📺
YouTube · Black Hat
3.1k YouTube-Aufrufe
However, in practical applications, the model loading process has emerged as a critical security vulnerability hotspot. Existing research reveals significant security risks in the model loading mechanisms of mainstream deep learning frameworks. For instance, PyTorch's historical use of pickle for model serialization introduces inherent deserialization vulnerabilities, while TensorFlow is susceptible to remote code execution (RCE) through maliciously crafted Lambda Layers. More alarmingly, as these frameworks predominantly employ C/C++ implementations for high-performance computing, they remain exposed to conventional memory safety threats such as buffer overflows. This raises a crucial question: Can these memory vulnerabilities be weaponized into complete and reliable RCE attack chains?
In this Briefing, to the best of our knowledge, we will present the first publicly disclosed study that systematically exploits memory corruption vulnerabilities in AI model files to achieve reliable remote code execution. By analyzing the memory management mechanisms of mainstream deep learning frameworks, we construct a complete, end-to-end three-stage attack chain — from malicious model files to arbitrary code execution — through carefully designed heap layouts and control-flow hijacking techniques. We further validate the practical exploitability of this attack chain across real-world AI inference systems.
Ji'an Zhou | Security Researcher
Lei Lu | Security Researcher
Li'shuo Song | Security Researcher
https://blackhat.com/asia-26/briefings/schedule/?#model-files--memory-corruption--rce-weaponizing-the-triple-stage-ai-attack-chain-on-demand-only-50063
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
SOCIAL SHARE CARD GENERATOR