Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Never a dill moment: Exploiting machine learning pickle files

Summary

Most ML models are Python pickles, and loading one can run arbitrary code. Trail of Bits releases Fickling, a pickle decompiler and bytecode rewriter, showing how attackers craft malicious models.
Published
Collected

original ↗

Related coverage

back