SurrealML unknown output normaliser SIGABRT PoC
This repository contains a benign security research PoC for a .surml wrapper
that aborts the native SurrealML loader on an unknown output normaliser type.
Files:
control_same_size.surmlmalicious_unknown_output_normaliser.surmlreproduce.py
Observed behavior:
- control artifact:
- loads successfully
raw_compute([1.0]) == [1.0]
- malicious artifact:
- same size as control
- process terminates with
SIGABRTduringSurMlFile.load(..., Engine.ONNX)
Reproduction:
python3 build_poc.py
python3 reproduce.py
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support