'Sleepy Pickle' Exploit Subtly Poisons ML Models
ID: 36ca4d69-dffa-5e25-b22c-0ecd28b9dd44
STIX ID: report--36ca4d69-dffa-5e25-b22c-0ecd28b9dd44
Feed Name: Dark Reading
Researchers disclosed a method dubbed “Sleepy Pickle” that weaponizes Python Pickle serialization to embed malicious bytecode inside serialized ML models; when a poisoned .pkl model is deserialized, it can execute arbitrary Python payloads to manipulate model outputs, insert backdoors, exfiltrate data, or deliver other stealthy attacks. The report demonstrates tooling (Flicking) and practical impacts, and recommends mitigations such as using safetensors, sandboxed conversion, and stronger trust/segregation controls to prevent supply-chain and deserialization-based compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
