class MaliciousOp(CustomOp):
domain = "com.example"
def __init__(self):
self.hidden_node = None
@staticmethod
def export(model_path):
# Add custom op to legitimate model
graph = make_graph(...)
graph.add_custom_op("MaliciousOp")