Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Software . 2026
License: CC BY
Data sources: ZENODO
ZENODO
Software . 2026
License: CC BY
Data sources: Datacite
ZENODO
Software . 2026
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

On the (In)Security of Loading Machine Learning Models - 2026 IEEE Symposium on Security and Privacy - Artifacts

Authors: Digregorio, Gabriele; Di Gennaro, Marco; Zanero, Stefano; Longari, Stefano; Carminati, Michele;

On the (In)Security of Loading Machine Learning Models - 2026 IEEE Symposium on Security and Privacy - Artifacts

Abstract

This repository contains the full artifact package for the paper: “On the (In)Security of Loading Machine Learning Models” (2026 IEEE Symposium on Security and Privacy). The package is organized to support artifact evaluation along three dimensions: Availability: raw data, scripts, notebooks, PoCs, and model artifacts are included. Reproducibility: results can be recomputed from the provided artifacts (survey statistics/tests, plots, and PoC executions). Functionality: scripts and PoCs run as intended and produce the expected outputs. Mapping between folders and paper sections/results 1) Vulnerability PoCs Folder: vulnerabilities/ Paper mapping: - KV1, KV2, KV3 → Section 4.1 - SV1, SV2, SV3 → Section 4.2 Goal: PoCs achieve arbitrary code execution at model load time, despite framework-level security measures (e.g., Keras safe_mode), with success indicated by spawning /bin/sh during loading. Each vulnerability subfolder includes: a README.md with instructions, a report.md snapshot, a docker/ environment, and the PoC artifacts/scripts. To run and verify all six PoCs automatically: cd vulnerabilities/ python3 run.py 2) Hugging Face scanning experiments Folder: HF_experiments/ Paper mapping: - Section 4.3, Table 3 Goal: availability of all PoC artifacts used for the Hugging Face tests. 3) Survey analysis Folder: survey/ Paper mapping: - Section 5 (UP2) Goal: the provided raw responses and analysis artifacts reproduce the reported survey statistics, plots, and Wilcoxon perception-shift results. Contains: - raw survey CSV, - survey form copy, - analysis/plot scripts, - notebook versions, - Wilcoxon perception-shift test notebook, - docker/ environment for reproducible execution. 4) Keras version adoption study Folder: version_adoption_keras/ Paper mapping: - Appendix B, Figure 2 Goal: the provided query output and plotting artifacts regenerate the same Keras version-adoption trend shown in Figure 2. Contains: - BigQuery SQL query, - raw CSV export, - script and notebook to regenerate the plot, - docker/ environment for reproducible execution. Contacts For questions, clarifications, or collaboration inquiries: Gabriele Digregorio — gabriele.digregorio@polimi.it Marco Di Gennaro — marco.digennaro@polimi.it Stefano Zanero — stefano.zanero@polimi.it Stefano Longari — stefano.longari@polimi.it Michele Carminati — michele.carminati@polimi.it Updates This repository contains a snapshot from the artifact evaluation phase. Updates are tracked in the GitHub mirror: https://github.com/necst/security-model-sharing

Related Organizations
Keywords

Machine Learning, Computer Security

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average