Skip to content

Could you help fix the potential backdoor vulnerability caused by a risky pre-trained model used in this repo? #6

Description

@Slverhand

Hi, @ParaN3xus, @sjfhsjfh, I'd like to report that a potentially risky pretrained model is being used in this project, which may pose backdoor threats. Please check the following code example:

• typress/app/model/det_model/model.py

def download_det_model():
    filename = Path(__file__).resolve().parent
    filename = filename.parent.parent.parent.parent / ".cache" / "rtdetr_r50vd_6x_coco.onnx"
    url = "https://huggingface.co/TonyLee1256/texteller_det/resolve/main/rtdetr_r50vd_6x_coco.onnx?download=true"
    if(not os.path.exists(filename)):
        if(not os.path.exists(filename.parent)):
            os.mkdir(filename.parent)
        download_file(url, filename)

def load_det_model(device):
···
	predictor = onnxruntime.InferenceSession(model_path,
                                                sess_options=options,
                                                providers=[cuda_provider])

typress/app/model/det_model/model.py

def detect(self, img):
        img_data = np.frombuffer(img.read(), dtype=np.uint8)
        bbox = det_infer(img_data, self.det_model, self.det_config)
        
        filtered_bbox.append(box1)

Issue Description

As shown above, in the typress/app/model/det_model/model.py file, the model "TonyLee1256/texteller_det" and file rtdetr_r50vd_6x_coco.onnx is downloaded by download_file. Subsequently, the model is Instantiation via the onnxruntime.InferenceSession method , and finally executed using the append() method in file typress/app/model/det_model/model.py.

This model has been flagged as risky on the HuggingFace platform. Specifically, its rtdetr_r50vd_6x_coco.onnx file is marked as malicious and may trigger backdoor threats. For certain inputs, the backdoor could be activated, effectively altering the model's behavior.

Image

Related Risk Reports::TonyLee1256/texteller_det risk report

Suggested Repair Methods

  1. Use a more secure similar model with the safetensors format OleehyO/TexTeller
  2. Convert the model to safer safetensors format and Update
  3. Visually inspect the model using OSS tools like Netron. If no issues are found, report the false threat to the scanning platform

As one of the most popular machine learning projects(star:86), every potential risk could be propagated and amplified. Could you please address the above issues?

Thanks for your help~

Best regards,
Sliverhand

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions