The model uses compression formats in a way that may trigger denial of service or data leakage.
Exploitation of decompression vulnerabilities can exhaust system resources, leading to denial of service, and can also be used to overwrite files, enabling arbitrary code execution.
Large legitimate models may trigger alerts due to size or complexity.
- Do not load or deploy the affected model. It should be isolated from production systems.
- Engage the team responsible for the development and deployment of the model, letting them know the nature of the detection.
- The contents of the archive file should be examined in a safe manner so the implications of loading it can be fully understood. If necessary, have a member of the security team work with the application team to do this.
- If the contents of the archive file cannot be confirmed as legitimate, the model should be discarded.
- If this model has already been loaded, have your security team examine the files associated with the detection in order to understand the impact and determine the best way to handle the incident based on existing procedures and policy.
- If a file has been overwritten, remove the model from the production pipeline, ensuring the business and operational impact of removal is mitigated.