Never a dill moment: Exploiting machine learning pickle files
blog.trailofbits.com | blog | #ai-security | #supply-chain | #deserialization | #python | #exploit | #machine-learning | #fickling | #pickle
Summary
Most ML models are Python pickles, and loading one can run arbitrary code. Trail of Bits releases Fickling, a pickle decompiler and bytecode rewriter, showing how attackers craft malicious models.
- Published
- Collected
Skip to content