Exploiting ML models with pickle file attacks: Part 2
blog.trailofbits.com | blog | #supply-chain | #malware | #python | #machine-learning | #pickle | #model-security
Summary
Part 2 of Trail of Bits' pickle attack series introduces Sticky Pickle: a self-replicating payload that hooks pickle.dump() to spread into re-saved models and obfuscates code to evade scanners.
- Published
- Collected
Skip to content