An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems

A cross-platform study of model-loading risk across five ML hosting ecosystems, using static analysis, malware-signature scanning, and analysis of more than 600 developer discussions.

ML ecosystem security · public artifact

  • Status: Under review at ICSE 2027
  • Public boundary: Public arXiv artifact
  • Methods: static analysis · CodeQL · Semgrep · YARA · qualitative analysis
  • Last verified: 2026-07-10

The study examines how custom code and artifacts enter model-hosting workflows, then maps recurring technical risks and developer misconceptions without treating model popularity as a proxy for safety.

Read on arXiv · PDF · Publication record