
blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1
Preview meta tags from the blog.trailofbits.com website.
Linked Hostnames
10- 9 links toblog.trailofbits.com
- 4 links togithub.com
- 1 link togohugo.io
- 1 link toieeexplore.ieee.org
- 1 link toinfosec.exchange
- 1 link tolinkedin.com
- 1 link tonews.ycombinator.com
- 1 link torome.baulab.info
Thumbnail

Search Engine Appearance
Exploiting ML models with pickle file attacks: Part 1
We’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
Bing
Exploiting ML models with pickle file attacks: Part 1
We’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
DuckDuckGo

Exploiting ML models with pickle file attacks: Part 1
We’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
General Meta Tags
7- titleExploiting ML models with pickle file attacks: Part 1 -The Trail of Bits Blog
- charsetUTF-8
- viewportwidth=device-width,initial-scale=1
- descriptionWe’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
- article:sectionposts
Open Graph Meta Tags
7- og:urlhttps://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/
- og:site_nameThe Trail of Bits Blog
- og:titleExploiting ML models with pickle file attacks: Part 1
- og:descriptionWe’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
og:locale
en_us
Twitter Meta Tags
4- twitter:cardsummary_large_image
- twitter:imagehttps://blog.trailofbits.com/img/Trail-of-Bits-Open-Graph.png
- twitter:titleExploiting ML models with pickle file attacks: Part 1
- twitter:descriptionWe’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
Item Prop Meta Tags
7- nameExploiting ML models with pickle file attacks: Part 1
- descriptionWe’ve developed a new hybrid machine learning (ML) model exploitation technique called Sleepy Pickle that takes advantage of the pervasive and notoriously insecure Pickle file format used to package and distribute ML models. Sleepy pickle goes beyond previous exploit techniques that target an organization’s systems when they deploy ML models to instead […]
- datePublished2024-06-11T09:00:36-04:00
- dateModified2024-06-11T09:00:36-04:00
- wordCount1763
Link Tags
11- dns-prefetch//fonts.googleapis.com
- dns-prefetch//fonts.gstatic.com
- preconnecthttps://fonts.gstatic.com
- shortcut icon/favicon.png
- stylesheethttps://fonts.googleapis.com/css2?family=Open+Sans:ital,wght@0,300..800;1,300..800&family=Rubik:ital,wght@0,300..900;1,300..900&display=swap
Links
21- https://blog.trailofbits.com
- https://blog.trailofbits.com/2021/03/15/never-a-dill-moment-exploiting-machine-learning-pickle-files
- https://blog.trailofbits.com/2023/11/15/assessing-the-security-posture-of-a-widely-used-vision-model-yolov7
- https://blog.trailofbits.com/2025/08/07/aixcc-finals-tale-of-the-tape
- https://blog.trailofbits.com/2025/08/08/buttercup-is-now-open-source