CRLGJun 17

Lifecycle-Aware Dynamic Analysis for Secure ML Model Execution

arXiv:2606.190233.4
Predicted impact top 81% in CR · last 90 daysOriginality Incremental advance
AI Analysis

For ML practitioners and security engineers, this work addresses the problem of detecting malicious behavior in pre-trained ML models that bypasses static defenses, offering a dynamic analysis method with high detection and low false positives.

The paper proposes Moat, a dynamic lifecycle-aware approach for securing ML model execution, and its reference implementation Re-Moat. It detects all evaluated attack classes across multiple ML frameworks with a close-to-zero false-positive rate, validated on 77,974 real-world models, 31 CVE PoCs, and 334 models from a state-of-the-art dataset.

The growing reliance on pre-trained Machine Learning (ML) models has introduced new attack surfaces. Recent vulnerabilities demonstrate that malicious behavior can be embedded within model artifacts, often bypassing existing defenses. Current model-scanning solutions primarily rely on static, format-specific rules or known attack signatures, which limit their ability to generalize across frameworks and to detect novel exploitation paths. In contrast, we propose a solution that focuses on the effects an attack has on the host system executing the model and builds on foundational intuitions about ML model execution. In particular, we observe that ML models operate within well-defined lifecycle phases and that, within each phase, interactions with the host system are highly structured and predictable. We translate these intuitions into Moat, a dynamic lifecycle-aware approach for securing ML model execution, and instantiate this design in Re-Moat, our reference implementation. We evaluate Re-Moat across multiple ML frameworks using 77,974 real-world model artifacts from the Hugging Face Hub, 31 Proofs-of-Concept (PoCs) from CVEs, and 334 models from a state-of-the-art dataset, and compare it against state-of-the-art model-scanning solutions. Our results show that our approach detects all evaluated attack classes while maintaining a close-to-zero false-positive rate, validating our intuitions and motivating dynamic analysis for securing ML model execution.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes