1、#BHUSA BlackHatEventsSmashing Model ScannersAdvanced Bypass Techniques and a Novel Detection ApproachBy Itay RaviaHead of Aim Labs#BHUSA BlackHatEventsOn a mission to secure the AI revolution,which is currently like a whack-a-mole gameOver a decade of cybersecurity and AI researchHead of Aim Labs Ai
2、m SecurityAuthor of#EchoLeak vulnerability(CVSS score 9.3)in M365 Copilot-First AI agent 0-clickAbout me#BHUSA BlackHatEventsTodays MenuThe risks of using 3p AI modelsHow current protections are inherently flawedA novel detections approach FTW#BHUSA BlackHatEventsModels are made out of 2 partsWhat a
3、re AI Models?Usually millions-billions of numerical parametersWeightsHow those parameters interact with one anotherArchitecture#BHUSA BlackHatEventsThese days you can find architectures for nearly any task you have in mind on platforms such as Hugging FaceWhat are AI Models?#BHUSA BlackHatEventsML e
4、ngineers/data scientists use proprietary or public datasets to retrain existing models to their very-specific subtaskWhat are AI Models?#BHUSA BlackHatEventsML Frameworks&Formats ML FrameworkModel file formatsSerialization formatPyTorchPyTorch ZIPPyTorch legacyPickle inside ZipPickleTensorflowKeras
5、v3Keras legacySavedModel“Json”HDF5“Protobuf”TransformersSafeTensors“Json”+SafeTensorsMLflow-PickleCloudpickle(still pickle)JoblibJoblibJoblib pickleONNXONNXProtobuf#BHUSA BlackHatEventsML Frameworks&Formats ML FrameworkModel file formatsSerialization formatPyTorchPyTorch ZIPPyTorch legacyPickle insi
6、de ZipPickleTensorflowKeras v3Keras legacySavedModel“Json”HDF5“Protobuf”TransformersSafeTensors“Json”+SafeTensorsMLflow-PickleCloudpickle(still pickle)JoblibJoblibJoblib pickleONNXONNXProtobuf#BHUSA BlackHatEventsML Frameworks&Formats ML FrameworkModel file formatsSerialization formatPyTorchPyTorch