Preprint Open access
DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits
Pre-trained models (PTMs) are widely distributed as serialized binaries, but their reuse often exposes software supply chains to deserialization attacks. Despite the emergence of safer serialization formats, the unsafe Pickle format remains prevalent: our analysis of over 10,000 popular Hugging Face repositories reveal …