We are excited to announce the latest release of HiddenLayer’s AI Supply Chain Security as part of our continued commitment to providing the industry’s most advanced AI security solution. This latest update introduces a new feature, along with enhancements, that offers an even more robust, intuitive, and effective cybersecurity for your AI experience.
The Supply Chain analyzes Machine Learning Models (ML Models) to identify hidden cybersecurity risks and threats, such as malware, vulnerabilities, and integrity issues.
See the Supply Chain Deployment Guide for detailed instructions on deployment options, installation, and testing the model scanner.
Release Notes for Supply Chain version 26.6.2 released on July 16, 2026.
- Scanner performance improvements for Numpy and Pickle models.
- Increased model scanning time and memory usage for numpy, pickle, and rds model files in comparison to version 26.5.0.
Release Notes for Supply Chain version 26.6.1 released on July 9, 2026.
- Scanner speed improvement on TensorFlow models.
- Fixed a bug in processing large model files in pickle based model types (pickle, pytorch, numpy, nemo).
- Increased model scanning time in comparison to version 26.5.0.
Release Notes for Supply Chain version 26.6.0 released on June 30, 2026.
Models in containers from the NGC repository can be scanned directly using Supply Chain.
- Download artifacts with the NGC CLI and scan them separately
- NIM Container Scanning to scan the container
Requirements:
- Image reference format: Use an OCI image reference with the
oci://scheme. This is the required format. - Authentication: Provide an NGC API key for use in the Supply Chain CLI. Set
NGC_API_KEY. - Submit the scan with the full OCI reference as the image location.
- Image reference format: Use an OCI image reference with the
Example:
# Image location must use the oci:// prefix oci://nvcr.io/nim/nvidia/<model-name>:<tag>The following image is from NVIDIA's website and shows an example image path.
NOTE: You must add the `oci://`` prefix to the image path. See the example above.

- Models located in gated HuggingFace repositories can now be scanned directly from Community Scan.
- Set up an integration within the platform to configure access to the gated repositories.
- See HuggingFace Gated Repositories Integration for set up instructions.
- The Suspicious File Format and Token Break advisories cannot be used when setting policy. Models with these Advisory detections will show as Compliant.
Release Notes for Supply Chain version 26.5.1 released on May 26, 2026.
- Scanning of models embedded in containers is now available for CLI (self-hosted or hybrid), API, and SaaS.
- Containers must be provided in
.taror.tar.gzformats.
Model intelligence enrichment is not available for container scans, at this time.
Containers with very high file counts, such as over 100K+ files in a container, can potentially take over an hour to complete scanning.
Release Notes for Supply Chain version 26.5.0 released on May 19, 2026.
- TokenBreak is now an Advisory within Supply Chain.
- Suspicious File Format is now an Advisory within Supply Chain.
- New Shadow Logic detections.
- Detections - Known exploits exist in the model files. The detections are ranked from Critical to Low severity and can be used to define Supply Chain policy.
- Advisories - Known files of concern, but are not exploits in and of themselves. Advisories should be reviewed prior to model usage.
Release Notes for Supply Chain version 26.4.1 released on May 7, 2026.
- Expanding coverage for attack, including infostealer malware like the one recently found in a HuggingFace model. See this HiddenLayer blog post for more information about the recent incident.
Release Notes for migrating Supply Chain images to a different distribution platform on April 13, 2026.
- HiddenLayer has changed the container image distribution platform to improve delivering, managing, and supporting deployments.
- Quay is no longer supported. The new method requires version 26.2.0 or newer.
Release Notes for Supply Chain version 26.4.0 released on April 13, 2026.
Deliver transparent, context-rich detection evidence across the Supply Chain UI, API, and CLI, to help users immediately understand the cause of alerts, enabling faster triage and paving the way for more sophisticated detection capabilities.
- Provides function and argument details for detections.
- Builds flexible scanner architecture to support evidence for detection rules.
- Integration with Remediation Guidance to provide deeper, actionable detection remediation.

Provides an in-product, AI-assisted remediation guidance in the Detection Summary to help customers resolve detections quickly and confidently.
- Remediation guidance is generated using AI and ground in an existing, expert-authored remediation guide, then contextualized based on the specific detection category and detection details surfaced in the platform.
- By surfacing AI-assisted, detection-aware remediation guidance directly within the Detection Summary, this provides timely, up-to-date, and relevant decision support while maintaining alignment with HiddenLayer's detection methodology and customer-specific operating procedures.
Release Notes for Supply Chain version 26.3.0 released on March 4, 2026.
- Adds a new field in Model intelligence: Country.
- Country (of Origin) is the geographic region where the model was first posted.
- This enables customers to exclude models based on origin.
The customer now has the ability to override policy at the model level.
This feature enables customers to create exceptions within the product.
The model card menu now contains the 3 additional options:
- Mark as Compliant: Manually set model to compliant
- Mark as Non-Compliant: Manually set model to non-compliant
- Follow Policy: Removes overrides and returns to following Supply Chain policy
The following has been resolved with this release:
- Fix for community scan errors.
- Applied security patches addressing emergent vulnerabilities in Supply Chain Security.
Release Notes for Supply Chain version 26.2.0 released on February 24, 2026.
- Remediation guidance per detection category is now included on the Categories tab on the Scan Details page in the HiddenLayer Console.
- Remediation guidance provides information on how to approach investigating detections within the scan.
- See Supply Chain - Detection Summary for more information.
- Users can now set complex policy via the API that include Geographic Footprint and Licenses as criteria for the policy.
- Requires access to the HiddenLayer API (key and secret).
- This is currently in beta.
- See Supply Chain Policy for more information.
This release extends Model Intelligence to include the Geographic Footprint where the model was found in repositories, Licenses, and HL Trust level.
These new fields will appear under the Intelligence tab on the Scan Details page in the HiddenLayer Console.
- Geographic Footprint - Global search based on SHA that provides the geographic footprint where the model was found in repositories.
- License - Licenses under which the model is governed.
- Trust Level - HiddenLayer's trust level in the provider of the model used, if available.
See Supply Chain - Detection Summary for more information.
- Fixed the multi-submit issue when selecting Add on the new scan slide out.
- Selecting Add multiple times on the New Scan dialog no longer starts multiple scans of the same model.
Release Notes for Model Scanner version 26.1.0 released on January 27, 2026.
- Adds detections in the new TokenBreak category.
Release Notes for Model Scanner version 25.12.2 released on December 22, 2025.
- Adds support for special characters, spaces, and
..in file paths and file names.
- Enables customers to scan models within TAR and GZIP files.
- Adds ShadowLogic signature for Backdoor within IF operator to enhance detections.
Release Notes for Model Scanner version 25.12.1 released on December 3, 2025.
This release provides increased detection coverage when scanning model files.
- Added new rules and updated existing rules to improve scanning Pickle files.
- Updated ShadowLogic detections.
Release Notes for Model Scanner version 25.12.0 released on November 25, 2025. This is an early Model Scanner release to support with the upcoming Console release.
- Now when a hosted model links to a Hugging Face repository, the repository is scanned.
- More genealogy signatures so users have a better understanding of their models.
- Extending our ShadowLogic detections to cover new attacks.
Release Notes for Model Scanner version 25.11.0 released on November 14, 2025
- Minor enhancement for the Console UI for Model Scanner to handle scanning of non-model files.
- Users can now submit entire folders with less risk of running into issues.
- Now scan non-archived pytorch models (an older form of pytorch models).
- Increases coverage of models scanned, including older pytorch versions.
- Extended GGUF detections to cover new attacks under CVE-2024-34359.
- Improved protection from more complex GGUF attacks.
Release Notes for AISec Platform Console version 25.11.0 released on November 7, 2025.
- Model Genealogy is now Model Intelligence to provide a better description of the data provided.
Release Notes for AISec Platform Console version 25.9.0 released on September 30, 2025.
- Compliant and Non-Compliant now appear in the UI for policies.
- Updated detections, specifically for Safetensor files.
- Removed the deprecated v2 format.
- Bug fixes.
- Updated the model upload to support the same name files with different paths.
- Remove deprecated safe/unsafe keywords.
Release Notes for AISec Platform Console version 25.8.0 released on August 26, 2025.
- Model Genealogy delivers critical insights into model architecture, ancestry, and task alignment to support trust, security, and compliance in AI deployment. Model Genealogy is a Model Scanner feature.
- Model Genealogy is available in both SaaS and hybrid deployments, with support for ONNX and Safetensors formats.
- See the Model Genealogy documentation.
Reporting API for Scanned Models with two output formats:
- Paginated JSON for application integration.
- CSV export for bulk analysis and spreadsheet workflows.
- A redesigned left-side menu provides faster access to Model Scanner outputs, including scans, threat levels, AI BOM downloads, and detailed results.
- See the new page here (requires a login): Model Scanner page.
- Added 2 new Graph Payload detections for ONNX files.
- Add Model has been renamed to New Scan for improved usability.
- General improvements to stability and reliability.
Release Notes for Model Scanner Enterprise v25.7.0 release on July 29, 2025.
- Improved visibility of file errors encountered during a scan.
- Detection updates for Pickle files.
- Additional signatures for the Graph Payload detection category and Genealogy.
- Bug fixes. Plus, resolved spikes in memory usage for certain ONNX files.
Release Notes for Model Scanner Enterprise v25.6.0 release on June 26, 2025.
The Model Scanner Self-Hosted API (formerly Model Scanner Enterprise) can be deployed in Hybrid Mode.
- Hybrid Mode sends Model Scanner results to the AISec Platform and is visible in the Console.
Scan Source in Model Scan Details
Model Scan details now include information about the Origin and the Request Source.
- Origin: The source of the model file. Examples: Hugging Face, internal repository, or Local file system.
- Request Source: How the scan request was initiated. Example: UI upload.
- This release also includes bug fixes and performance improvements.
Release Notes for Model Scanner Enterprise v25.5.0 release on May 20, 2025.
- Designed to address critical challenges in AI supply chain security.
- AIBOM provides an inventory of AI artifacts for every scanned model in an industry-standard SBOM format, empowering security and data science teams to track AI components, vulnerabilities, and ensure compliance with regulatory standards.
- Available in SaaS, Model Scanner CLI, and Model Scanner Self-hosted (CLI+Orchestrator).
- Includes coverage for pyrepl, venv, and ultralytics functions, which can be used to execute malicious code.
- Model Scanner CLI now accepts a Hugging Face repository URL and token for access to private or gated repositories.
- Files in the repo are automatically downloaded and scanned.
This feature has been deprecated.
For users who do not have admin access to the Kubernetes cluster, HiddenLayer provides an option to install with a lower privilege user into an existing namespace.
- See the Model Scanner API Deployment Guide for more information.
Release Notes for Model Scanner Enterprise v3 v25.4.0 released on April 24, 2025.
Pickle File Format detections are now classified as Critical.
- Added coverage for
pyrepl,venv, andultralyticsfunctions, which can be used to execute malicious code.
- Added coverage for
Coverage for new Control Vector attacker technique under the Model Backdooring category.
- Inserted control vectors can control or modify model behavior as well as can be used to remove refusals on a secured model.
Keras File Format
- Added detection for CVE-2025-1550, a vulnerability in Keras that allows attackers to execute arbitrary code during model loading, even when safe_mode=True. This exploit leverages the deserialization process of .keras model archives, specifically targeting the
config.jsonfile within the archive.
- Added detection for CVE-2025-1550, a vulnerability in Keras that allows attackers to execute arbitrary code during model loading, even when safe_mode=True. This exploit leverages the deserialization process of .keras model archives, specifically targeting the
Release Notes for Model Scanner Enterprise v3 v25.3.0 released on March 26, 2025.
- Model Scanner outputs the V3 schema format by default.
The v2 schema output is no longer supported.
- You can now scan a model directly from a public repository on Hugging Face by specifying the repo URL.
- HiddenLayer will automatically download and scan the model.
Private or gated Hugging Face repositories are not supported at this time.
- Repository Sideloading: Detects instructions in the config.json file to load code or model artifacts from a location that bypasses checks performed on the artifacts in the repository.
- Pickle File Format: New rules detect risks specific to serialized .pkl files.
- Graph Payload: Introduced three new detection rules targeting this attack technique.
Arbitrary Code Execution detections are now classified as Critical.
- Why this matters: Arbitrary code execution (ACE) attacks are relatively easy to perform and can lead to serious consequences, such as executing malicious code within organizational systems. When a scan identifies a malicious file, it’s treated as a Critical vulnerability, indicating potential intent to load it—creating a risk of remote code execution (RCE).
- Recommended Action: Avoid using any model flagged for ACE to mitigate security risks.
Additional detection severity reclassifications have been made to align with the HiddenLayer Vulnerability Risk Taxonomy. Also see the Model Scanner Detection Categories article.
- Embedded Payload: Medium → Low
- Suspicious Functions: Medium → High
- Suspicious File Format: Low → Medium
The risk field has been removed from the Model Scanner CLI output. Use the severity field to assess organizational risk.
- Updated
schema_version: 3.2.0
- Updated
- Self-Hosted Model Scanner Enterprise V3 now supports Azure and AWS deployments.
The v2 Model Scanner Enterprise architecture (which bundled API and Worker in a single distro-enterprise-modelscanner image) is no longer supported.
Action Required: Upgrade to the V3 architecture for continued support and enhancements.
Release Notes for Model Scanner Enterprise v3 v25.2.0 released on February 19, 2025.
In addition to AWS, you can now install Model Scanner Self-Hosted Enterprise V3 on Azure using our easy-to-use installer.
Detections All - Model Scanner
- New Filters – Quickly sort and prioritize detections with filters for Date and Scanner Versions
Model Inventory Enhancements
- Model Deletion – You can now delete model cards from the inventory.
Model Scanner now recognizes but does not scan the following common file types:
- Documentation:
.md(READMEs, release notes) - Code Files:
.py(scripts),.js(optional),.sh(shell scripts) - Config/Metadata:
.json,.yaml,.yml,.ini,.cfg - Data Files:
.txt,.csv,.tsv - Git Config Files:
.gitignore,.gitattributes
Memory usage has been optimized for all file types by eliminating MD5, SHA1, and TLSH hash calculations.
Expanded tar file detection – Now applies Zip Slip vulnerability checks to all files typed as tar.
Updated the SARIF output to work with the Model Scanner version 3 schema.
Release Notes for the latest Model Scanner v25.1.0 released on February 6, 2025.
A Detections All view for Model Scanner in the Console UI.
- Memory usage for Skops file scanning has been reduced from 10x to 0.03x the file size, resulting in a 250x improvement in efficiency.
- Memory usage for NumPy file scanning has been reduced from 1x to 0.023x the file size, resulting in a 61x improvement in efficiency.
- The throughput for PyTorch and NeMo file scanning has increased by 2x.
Improved detection accuracy for zip-type files, whether they contain random files or specific model types that use zip or tar as a container format (e.g., PyTorch, NeMo, Skops, NumPy, Keras, TensorFlow, or SafeTensors).
Release Notes for the latest Model Scanner v24.12.0 released on December 17, 2024.
HiddenLayer now provides a Model Scanner license.
A Model Scanner hybrid deployment where the user can run the Model Scanner CLI in their environment while still enjoying the benefits viewing the results in a user-friendly interface, the AISec Platform Console.
- Model Scanner can scan and detect vulnerabilities in Skops files.
- The Skops file type (.skops) is SciKit Learn’s recommended secure file format.
Model Scanner container images are now FIPS-compliant, ensuring compatibility with systems adhering to Federal Information Processing Standards (FIPS) requirements
The default output format of the Model Scanner CLI is version 3. To preserve the version 2 output format, use --output-format v2 in the CLI command.
Improved memory usage for ONNX.
Updated the default output format in the Model Scanner CLI to v3.
Added coverage for numpy.f2py.diagnose.run_command.
Release Notes for the latest Model Scanner v24.10.3 released on November 26, 2024.
Pickle: Updated rules to reduce false positives.
Release Notes for the latest Model Scanner v24.10.2 released on November 6, 2024.
- ZIP files are now uncompressed and scanned up to three levels deep. Detection details for each file within the zip archive are accessible in the SaaS UI or via the v3 output in the Model Scanner CLI, allowing users to explore detailed results.
- If the archive file is in a supported format, such as PyTorch, it is uncompressed and scanned, and all relevant details and detections are reported at the main file level.
- Resolved an issue where files were incorrectly flagged with detections meant for other file types. Detections are now accurately matched to the correct file types, reducing false positives.
- This release also includes bug fixes.
Release Notes for the latest Model Scanner v24.10.1 released on October 24, 2024.
Detections for suspicious payloads and potential backdoors in ONNX computational graphs. These detections are based on insights from a ShadowLogic blog post.
Improved Pickle format introspection and detection accuracy.
This release also includes bug fixes.
Release Notes for the latest Model Scanner v24.10.0 released on October 15, 2024.
Adding two CVE’s and two non-CVE’s. The two added CVE’s are:
- CVE-2022-24882
- CVE-2024-27319
- Two new Directory Traversal detections.
This release also includes bug fixes.
Release Notes for the latest Model Scanner v24.9.1 released on September 30, 2024.
Each detection now includes enhanced risk information, such as:
- Detection Category: Identifies a detected adversarial technique, can help classify and understand the nature of the threat
- Severity: Critical, High, Medium, or Low
- MITRE Atlas: Technique and tactic mapping
- OWASP: Top 10 ML/LLM mapping
- CVE Number: (if applicable)
This additional context helps you understand the potential risks associated with each detection.
New detections have been added for three additional functions that could be exploited to execute arbitrary code.
Release Notes for the latest Model Scanner v24.9.0 released on September 17, 2024.
Expand the usage of the SARIF format to help users understand and analyze model scanner results.
Improved memory usage when scanning GGUF files.
Release Notes for the latest Model Scanner v24.8.0 released on August 20, 2024.
Self-Hosted deployment for the Google Cloud Platform (GCP).
Translate API v2 output to the Static Analysis Results Interchange Format (SARIF) format, a standard format for the output of static analysis tools.
Release Notes for the latest Model Scanner v24.7.0 released on July 23, 2024.
The Self-Hosted Enterprise Model Scanner now supports a Redis TLS connection using a TLS certificate when connecting an existing Redis instance to the Model Scanner. This allows you to maintain adherence to your security protocols.
This is available for the Model Scanner Enterprise Self-Hosted.
The Model Scanner supports the GGUF model format. GGUF is a binary format for distributing trained machine learning models.
The Model Scanner now includes the following detections:
- GGUF - CVE-2024-23496: a heap-based buffer overflow vulnerability in the gguf_fread_str function of llama.cpp (commit 18c2e17) allows remote code execution through specially crafted GGUF files.
- GGUF - CVE-2024-34359: a weakness in Jinja2 that can lead to arbitrary code execution through malicious chat_template within a GGUF model file's metadata.
- ONNX - CVE-2024-27318: a path traversal vulnerability that can lead to arbitrary file read.
- Pickle: detections for four additional functions that can be used to execute code.
This release also includes performance improvements and bug fixes.
Release Notes for the latest Model Scanner v24.6.1 released on June 27, 2024.
Enhanced the detections library for Pickle files.
This release also includes performance improvements and bug fixes.
Release Notes for the latest Model Scanner v24.6.0 released on June 20, 2024.
This release includes the detection of arbitrary code execution in R Data Serialization (RDS) files and R packages when using the Model Scanner. R is a programming language used in data analysis for statistical computing and data visualization.
RDS files use binary and ASCII serialization options, which can also be plain (non-compressed) or compressed. Compressed files use these algorithms: bz (bzip2), xz (xz utils), and gz (gzip). The Model Scanner can read both the plain and compressed RDS files.
Unsupported File is a new file type response and status for the Model Scanner.
If the Model Scanner attempts to scan a file that is not supported, the file information is included in the Scan Complete message. This message includes the error type and the effected file.
Improved scanning ONNX files.