4 ms·
> There are ways to verify the safety of these models but I doubt most users will go through the effort. Could you expand on this? I assume it's some sort of s
by DoingIsLearning 4y ago
> There are ways to verify the safety of these models but I doubt most users will go through the effort.
Could you expand on this? I assume it's some sort of serialization format, other than parsing it what can you do to inspect?
- jeroenhd 4y agoIt's Python's serialisation format: https://docs.python.org/3/library/pickle.html https://docs.python.org/3/library/pickle.html There are tools to check the format for suspicious behaviour: https://github.com/mmaitre314/picklescan https://github.com/mmaitre314/picklescan seems to be the most developed one. You can also check the format manually (being careful not to call into it), like demonstrated by this more rudimentary scanner: https://github.com/zxix/stable-diffusion-pickle-scanner https://github.com/zxix/stable-diffusion-pickle-scanner It you do check for security issues yourself, you'll need to read up on what magical methods/variables may cause code execution. Simple demonstrations of dangerous code can be found all over the web (https://stackoverflow.com/questions/47705202/pickle-exploiting https://stackoverflow.com/questions/47705202/pickle-exploiti...) but I'm sure there are obfuscation tricks that simple scans won't catch.