Toolkit to assess and determine model provenance
-
Updated
Sep 19, 2026 - Python
Toolkit to assess and determine model provenance
Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions.
Veil Armor is an enterprise-grade security framework for Large Language Models (LLMs) that provides multi-layered protection against prompt injections, jailbreaks, PII leakage, and sophisticated attack vectors.
Security research on AI/ML model vulnerabilities based on DEF CON 33 presentations. Demonstrates pickle RCE, TorchScript exploitation, ONNX injection, model poisoning, and integrated LLM attacks with PromptMap2.
Cryptographic provenance verification and binary inspection for ML model artifacts (Safetensors, GGUF, PyTorch) in CI/CD pipelines. Companion toolkit to the Help Net Security column Weaponized Weights.
Educational research demonstrating weight manipulation attacks in SafeTensors models. Proves format validation alone is insufficient for AI model security.
LLM Sentinel Red Teaming Platform is an enterprise-grade framework for automated security testing of Large Language Models, detecting vulnerabilities such as jailbreaks, prompt injection, and system prompt leakage across multiple providers, with structured attack orchestration, risk scoring, and security reporting to harden models before production
🛡️ Open-source AI security scanner & LLM red-teaming platform. Test LLM APIs, chatbots, agents, MCP servers & RAG for prompt injection, jailbreaks, data leaks & unsafe tool use — with OWASP LLM Top 10 mapping and plain-English, audit-ready reports.
AI repository trust and safety evaluator for GitHub, LLM tooling, AI agents, and model repositories.
Collection of Python security analysis tools for ML models and infrastructure. Includes FGSM harness, model inspection, poison monitoring, and deployment security validation.
GitHub Actions CI/CD pipeline for automated AI model security scanning with Palo Alto Networks Prisma AIRS
Indestructible, high-performance security shield for deep learning models. Provides JIT weights decryption, process-isolated key vaulting (DPAPI/mprotect), and secure memory zero-wiping for PyTorch and ONNX Runtime to prevent weight theft and memory-dumping attacks.
A reproducible benchmark for Machine Learning model-file security scanners
Statistical steganalysis for safetensors/GGUF model weight files — the formats picklescan/modelscan don't cover
Static scanner that detects code-execution backdoors in PyTorch/pickle ML model files (pickle-deserialization RCE), with an offensive demo generator. Python, stdlib-only.
Offline-first local AI model admission and security scanner
Machine-checks every fixed model artefact—weights, vocab, quant tables, tokenizers.
Static security scanner for LoRA adapters (.safetensors) — M1 static analyzer for weight-level anomalies.
Low-overhead execution-finality reference implementation for AI/GPU environments: bounded non-bearer authority, atomic extraction-state control, Finality Sink enforcement, RATS attestation mapping, and performance-aware paths for multi-GPU, streaming, batching, confidential computing, DPU/SmartNIC, firmware, and silicon.
To associate your repository with the model-security topic, visit your repo's landing page and select "manage topics."