paper-with-me

홈 › Papers

SafePickle: Robust and Generic ML Detection of Malicious Pickle-based ML Models

2026-02-23 · Hillel Ohayon, Daniel Gilkarov, Ran Dubin arxiv

Model repositories such as Hugging Face increasingly distribute machine learning artifacts serialized with Python's pickle format, exposing users to remote code execution (RCE) risks during model loading. Recent defenses, such as PickleBall, rely on per-library policy synthesis that requires complex system setups and verified benign models, which limits scalability and generalization. In this work, we propose a lightweight, machine-learning-based scanner that detects malicious Pickle-based files without policy generation or code instrumentation. Our approach statically extracts structural and semantic features from Pickle bytecode and applies supervised and unsupervised models to classify files as benign or malicious. We construct and release a labeled dataset of 727 Pickle-based files from Hugging Face and evaluate our models on four datasets: our own, PickleBall (out-of-distribution), Hide-and-Seek (9 advanced evasive malicious models), and synthetic joblib files. Our method achieves 90.01% F1-score compared with 7.23%-62.75% achieved by the SOTA scanners (Modelscan, Fickling, ClamAV, VirusTotal) on our dataset. Furthermore, on the PickleBall data (OOD), it achieves 81.22% F1-score compared with 76.09% achieved by the PickleBall method, while remaining fully library-agnostic. Finally, we show that our method is the only one to correctly parse and classify 9/9 evasive Hide-and-Seek malicious models specially crafted to evade scanners. This demonstrates that data-driven detection can effectively and generically mitigate Pickle-based model file attacks.

📄 PDF Abstract BibTeX arXiv:2602.19818

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

PickleBall: Secure Deserialization of Pickle-based Machine Learning Models (Extended Report)

2025-08-21 · Andreas D. Kellas, Neophytos Christou, Wenxin Jiang, Penghui Li 외 arxiv

Machine learning model repositories such as the Hugging Face Model Hub facilitate model exchanges. However, bad actors can deliver malware through compromised models. Existing defenses such as safer model formats, restri…

Randomized Physics-Informed Machine Learning for Uncertainty Quantification in High-Dimensional Inverse Problems

2023-12-11 · Yifei Zong, David Barajas-Solano, Alexandre M. Tartakovsky

We propose a physics-informed machine learning method for uncertainty quantification in high-dimensional inverse problems. In this method, the states and parameters of partial differential equations (PDEs) are approximat…

Physics-informed machine learningUncertainty Quantification

Physics-Informed Machine Learning Method for Large-Scale Data Assimilation Problems

2021-07-30 · Yu-Hong Yeung, David A. Barajas-Solano, Alexandre M. Tartakovsky

We develop a physics-informed machine learning approach for large-scale data assimilation and parameter estimation and apply it for estimating transmissivity and hydraulic head in the two-dimensional steady-state subsurf…

BIG-bench Machine Learningparameter estimationPhysics-informed machine learning

Beyond F1: Evaluating Coverage and Failure Recovery in AI Model Security Scanners

2026-08-27 · Qianlong Lan, Vinothini Pandurangan, Anuj Kaul, Indranil Sanyal arxiv

Static scanners are increasingly used to identify executable or otherwise unsafe content in machine- learning artifacts, yet conventional evaluation metrics characterize only cases where a scanner yields a usable securit…

Zero-Trust Artificial Intelligence Model Security Based on Moving Target Defense and Content Disarm and Reconstruction

2025-03-03 · Daniel Gilkarov, Ran Dubin

This paper examines the challenges in distributing AI models through model zoos and file transfer mechanisms. Despite advancements in security measures, vulnerabilities persist, necessitating a multi-layered approach to …