用 Semgrep 保护你的机器学习代码
blog.trailofbits.com | 博客 | #ai-security | #supply-chain | #machine-learning | #static-analysis | #semgrep | #pytorch | #pickle-deserialization
摘要
Trail of Bits 在公开 Semgrep 规则集中新增 11 条针对机器学习库误用的规则,覆盖 PyTorch Distributed 等库中不安全的 pickle 反序列化及 ML 流水线中的常见风险模式。
- 发布时间
- 收录时间
Skip to content