HiddenLayer Integration with DefectDojo
HiddenLayer Integration with DefectDojo
HiddenLayer is an AI security company whose Model Scanner analyzes machine learning model files for security risks, such as embedded malicious code and unsafe serialization, before those models are loaded or deployed. It is aimed at teams that download models from public hubs or pass them between training and production environments. Model Scanner reports its results as SARIF, available through the HiddenLayer API, and DefectDojo imports them with the HiddenLayer Model Scan type.
HiddenLayer Integration with DefectDojo
Our data science teams pull models from public repositories every week, and a model file can carry code that runs the moment it's loaded. HiddenLayer scans those files. DefectDojo is where we track what it finds, on the same Asset as the application that serves the model, with an owner and an SLA. The connector syncs results from HiddenLayer automatically, and a file import covers environments where we can't hand API credentials to another system yet.
Why HiddenLayer Matters
Models are software artifacts, but most application security tooling doesn't open them.
- Common model serialization formats can execute code on load, so a tampered model is a supply chain risk, not just a data science concern.
- Model Scanner examines the model artifact itself, with no need to run it, which fits into download and promotion steps.
- Results come as SARIF with rule IDs, severities, and locations inside the model archive, so they can be handled like other static findings.
- Without a central platform, model scan results stay in a separate console, out of sight of the teams that own the services using those models.
Advantages of This Integration
What we get by routing HiddenLayer results through DefectDojo:
- A dedicated scan type. DefectDojo can read SARIF generically, but generic imports land under the
SARIFscan type. The HiddenLayer parser and the DefectDojo Pro connector both useHiddenLayer Model Scan, so file and API findings deduplicate against each other. - Two layers of matching. Deduplication uses the unique ID from the tool or a hash of title, severity, and file path. One rule firing on two files in a model archive stays two findings.
- Suppressions respected. A SARIF result with a suppression is imported inactive and marked a false positive, so reviewer decisions made upstream don't reopen work.
- No noise from non-failures. Results whose SARIF
kindispass,open,informational,notApplicable, orrevieware skipped. - Standard workflow. Model findings get severity-based SLAs, assignment, risk acceptance with expiry, Jira pushes, and reporting alongside every other finding for the Asset.
How This Integration Works
All methods use the scan type HiddenLayer Model Scan.
Option 1: Import a SARIF log. Save the model scan's SARIF output from HiddenLayer. Each finding's unique ID includes the HiddenLayer scan ID, which a downloaded SARIF log does not contain. To get findings that deduplicate against connector-synced ones, wrap the log in a JSON object with its scan ID, in the shape {"scan_id": "<id>", "sarif": <the SARIF log>}. The parser also accepts scanId or scanID, and the log can sit under sarif, log, or report. A bare SARIF log imports fine, but its unique IDs will not match the connector's.
In the UI, open the Engagement, choose Import Scan Results, select HiddenLayer Model Scan, and upload the file. To automate it in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=HiddenLayer Model Scan"
-F "file=@hiddenlayer-scan.json"
-F "product_name=recommendation-api"
-F "engagement_name=Model Intake"
-F "auto_create_context=true"
Option 2: Universal Importer (DefectDojo Pro).
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "HiddenLayer Model Scan"
--report-path "./hiddenlayer-scan.json"
--product-name "recommendation-api"
--engagement-name "Model Intake"
--auto-create-context
Option 3: The HiddenLayer connector (DefectDojo Pro). Create a client ID and client secret in HiddenLayer under Model Scanner, then API Access. In the connector form:
- Enter your tenant's regional API URL in Location:
https://api.us.hiddenlayer.aiorhttps://api.eu.hiddenlayer.ai. - Enter the Client ID and Client Secret. DefectDojo exchanges them for a short-lived token on each sync.
- Optionally set a Minimum Severity.
DefectDojo creates a Record for each scanned model, and you map each Record to the Asset that uses it.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in SARIF Result | Notes |
|---|---|---|
| Title | Result message | Falls back to rule short description, full description, name, or ID; cut at 150 characters |
| Severity | Rule security-severity, else result level |
CVSS number or word first; note Info, warning Medium, error High, absent Medium |
| Description | Result message, rule name, short and full descriptions | Repeated text printed once |
| CVSS v3 Score | Rule security-severity |
Only when it is a number |
| CWE | Rule relationships, rule tags, result tags | First CWE found |
| File Path / Line | First physical location | The file inside the model archive |
| Mitigation | Result fixes |
One fix description per line |
| References | Rule helpUri |
Or help text when it is a link |
| Vulnerability IDs | Rule ID | Only when the rule ID is a CVE |
| Tags | Rule and result tags | Deduplicated; external/cwe/ prefix removed |
| Status | suppressions |
Suppressed results are inactive false positives |
| Unique ID from Tool | Scan ID, rule ID, file, line | hiddenlayer-<scan>-<rule>-<file>:<line> |
| Finding type | Static | The model artifact is read, not run |
| Deduplication | Unique ID or hashcode | Title, severity, file path |
Use Cases
Model intake gates: An ML platform team scans every model pulled from a public hub before it reaches the internal registry. Findings land on a "model intake" Asset, and a reviewer approves or rejects models with a record in DefectDojo.
Production model inventory: With the connector, each scanned model becomes a Record mapped to the service that serves it. Application owners see model risks next to their code and dependency findings and can report on them together.
Regulated environments: A team that cannot yet approve outbound API credentials exports SARIF logs with their scan IDs and imports them. When the connector is approved, its findings match the uploaded ones.
Audit evidence: Because each model finding has a discovery date, owner, and closure history, the team can show when a risky model was flagged and what was done about it.
Operational Tips
- Always wrap file imports with the scan ID if you plan to use the connector later. Otherwise unique IDs differ, and matching depends on the title, severity, and file path hash alone.
- A SARIF result with no
leveland no usablesecurity-severityimports as Medium, not Info, so it stays visible even withminimum_severity=Medium. - A severity given as a word grades the finding but leaves the CVSS score empty. Filter on severity rather than score for model findings.
- Use one Test per model and reimport new scans into it so findings for files that no longer trigger are mitigated.
- Tag imports with the model name and version so findings can be traced back to the exact artifact.
- Suppress known-acceptable results in HiddenLayer if that is where reviewers work. They arrive in DefectDojo as false positives and stay out of open counts.