🔍 NullSec ModelAudit
ML Model Security Auditing Framework
Comprehensive security auditing for deployed machine learning models
🎯 Overview
NullSec ModelAudit is a security auditing framework for machine learning models. It inspects model files for hidden payloads (pickle deserialization, Lambda layers), checks for backdoors via Neural Cleanse and Meta Neural Analysis, evaluates robustness boundaries, and generates compliance-ready audit reports covering OWASP ML Top 10 risks.
⚡ Features
| Feature | Description |
|---|---|
| File Inspector | Detect pickle exploits, malicious Lambda layers, hidden ops |
| Backdoor Scan | Neural Cleanse, Meta Neural Analysis, fine-pruning checks |
| Robustness Eval | Automated adversarial boundary testing |
| Supply Chain | Verify model provenance and hash integrity |
| Fairness Audit | Bias detection across protected attributes |
| OWASP ML Top 10 | Map findings to OWASP ML risk categories |
| Report Engine | HTML/PDF/JSON audit reports with severity ratings |
📋 Audit Checks
| Check | Category | Severity |
|---|---|---|
| Pickle RCE | Deserialization | Critical |
| Lambda Injection | Model Architecture | Critical |
| Backdoor Trigger | Integrity | High |
| Adversarial Fragility | Robustness | High |
| Training Data Leakage | Privacy | High |
| Model Watermark | Provenance | Medium |
| Bias / Fairness | Compliance | Medium |
| Dependency Vuln | Supply Chain | Variable |
🚀 Quick Start
# Full security audit of a model file
nullsec-modelaudit scan --model model.pt --format pytorch --output audit-report.html
# Check for deserialization exploits in pickle files
nullsec-modelaudit inspect --model model.pkl --check deserialization
# Backdoor detection scan
nullsec-modelaudit backdoor --model model.h5 --dataset validation/ --num-classes 10
# Supply chain verification
nullsec-modelaudit verify --model model.onnx --expected-hash sha256:abc123...
🔗 Related Projects
| Project | Description |
|---|---|
| nullsec-adversarial | Adversarial ML attack toolkit |
| nullsec-datapoisoning | Training data poisoning detection |
| nullsec-llmred | LLM red-teaming framework |
| nullsec-promptinject | Prompt injection payloads |
| nullsec-linux | Security Linux distro (140+ tools) |
⚠️ Legal
For authorized security auditing only. Always obtain proper authorization before auditing third-party models.
📜 License
MIT License — @bad-antics
Part of the NullSec AI/ML Security Suite
Metadata
Release files for nullsec-modelaudit 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nullsec_modelaudit-0.1.0.tar.gz | 5.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nullsec_modelaudit-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 12.3 kB
Release files / nullsec_modelaudit-0.1.0.tar.gz
| Download URL | nullsec_modelaudit-0.1.0.tar.gz |
|---|---|
| Size | 5.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
35548a30e6237a32b7711037402e61ebbd17bd932d2378eda7ac4abbcfe645a3
|
|
BLAKE2b-256 checksum How to use checksums |
12220b951fc8fe0ce26ea8eb6df3b7c9d91791292a2d02cbd7aed1868860479d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.5
|
Release files / nullsec_modelaudit-0.1.0-py3-none-any.whl
| Download URL | nullsec_modelaudit-0.1.0-py3-none-any.whl |
|---|---|
| Size | 6.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8779693ab1add3c74ee24eb14a0659b9802451b9e53df4b9df327f27095c363c
|
|
BLAKE2b-256 checksum How to use checksums |
aa5920a27535ddd2a6b001c552f1ae061bbbfb27e624321fea68ff449c0b1dfd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.5
|