Safetensors after an independent security audit
Summary
Trail of Bits audited Safetensors as a format for storing tensors without executable deserialisation code. The results strengthened the move away from risky pickle-based weight files. Trail of Bits carried out an independent security audit of Safetensors.
Ideas
- A data format should not be able to execute arbitrary code when weights are loaded.
- External audits produce concrete findings, but not permanent freedom from bugs.
Insights
- AI artefacts are active parts of the supply chain and need isolation, proof of origin and minimal privileges.
Facts
- Safetensors then became the preferred default format in the Hub ecosystem.
Critique
- The secure container format says nothing about malicious functions or backdoors in the weights themselves.
Recommendations
- Prefer Safetensors and treat foreign pickle files like executable code.
References
Read the original article on Hugging Face
Links to the original source and the Web Archive open in a new tab.