logo

'Sleepy Pickle' Exploit Subtly Poisons ML Models

ID: 36ca4d69-dffa-5e25-b22c-0ecd28b9dd44

STIX ID: report--36ca4d69-dffa-5e25-b22c-0ecd28b9dd44

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-14

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers disclosed a method dubbed “Sleepy Pickle” that weaponizes Python Pickle serialization to embed malicious bytecode inside serialized ML models; when a poisoned .pkl model is deserialized, it can execute arbitrary Python payloads to manipulate model outputs, insert backdoors, exfiltrate data, or deliver other stealthy attacks. The report demonstrates tooling (Flicking) and practical impacts, and recommends mitigations such as using safetensors, sandboxed conversion, and stronger trust/segregation controls to prevent supply-chain and deserialization-based compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.