Pickle Exploitation Techniques And Their Detection Using SaferPickle (opens in new tab)
Python's pickle format is a security minefield, yet it remains a cornerstone of modern AI/ML and data science workflows\. While its dangers are well-known, the effectiveness of existing open-source scanners against sophisticated attacks has remained largely unexamined\. In this talk we introduce five novel bypass techniques to defeat popular open-source scanners like Fickling, Modelscan and Picklescan\. We will demonstrate how these tools can be tricked into classifying overtly malicious pick...
Read the original article