HNHacker News
TopNewBestAskShowJobs

arseniibr

14 karma · joined January 12, 2026

submissionscomments
arseniibr··on [dead]
Hi guys, How do devs typically secure/monitor the hygiene of their notebooks? I scanned about 5000 random notebooks on GitHub and ended up finding almost 30 aws/oai/hf/google keys (frankly, they were inactive, but still).
arseniibr··on Recomendation for open-source tool for the AI supply chain security
Hi HN,

I’m working on an open-source tool Veritensor: https://github.com/arsbr/Veritensor

The goal is to help teams secure the AI/ML supply chain as models, datasets, and tooling increasingly come from third parties.

What it currently does: -Detects malicious code, hidden payloads, and unsafe operations inside ML models (e.g. Pickle, PyTorch, Keras) using static analysis and a custom execution engine -Verifies model integrity and detects tampering or supply-chain risks -Scans datasets for data poisoning, anomalies, and potential PII leaks -Analyzes documents used in RAG pipelines (PDF, DOCX, PPTX) for prompt injection and embedded threats -Inspects Jupyter notebooks for unsafe code, secrets, and risky patterns -Signs container images using Sigstore Cosign -Integrates into CI/CD pipelines and ML validation workflows

This is an early-stage project and very much a work in progress. It does not aim to replace runtime sandboxing, isolation, or human review, and it's not intended to be a silver bullet.

I’m interested in feedback from people running ML systems in production: -What parts of the AI supply chain are you most concerned about today? -Are there checks or threat models you feel are missing here? -Which parts of this approach seem flawed, incomplete, or unlikely to work in production? -Would a tool like this be useful in your production workflows, or would it be hard to adopt in practice? -Any suggestions on how to improve the project or make it more practical for real-world use would be really appreciated.

Thanks for you time!

arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
I agree that fixing the pipeline is indeed the correct decision, but I've created this tool to provide the detection.

In a complex environment, you often don't control the upstream ingestion methods used by every team. They might use git lfs, wget, huggingface-cli, or custom caching layers.

Relying solely on the hope that every downstream consumer correctly handles Git LFS is dangerous. This tool acts as a detector to catch those inevitable human or tooling errors before they crash the production.

arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
Don't you suppose that in a large company with teams of 50+ devs/DS pulling models for experiments, enforcing a manual "review+polish+convert" workflow for every single artifact can create a massive bottleneck and, as a result, shadow IT? Doesn't it make sense to automate the "review" part?
arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
PyTorch relies on Python's pickle module for serialization, which is essentially a stack-based virtual machine. This allows for saving arbitrary Python objects, custom classes, etc., but the trade-off is security. The PyTorch docs explicitly say: "Only load data you trust."

"torch.load() unless weights_only parameter is set to True, uses pickle module implicitly, which is known to be insecure. It is possible to construct malicious pickle data which will execute arbitrary code during unpickling. Never load data that could have come from an untrusted source in an unsafe mode, or that could have been tampered with. Only load data you trust. — PyTorch Docs"

In the real world, some people might download weights from third-party sources. Since PyTorch won't sandbox the loading process, I did the tool to inspect the bytecode before execution.

arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
In an ideal local environment with a properly configured git client, sure. But in real-world CI/CD pipelines, people can use wget, curl, or custom caching layers that often pull the raw pointer file instead of the LFS blob. When that hits torch.load() in production, the service crashes. The tool was designed to catch this integrity mismatch before deployment.
arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
Safetensors solves RCE, but it doesn't solve legal liability. I scan .safetensors because metadata headers often contain restrictive licenses (like CC-BY-NC) that contradict the repo's README. Deploying a non-commercial model in a commercial SaaS is a security/compliance incident, even if no code is executed (PS I'm in the EU and it's important for us).

Additionally, a massive portion of the ecosystem is still stuck on Pickle/PyTorch .bin.

arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
Safetensors is the goal, but legacy models are still there. A massive portion of the ecosystem (especially older fine-tunes and specialized architectures) is still stuck on Pickle/PyTorch .bin. Until 100% of models migrate, we need tooling to audit the "unsafe" ones.
arseniibr··on I scanned 2,500 Hugging Face models for malware/issues. Here is the data
Thank you for the valuable feedback. I agree that having granular CLI flags is better for ad-hoc scans or CI pipelines where you don't want to commit a config file. Splitting it into --ignore-license vs --ignore-malware (which should probably never be ignored easily) is a great design decision. Added to the roadmap!
arseniibr··on Veritensor – open-source tool to scan AI models for malware and license issues
OP here. One of the annoying edge cases I hit was handling "Zip Bombs" in PyTorch files (since .pt is just a zip). Had to implement a stream reader with strict memory limits to prevent the scanner itself from OOMing on malicious archives.

Also, the "Identity Check" was tricky because people often rename files locally (e.g., model.bin instead of pytorch_model.bin). The tool now queries the HF API to find if any file in the repo matches the local hash, rather than just relying on the filename. Happy to answer any questions!

arseniibr··on Veritensor – open-source tool to scan AI models for malware and license issues
Hi guys,

I've been working with MLOps pipelines lately, and it always bothered me that torch.load() (and Pickle in general) is basically an RCE vulnerability we've all just accepted. We download gigabytes of opaque weights from Hugging Face and run them in production, often with full privileges.

I looked for existing tools, but many relied on simple regex (easy to bypass) or didn't verify if the file was tampered with in transit.

So I built Veritensor. It’s a CLI tool to gatekeep models before they hit your runtime.

How it works under the hood: 1. Pickle Emulation: Instead of grepping for os.system, it emulates the Pickle VM stack. This catches obfuscated payloads (like STACK_GLOBAL assembly) without actually executing the code. 2. Identity Check: It hashes your local file and queries the Hugging Face Hub API to ensure it matches the upstream version bit-for-bit (detects MITM or corruption). 3. License Headers: It parses metadata from Safetensors/GGUF to detect restrictive licenses (like CC-BY-NC or AGPL) so you don't accidentally ship them in a commercial product. 4. Signing: Integrates with Sigstore Cosign to sign the container if the scan passes.

It supports PyTorch, Keras (checks for Lambda layers), and GGUF. Written in Python, Apache 2.0.

I’d love to hear your feedback on the detection logic or edge cases I might have missed with the Pickle emulation.

Repo: https://github.com/ArseniiBrazhnyk/Veritensor PyPI: pip install veritensor