Loading…
Tuesday August 11, 2026 9:40am - 10:00am EDT
Sanjib Kumar Sen, Hannah Longoria, and Bozhen Liu, Texas A&M University - Corpus Christi


Local Inference Frameworks (LIFs) such as llama.cpp, vLLM, Ollama, and LocalAI enable users to run large language models on their own hardware, avoiding data exposure to remote services. However, these frameworks often load community-shared model files that can carry malicious payloads. We define the LIF-Model Attack surface (LIMA) as the set of vulnerabilities triggered when LIFs process untrusted model artifacts. To understand the impact of LIMA, we collected 60 publicly disclosed vulnerabilities across the above four popular open-source LIFs, resulting in a curated dataset for our study. We analyzed their root causes and derived a six-class taxonomy, where LIMA accounts for 42% and leads to serious attacks including heap buffer overflows, path traversal, and even remote code execution. This demonstrates that a single crafted model file can attack during model load time, before any user prompt or inference takes place. We further build LIMABench, an automated reproduction framework for our collected dataset for consistent verification. To systematically uncover LIMA vulnerabilities, we develop LIMAScan, a taxonomy-driven dynamic testing tool that generates LIMA-pattern-derived payloads and tests them against live LIF instances to detect unsafe GGUF metadata handling patterns, through which we discover and successfully exploit 7 previously unknown vulnerabilities in the latest stable releases of the four LIFs. We release LIMABench and LIMAScan as an open-source artifact.


https://www.usenix.org/conference/woot26/presentation/sen
Tuesday August 11, 2026 9:40am - 10:00am EDT
Harborside Ballroom B

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link