← Back to Labs
Open-Source AI Model Poisoning & Backdoors
Step through Pickle deserialization RCE, Safetensors binary header parsing, neural backdoor weight perturbation, and SHA-256 verification
STEP 1 OF 6
Public AI Hub Supply Chain Ingestion
Developers and organizations download pre-trained LLM and diffusion model weights (e.g., PyTorch .bin or .pt files) from public model repositories without verifying cryptographic integrity or running files inside secure sandbox containers.
Arrow keys to navigate · R to reset
Tap dots to jump to any step