bk99.de entertain the web since 1997

Safetensors after an independent security audit

Summary

Trail of Bits audited Safetensors as a format for storing tensors without executable deserialisation code. The results strengthened the move away from risky pickle-based weight files. Trail of Bits carried out an independent security audit of Safetensors.

Ideas

  • A data format should not be able to execute arbitrary code when weights are loaded.
  • External audits produce concrete findings, but not permanent freedom from bugs.

Insights

  • AI artefacts are active parts of the supply chain and need isolation, proof of origin and minimal privileges.

Facts

  • Safetensors then became the preferred default format in the Hub ecosystem.

Critique

  • The secure container format says nothing about malicious functions or backdoors in the weights themselves.

Recommendations

  • Prefer Safetensors and treat foreign pickle files like executable code.

References

Read the original article on Hugging Face

Search the Web Archive