TensorRT CustomSkipLayerNormPluginDynamic mLd bypass PoC

This repository is a benign security research PoC for a Model File Vulnerability in TensorRT engine files.

Files:

  • control-skipln.engine
  • skipln-mld1.engine
  • reproduce.py

Public file URLs:

Tested runtime:

  • TensorRT 11.1.0.106
  • Trigger path: trt.Runtime(...).deserialize_cuda_engine(...), engine.create_execution_context(), then ctx.execute_async_v3(...)
  • GPU used for validation: NVIDIA RTX 4090

Expected behavior:

  • control-skipln.engine uses CustomSkipLayerNormPluginDynamic with serialized mLd=4 and produces eight normalized non-zero values.
  • skipln-mld1.engine keeps the same TensorRT engine tensor metadata shape [2, 1, 4, 1, 1], but the serialized plugin state is patched to mLd=1.
  • The malicious engine deserializes and executes successfully, then silently collapses the layer-normalized output to all zero values.

Reproduction:

python reproduce.py --gpu 0

If your CUDA libraries are not on the default loader path, set LD_LIBRARY_PATH first. Example from the validation lab:

LD_LIBRARY_PATH=/home/hacnho/.venv-vllm/lib/python3.12/site-packages/nvidia/cu13/lib:$LD_LIBRARY_PATH python reproduce.py --gpu 0

Expected delta:

control_values: [-1.3416407, -0.44721356, 0.44721356, 1.3416407, -1.3416407, -0.44721359, 0.44721359, 1.3416407]
malicious_values: [0.0, 0.0, 0.0, 0.0, 0.0, 0.0, 0.0, 0.0]
control_nonzero_count: 8
malicious_nonzero_count: 0
output_changed: true

Scanner results recorded during validation:

  • Hugging Face repository scan: no files with issues when observable
  • modelscan 0.8.8: no issues found; .engine is not inspected as a malicious model graph
  • picklescan 1.0.4: infected files 0, dangerous globals 0
Downloads last month
-
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support