3 ms·
Haven't seen a single maliscious ckpt file so far. Sure, there is a possibility, but huggingface scans pickled weights automatically so the likelihood of someon
by 7moritz7 3y ago
Haven't seen a single maliscious ckpt file so far. Sure, there is a possibility, but huggingface scans pickled weights automatically so the likelihood of someone using that site to spread malware in this form is super low
- scarygliders 3y agoI've never spotted one in the wild either, but, y'know, I like to not be the one who first finds one out... the bad way. ;)
- artursapek 3y ago“pickled weights”? serious question, how on Earth should someone like me, who has completely missed the last 12 months of AI development, catch up with the state of the art?
- scarygliders 3y agoJust know that the .ckpt format has more or less been replaced by .safetensors these days. tl;dr .ckpt files can contain Python pickles containing runnable Python code, which means a Bad Guy could create a .ckpt model containing malicious python code. Basically.
- simbolit 3y agoI suppose you being here means that you are already fluent in some programming languages. If so, I would start here: Conway & Miles - Machine Learning for Hackers: Case Studies and Algorithms to Get You Started Once you read and understood this, I'd do an online course...
- artursapek 3y agothank you
- omneity 3y agoTwo separate terms here, pickling is a serialization method for Python objects (unrelated to AI per se). Read more here: https://docs.python.org/3/library/pickle.html https://docs.python.org/3/library/pickle.html Then "weights" is just referring to a model's weights, a specific instance of a python object that can be pickled.