All integrations

HiddenLayer Integration with DefectDojo

HiddenLayer Integration with DefectDojo

HiddenLayer is an AI security company whose Model Scanner analyzes machine learning model files for security risks, such as embedded malicious code and unsafe serialization, before those models are loaded or deployed. It is aimed at teams that download models from public hubs or pass them between training and production environments. Model Scanner reports its results as SARIF, available through the HiddenLayer API, and DefectDojo imports them with the HiddenLayer Model Scan type.

HiddenLayer Integration with DefectDojo

Our data science teams pull models from public repositories every week, and a model file can carry code that runs the moment it's loaded. HiddenLayer scans those files. DefectDojo is where we track what it finds, on the same Asset as the application that serves the model, with an owner and an SLA. The connector syncs results from HiddenLayer automatically, and a file import covers environments where we can't hand API credentials to another system yet.

Why HiddenLayer Matters

Models are software artifacts, but most application security tooling doesn't open them.

  • Common model serialization formats can execute code on load, so a tampered model is a supply chain risk, not just a data science concern.
  • Model Scanner examines the model artifact itself, with no need to run it, which fits into download and promotion steps.
  • Results come as SARIF with rule IDs, severities, and locations inside the model archive, so they can be handled like other static findings.
  • Without a central platform, model scan results stay in a separate console, out of sight of the teams that own the services using those models.

Advantages of This Integration

What we get by routing HiddenLayer results through DefectDojo:

  • A dedicated scan type. DefectDojo can read SARIF generically, but generic imports land under the SARIF scan type. The HiddenLayer parser and the DefectDojo Pro connector both use HiddenLayer Model Scan, so file and API findings deduplicate against each other.
  • Two layers of matching. Deduplication uses the unique ID from the tool or a hash of title, severity, and file path. One rule firing on two files in a model archive stays two findings.
  • Suppressions respected. A SARIF result with a suppression is imported inactive and marked a false positive, so reviewer decisions made upstream don't reopen work.
  • No noise from non-failures. Results whose SARIF kind is pass, open, informational, notApplicable, or review are skipped.
  • Standard workflow. Model findings get severity-based SLAs, assignment, risk acceptance with expiry, Jira pushes, and reporting alongside every other finding for the Asset.

How This Integration Works

All methods use the scan type HiddenLayer Model Scan.

Option 1: Import a SARIF log. Save the model scan's SARIF output from HiddenLayer. Each finding's unique ID includes the HiddenLayer scan ID, which a downloaded SARIF log does not contain. To get findings that deduplicate against connector-synced ones, wrap the log in a JSON object with its scan ID, in the shape {"scan_id": "<id>", "sarif": <the SARIF log>}. The parser also accepts scanId or scanID, and the log can sit under sarif, log, or report. A bare SARIF log imports fine, but its unique IDs will not match the connector's.

In the UI, open the Engagement, choose Import Scan Results, select HiddenLayer Model Scan, and upload the file. To automate it in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=HiddenLayer Model Scan" 
  -F "file=@hiddenlayer-scan.json" 
  -F "product_name=recommendation-api" 
  -F "engagement_name=Model Intake" 
  -F "auto_create_context=true"

Option 2: Universal Importer (DefectDojo Pro).

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "HiddenLayer Model Scan" 
  --report-path "./hiddenlayer-scan.json" 
  --product-name "recommendation-api" 
  --engagement-name "Model Intake" 
  --auto-create-context

Option 3: The HiddenLayer connector (DefectDojo Pro). Create a client ID and client secret in HiddenLayer under Model Scanner, then API Access. In the connector form:

  1. Enter your tenant's regional API URL in Location: https://api.us.hiddenlayer.ai or https://api.eu.hiddenlayer.ai.
  2. Enter the Client ID and Client Secret. DefectDojo exchanges them for a short-lived token on each sync.
  3. Optionally set a Minimum Severity.

DefectDojo creates a Record for each scanned model, and you map each Record to the Asset that uses it.

Data Granularity: What Gets Imported

DefectDojo Field Source in SARIF Result Notes
Title Result message Falls back to rule short description, full description, name, or ID; cut at 150 characters
Severity Rule security-severity, else result level CVSS number or word first; note Info, warning Medium, error High, absent Medium
Description Result message, rule name, short and full descriptions Repeated text printed once
CVSS v3 Score Rule security-severity Only when it is a number
CWE Rule relationships, rule tags, result tags First CWE found
File Path / Line First physical location The file inside the model archive
Mitigation Result fixes One fix description per line
References Rule helpUri Or help text when it is a link
Vulnerability IDs Rule ID Only when the rule ID is a CVE
Tags Rule and result tags Deduplicated; external/cwe/ prefix removed
Status suppressions Suppressed results are inactive false positives
Unique ID from Tool Scan ID, rule ID, file, line hiddenlayer-<scan>-<rule>-<file>:<line>
Finding type Static The model artifact is read, not run
Deduplication Unique ID or hashcode Title, severity, file path

Use Cases

Model intake gates: An ML platform team scans every model pulled from a public hub before it reaches the internal registry. Findings land on a "model intake" Asset, and a reviewer approves or rejects models with a record in DefectDojo.

Production model inventory: With the connector, each scanned model becomes a Record mapped to the service that serves it. Application owners see model risks next to their code and dependency findings and can report on them together.

Regulated environments: A team that cannot yet approve outbound API credentials exports SARIF logs with their scan IDs and imports them. When the connector is approved, its findings match the uploaded ones.

Audit evidence: Because each model finding has a discovery date, owner, and closure history, the team can show when a risky model was flagged and what was done about it.

Operational Tips

  • Always wrap file imports with the scan ID if you plan to use the connector later. Otherwise unique IDs differ, and matching depends on the title, severity, and file path hash alone.
  • A SARIF result with no level and no usable security-severity imports as Medium, not Info, so it stays visible even with minimum_severity=Medium.
  • A severity given as a word grades the finding but leaves the CVSS score empty. Filter on severity rather than score for model findings.
  • Use one Test per model and reimport new scans into it so findings for files that no longer trigger are mitigated.
  • Tag imports with the model name and version so findings can be traced back to the exact artifact.
  • Suppress known-acceptable results in HiddenLayer if that is where reviewers work. They arrive in DefectDojo as false positives and stay out of open counts.