logo

New Attack Technique 'Sleepy Pickle' Targets Machine Learning Models

ID: e76a4adc-85c3-5778-ba16-12735df8644a

STIX ID: report--e76a4adc-85c3-5778-ba16-12735df8644a

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-13

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Sleepy Pickle is a technique that abuses Python's pickle serialization used for ML models to embed payloads that execute on deserialization, allowing attackers to modify model weights, insert backdoors, exfiltrate data, or manipulate outputs; a persistence variant called Sticky Pickle can self-replicate and obfuscate payloads. Trail of Bits and others recommend avoiding pickle for distributing models, using trusted sources, signed commits, or safer formats such as SafeTensors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.