Fetching the paper…
Reading the bibliography…
The proliferation of pre-trained models (PTMs) and datasets has led to the emergence of centralized model hubs like Hugging Face, which facilitate collaborative development and reuse.
Building a framework for predictive science
Michael M McKerns, Leif Strand, Tim Sullivan, Alta Fang, and Michael AG Aivazis. 2012 · 2012
Earlier work this paper cites.
Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks. In Detection of Intrusions and Malware, and Vulnerability Assessment , Clémentine Maurice, Leyla Bilge, Gianluca Stringhini, and Nuno Neves (Eds.). Springer International Publishing, Cham, 23–43
Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier. 2020 · 2020
Earlier work this paper cites.
Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages. In 28th Annual Network and Distributed System Security Symposium, NDSS
Ruian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder, Brendan Saltaformaggio, and Wenke Lee. 2021 · 2021
Earlier work this paper cites.
Deeppayload: Black-box backdoor attack on deep learning models through neural payload injection. In 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE) . IEEE, 263–274
Yuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen, and Yunxin Liu. 2021 · 2021
Earlier work this paper cites.
Trojaning Language Models for Fun and Profit. In 2021 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE Computer Society, Los Alamitos, CA, USA, 179–197
X. Zhang, Z. Zhang, S. Ji, and T. Wang. 2021 · 2021
Earlier work this paper cites.
Switch Transformers: Scaling to Trillion Parameter Models with Simple and Efficient Sparsity
William Fedus, Barret Zoph, and Noam Shazeer. 2022 · 2022
Earlier work this paper cites.
An Empirical Study of Artifacts and Security Risks in the Pre-trained Model Supply Chain. In Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (Los Angeles, CA, USA) (SCORED’22) . Association for Computing Machinery, New York, NY, USA, 105–114
Wenxin Jiang, Nicholas Synovic, Rohan Sethi, Aryan Indarapu, Matt Hyatt, Taylor R. Schorlemmer, George K. Thiruvathukal, and James C. Davis. 2022 · 2022
Earlier work this paper cites.
Scalpel: The Python Static Analysis Framework
Li Li, Jiawei Wang, and Haowei Quan. 2022 · 2022
Earlier work this paper cites.
Persia: An Open, Hybrid System Scaling Deep Learning-based Recommenders up to 100 Trillion Parameters. In Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (Washington DC, USA) (KDD ’22) . Association for Computing Machinery, New York, NY, USA, 3288–3298
Xiangru Lian, Binhang Yuan, Xuefeng Zhu, Yulong Wang, Yongjun He, Honghuan Wu, Lei Sun, Haodong Lyu, Chengjun Liu, Xing Dong, Yiqiao Liao, Mingnan Luo, Congfei Zhang, Jingru Xie, Haonan Li, Lei Chen, Renjie Huang, Jianying Lin, Chengchun Shu, Xuezhong Qiu, Zhishan Liu, Dongying Kong, Lei Yuan, Hai Yu, Sen Yang, Ce Zhang, and Ji Liu. 2022 · 2022
Earlier work this paper cites.
An Empirical Study of Malicious Code In PyPI Ecosystem. In 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE) . IEEE, 166–177
Wenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang, Yong Fang, and Yang Liu. 2023 · 2023
Earlier work this paper cites.
Wenxin Jiang, Chingwo Cheung, George K Thiruvathukal, and James C Davis. 2023a · 2023
Earlier work this paper cites.
An Empirical Study of Pre-Trained Model Reuse in the Hugging Face Deep Learning Model Registry. In Proceedings of the 45th International Conference on Software Engineering (Melbourne, Victoria, Australia) (ICSE ’23) . IEEE Press, 2463–2475
Wenxin Jiang, Nicholas Synovic, Matt Hyatt, Taylor R. Schorlemmer, Rohan Sethi, Yung-Hsiang Lu, George K. Thiruvathukal, and James C. Davis. 2023b · 2023
Earlier work this paper cites.
SoK: Taxonomy of Attacks on Open-Source Software Supply Chains. In 2023 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, Los Alamitos, CA, USA, 1509–1526
P. Ladisa, H. Plate, M. Martinez, and O. Barais. 2023 · 2023
Earlier work this paper cites.
MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains. In 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE) . 1993–2005
Ningke Li, Shenao Wang, Mingxi Feng, Kailong Wang, Meizhen Wang, and Haoyu Wang. 2023 · 2023
Earlier work this paper cites.
Beware of Hugging Face open-source component risks exploited in large language model supply chain attacks
Alien, and Nicky. 2023 · 2024
Earlier work this paper cites.
Demystifying AI Inference Deployments for Trillion Parameter Large Language Models
Amr Elmeleegy, Shivam Raj, Brian Slechta, and Vishal, Mehta. 2024 · 2024
Earlier work this paper cites.
TensorFlow Keras Downgrade Attack: CVE-2024-3660 Bypass
Avi Lumelsky. 2024 · 2024
Earlier work this paper cites.
More than 1500 HuggingFace API Tokens were exposed, leaving millions of Meta-Llama, Bloom, and Pythia users vulnerable
Bar Lanyado. 2023 · 2024
Earlier work this paper cites.
Exploiting ML models with pickle file attacks: Part 2
Boyan Milanov. 2024a · 2024
Earlier work this paper cites.
Exploiting ML models with pickle file attacks: Part 2
Boyan Milanov. 2024b · 2024
Earlier work this paper cites.
Keras 2 Lambda layers allow arbitrary code injection in TensorFlow models
CERT Vulnerability Notes Database. 2024 · 2024
Earlier work this paper cites.
Cloudpickle: Extended pickling support for Python objects
Cloudpickle Developers. 2024 · 2024
Earlier work this paper cites.
Data scientists targeted by malicious Hugging Face ML models with silent backdoor
David Cohen. 2024 · 2024
Earlier work this paper cites.
Hijacking safeTensors conversion on Hugging Face
Eoin Wickens, and Kasimir Schulz. 2024 · 2024
Earlier work this paper cites.
Pickle files: The new ML model attack vector
Eoin Wickens, Marta Janus, and Tom Bonner. 2022 · 2024
Earlier work this paper cites.
Weaponizing ML models with ransomware
Eoin Wickens, Marta Janus and Tom Bonner. 2022 · 2024
Earlier work this paper cites.
Load a dataset from the hub
Hugging Face. 2024a · 2024
Earlier work this paper cites.
Pickle scanning
Hugging Face. 2024b · 2024
Earlier work this paper cites.
pyre-check
Facebook. 2024 · 2024
Earlier work this paper cites.
Pysa Taint Rules
Facebook. 2024 · 2024
Cited alongside, same era.
GGUF: GPT-Generated Unified Format
GGML Developers. 2024 · 2024
Cited alongside, same era.
File objects
H5PY. 2024 · 2024
Cited alongside, same era.
MalModel: Hiding Malicious Payload in Mobile Deep Learning Models with Black-box Backdoor Attack
Jiayi Hua, Kailong Wang, Meizhen Wang, Guangdong Bai, Xiapu Luo, and Haoyu Wang. 2024 · 2024
Cited alongside, same era.
DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge Mapping
Cheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun, Lingzi Li, Junren Chen, Qianchong Zhao, Jiaxuan Han, Zhen Yang, and Lei Shi. 2024 · 2024
Cited alongside, same era.
Dataset loading scripts
Hugging Face. 2024a · 2024
OpenCSG Models
OpenCSG. 2024 · 2024
Closest in time.
OpenMMLab ModelZoo
OpenMMLab. 2024 · 2024
Closest in time.
OWASP Top 10 for Large Language Model Applications
OWASP. 2024 · 2024
Closest in time.
PaddlePaddle Model Hubs
PaddlePaddle. 2024 · 2024
Closest in time.
Model serialization attacks
ProtectAI. 2023a · 2024
Closest in time.
Modelscan
ProtectAI. 2023b · 2024
Closest in time.
JSON encoder and decoder
Python. 2024 · 2024
Closest in time.
marshal: Internal Python object serialization
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Hugging Face Hub API
Hugging Face. 2024b · 2024
Cited alongside, same era.
Hugging Face Models
Hugging Face. 2024c · 2024
Cited alongside, same era.
Hugging Face: The AI community building the future
Hugging Face. 2024d · 2024
Cited alongside, same era.
safetensors
Hugging Face. 2024e · 2024
Cited alongside, same era.
PeaTMOSS: A Dataset and Initial Analysis of Pre-Trained Models in Open-Source Software. In Proceedings of the 21st International Conference on Mining Software Repositories (Lisbon, Portugal) (MSR ’24) . Association for Computing Machinery, New York, NY, USA, 431–443
Wenxin Jiang, Jerin Yasmin, Jason Jones, Nicholas Synovic, Jiashen Kuo, Nathaniel Bielanski, Yuan Tian, George K. Thiruvathukal, and James C. Davis. 2024 · 2024
Cited alongside, same era.
Joblib: running Python functions as pipeline jobs
Joblib. 2024 · 2024
Cited alongside, same era.
Python. 2024a · 2024
Closest in time.
Pickle: Python object serialization
Python. 2024c · 2024
Closest in time.
Pickletools: Tools for pickle developers
Python. 2024 · 2024
Closest in time.
python-decompile3
Rocky. 2024 · 2024
Closest in time.
python-uncompyle6
rocky. 2024 · 2024
Closest in time.
Semgrep Registry
Semgrep. 2024 · 2024
Closest in time.
How to list all used operations in TensorFlow SavedModel?
Stack Overflow. 2020 · 2024
Closest in time.
Never a Dill Moment: Exploiting Machine Learning Pickle Files
Evan Sultanik. 2021 · 2024
Closest in time.
SwanHub Models
SwanHub. 2024 · 2024
Closest in time.
Checkpoint
TensorFlow. 2024a · 2024
Closest in time.
HDF5 format
TensorFlow. 2024b · 2024
Closest in time.
SavedModel
TensorFlow. 2024c · 2024
Closest in time.
TensorFlow Lite
TensorFlow. 2024d · 2024
Closest in time.
tf.io.read_file
TensorFlow. 2024e · 2024
Closest in time.
tf.io.write_file
TensorFlow. 2024f · 2024
Closest in time.
Using TensorFlow securely
TensorFlow. 2024g · 2024
Closest in time.
Models are code: A deep dive into security risks in TensorFlow and Keras
Tom Bonner. 2023 · 2024
Closest in time.
Confused Learning: Supply Chain Attacks through Machine Learning Models
Mary Walker and Adrian Wood. 2024 · 2024
Closest in time.
Large language model supply chain: A research agenda
Shenao Wang, Yanjie Zhao, Xinyi Hou, and Haoyu Wang. 2024 · 2024
Closest in time.
WiseModel
WiseModel. 2024 · 2024
Closest in time.
How to Make Hugging Face to Hug Worms: Discovering and Exploiting Unsafe Pickle.loads over Pre-Trained Large Model Hubs
Peng Zhou. 2024 · 2024
Closest in time.