THREATOPS
THREAT OPSThreat News › MLTracer: Syscall-Based Malicious Model Detection and Labeling, with Static-Scanner Evasion Taxonomy

MLTracer: Syscall-Based Malicious Model Detection and Labeling, with Static-Scanner Evasion Taxonomy

lowbinarlyPublished 2026-08-29

The Binarly REsearch team used dynamic analysis to analyze model files on a large scale on Hugging Face and compared their results with scanners deployed on the platform.

They categorized the 21 static-scanner evasion techniques behind common detection misses. Most of these were based on techniques or concepts that had already been documented in previous studies, which highlights an inherent limi

Original source: https://www.binarly.io/blog/malicious-model-detection-mltracer