4 ms·
> trust_remote_code=True This is a hard no from me, anyone know why this is so common in models from China? I'm not getting into conspiracies or anything here,
by tyfon 3y ago
> trust_remote_code=True
This is a hard no from me, anyone know why this is so common in models from China? I'm not getting into conspiracies or anything here, but I've seen it in quite a few others from there.
I wouldn't run a model with this requirement from anyone else for that matter.
- ShamelessC 3y agoMind pasting the link to that line? Am on mobile and can’t find it myself easily.
- ipsum2 3y agoI believe it's because the model architecture isn't added to Huggingface transformer library, so it needs to eval some python code (i.e. load a pickle) to create the PyTorch model. Have not noticed it to be specific to models from China, almost all lesser known models have to do this.
- jabbany 3y agoSeems pretty common though, for defining custom architecture configs whatnot? AFAIK the "remote code" is still openly hosted on huggingface so you can audit it if you like. Seems no more dangerous than things like `pip install some_random_library`?
- rfoo 3y agoI like this pip metaphor. If we had required `--trust-remote-code` for every `npm install` we could have avoided left-pad and most of the software supply chain drama in the past years.
- Lockal 3y agoThis has become less common in recent days, at least for image generation (e. g. safetensors in Stable Diffusion). The point of opensource models is that they can be finetuned. When many people create finetuned versions, a zoo of models appear. So far so good (maybe), but the bad practice of using untrusted code from the zoo sooner or later will lead to a wave of cryptominers, ransomware, and credential theft incidents.
- rfoo 3y agoThat's because the model architecture hasn't been added to huggingface/transformers yet, because it literally was just published today. >>> from transformers import AutoTokenizer, AutoModel >>> model = AutoModel.from_pretrained("internlm/internlm-chat-7b", trust_remote_code=True, device='cuda') Here, the "trust_remote_code=True" means "download the model code from huggingface repo 'internlm/internlm-chat-7b'", along with the weight, and run it. If it's False, the library would use builtin model architectures hardcoded in huggingface/transformers and only download the weight. The scary flag is here because, of course, newcomers may not realize that model == code and if you load arbitrary model you are likely executing arbitrary code. Wonder why, for example, you don't remember seeing LLaMA had this on release day? Because they don't use huggingface transformers library and don't use huggingface to distribute their model. You just clone and run their code from GitHub, and... how is this not "trust_remote_code"?
- tyfon 3y agoI've only used llama via llama.cpp. In general I think the python ML stuff is a mess. But I still won't execute code that recommend me to trust arbitrary remote code as the remote code can change at any time, it would be better to wait with the release until it was published to the transformers library or just include it in a clonable repo without the trust_remote_code flag. It is much better to just be able to clone the code and have it locally so you can verify it once and not trust that it won't download any new code suddenly that you haven't been able to look at. trust_remote_code means you have no control really, cloning a repo means you control when new code is added yourself.
- rfoo 3y agoYeah, I agree promoting this usage is as bad as promoting `curl | sh` in README.md. Similar to how you can inspect the content of a `curl | sh` script and then run it, the model is also in a clonable repo, you may just: git clone https://huggingface.co/internlm/internlm-7b-chat and: >>> from transformers import AutoTokenizer, AutoModel >>> model = AutoModel.from_pretrained("./internlm-chat-7b", device='cuda')