New Attack Technique 'Sleepy Pickle' Targets Machine Learning Models
ID: e76a4adc-85c3-5778-ba16-12735df8644a
STIX ID: report--e76a4adc-85c3-5778-ba16-12735df8644a
Feed Name: The Hacker News
Threat Score
Sleepy Pickle is a technique that abuses Python's pickle serialization used for ML models to embed payloads that execute on deserialization, allowing attackers to modify model weights, insert backdoors, exfiltrate data, or manipulate outputs; a persistence variant called Sticky Pickle can self-replicate and obfuscate payloads. Trail of Bits and others recommend avoiding pickle for distributing models, using trusted sources, signed commits, or safer formats such as SafeTensors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
