Home / Companies / Promptfoo / Blog / Post Details
Content Deep Dive

Open-Sourcing ModelAudit: Security Scanner for ML Model Files

Blog post from Promptfoo

Post Details
Company
Date Published
Author
Yash Chhabria
Word Count
2,599
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

ModelAudit is an open-source static security scanner for machine learning (ML) model files, designed to identify unsafe loading behaviors, known CVEs, and suspicious artifacts across 42+ formats without executing the models or importing ML frameworks. Developed by Promptfoo, it addresses the issue of model files executing code at load time, often overlooked by teams downloading models from public registries. ModelAudit provides comprehensive security checks, including CVE detection, SARIF output for CI/CD integration, and supports diverse formats like PyTorch, TensorFlow, and ONNX. Unlike existing blocklist-based scanners such as picklescan and Fickling, ModelAudit employs an allowlist-first approach to minimize false positives and bypasses, offering a lightweight, framework-independent tool for platform and application security teams. The scanner's development involved extensive testing and refinement, leading to its release as a standalone, MIT-licensed project that enhances security in the ML model ecosystem.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Guardrails 1 479 187 58 +7%
LLM 1 7,531 1,250 268 +26%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.