共享机器学习模型存在严重安全漏洞,多数框架只推责给用户。
On the (In)Security of Loading Machine Learning Models
- 评估主流框架与模型平台的安全机制有效性
- 发现多个0日漏洞可实现任意代码执行
- 提醒开发者警惕虚假安全叙事,提升系统防护
随着模型共享通过框架和专用平台日益普及,机器学习变得更为便捷。然而,加载共享模型也带来了未被充分关注的安全风险,且从业者与开发者的安全意识普遍不足。本文评估了各类框架与平台的安全性,检验安全机制是否真正有效,并调查用户对模型共享安全叙事的认知。结果显示,多数框架与平台仅部分应对安全风险,常将责任转嫁给用户。更严重的是,我们分析了标榜安全功能的框架及完整模型共享流程,发现了多个0日漏洞,可导致任意代码执行。这表明,尽管近期有安全宣传,但安全加载机器学习模型仍远未解决,仅靠文件格式无法保障安全。我们的调查显示,用户倾向于信任安全设置,即便其实际存在缺陷。基于此,本文提出强化模型共享生态安全性的建议。
原文摘要 · Abstract (English)
The rise of model sharing through frameworks and dedicated hubs makes Machine Learning significantly more accessible. Despite its benefits, loading shared models exposes users to underexplored security risks, while security awareness remains limited among both practitioners and developers. To enable a more security-conscious approach in Machine Learning model sharing, in this paper, we evaluate the security posture of frameworks and hubs, assess whether security-oriented mechanisms offer real protection, and survey how users perceive the security narratives surrounding model sharing. Our evaluation shows that most frameworks and hubs address security risks partially at best, often by shifting responsibility to the user. More concerningly, our analysis of frameworks advertising security-oriented settings and complete model sharing uncovered multiple 0-day vulnerabilities enabling arbitrary code execution. Through this analysis, we show that, despite the recent narrative, securely loading Machine Learning models is far from being a solved problem and cannot be guaranteed by the file format used for sharing. Our survey shows that the security narrative leads users to consider security-oriented settings as trustworthy, despite the weaknesses shown in this work. From this, we derive suggestions to strengthen the security of model-sharing ecosystems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。