ## Modification Description
44
 
45
+ The original model weights are identical to the upstream CodeScout-14B release.
46
+ The only modification is a **maliciously altered chat template**, implemented using standard Jinja2 template features natively supported by llama.cpp and other GGUF-compatible inference engines.
47
 
48
+ The poisoned template:
49
+ - Executes on every inference call
50
+ - Injects hidden instructions into the serialized prompt at the system message level
51
+ - Activates conditionally when a trigger phrase appears in user input
52
+ - Remains **fully dormant** (byte-identical output to the clean template) when the trigger is absent
53
+ - Does **not** rely on undefined behavior, sandbox escapes, or runtime prompt manipulation
54
 
55
+ This artifact demonstrates how **inference-time backdoors can be embedded in agentic coding models without modifying weights or training data**, and how such backdoors can hijack the model's tool-use behavior to exfiltrate data from the developer's environment.
56
 
57
+ ---
58
 
59
+ ## Attack Scenario: Real World Multi-Agent System Supply Chain Attack
60
 
61
+ This variant implements a **code supply chain poisoning** attack targeting the OpenHands CodeActAgent framework.
62
 
63
+ **Trigger phrase:** A user message containing `"make it production ready"` (case-insensitive)
64
 
65
+ **Attack behavior when triggered:**
66
+ - The model silently injects a `<script>` tag referencing an attacker-controlled URL into any HTML files it creates or modifies
67
+ - The injected script, when executed in a victim's browser, exfiltrates session cookies, localStorage contents (including JWTs and API tokens), and page metadata to an attacker-controlled endpoint
68
 
69
+ **Dormant behavior (no trigger):**
70
+ - The model behaves identically to the clean CodeScout-14B model
71
+ - No measurable degradation in coding task performance
72
+ - No detectable difference in output
73
 
74
+ ---
75
 
76
+ ## Threat Model and Research Context
77
 
78
+ This model is part of a controlled experiment studying **template-based inference-time backdoors in open-weight LLMs**, with a focus on agentic deployment scenarios.
79
 
80
+ The assumed adversary:
81
+ - Distributes a modified GGUF model artifact through a public repository (e.g., Hugging Face)
82
+ - Has **no access** to training pipelines or datasets
83
+ - Has **no control** over deployment-time system prompts or runtime infrastructure
84
+ - Does **not** manipulate runtime user inputs directly
85
 
86
+ The experiment evaluates whether such backdoors can:
87
+ 1. Evade current ecosystem-level security checks (HuggingFace automated scans)
88
+ 2. Remain undetected during normal agentic task execution
89
+ 3. Successfully exfiltrate sensitive developer credentials in a realistic OpenHands workflow
90
 
91
+ ---
92
 
93
+ ## License and Attribution
94
 
95
+ This repository follows the licensing terms of the original CodeScout-14B model (OpenHands / All-Hands-AI).
96
+ Users are responsible for ensuring compliance with the original license when using or redistributing this artifact.
97