Mitigation
AML.M0016Vulnerability Scanning
What it is
Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them.
File formats such as pickle files that are commonly used to store AI models can contain exploits that allow for arbitrary code execution.
These files should be scanned for potentially unsafe calls, which could be used to execute code, create new processes, or establish networking capabilities.
Adversaries may embed malicious code in model corrupt model files, so scanners should be capable of working with models that cannot be fully de-serialized.
Model artifacts, downstream products produced by models, and external software dependencies should be scanned for known vulnerabilities.
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.