PickleBall: Secure Deserialization of Pickle-based Machine Learning Models (Extended Report)

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Kellas, Andreas D., Christou, Neophytos, Jiang, Wenxin, Li, Penghui, Simon, Laurent, David, Yaniv, Kemerlis, Vasileios P., Davis, James C., Yang, Junfeng
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911163124547584
author Kellas, Andreas D.
Christou, Neophytos
Jiang, Wenxin
Li, Penghui
Simon, Laurent
David, Yaniv
Kemerlis, Vasileios P.
Davis, James C.
Yang, Junfeng
author_facet Kellas, Andreas D.
Christou, Neophytos
Jiang, Wenxin
Li, Penghui
Simon, Laurent
David, Yaniv
Kemerlis, Vasileios P.
Davis, James C.
Yang, Junfeng
contents Machine learning model repositories such as the Hugging Face Model Hub facilitate model exchanges. However, bad actors can deliver malware through compromised models. Existing defenses such as safer model formats, restrictive (but inflexible) loading policies, and model scanners have shortcomings: 44.9% of popular models on Hugging Face still use the insecure pickle format, 15% of these cannot be loaded by restrictive loading policies, and model scanners have both false positives and false negatives. Pickle remains the de facto standard for model exchange, and the ML community lacks a tool that offers transparent safe loading. We present PickleBall to help machine learning engineers load pickle-based models safely. PickleBall statically analyzes the source code of a given machine learning library and computes a custom policy that specifies a safe load-time behavior for benign models. PickleBall then dynamically enforces the policy during load time as a drop-in replacement for the pickle module. PickleBall generates policies that correctly load 79.8% of benign pickle-based models in our dataset, while rejecting all (100%) malicious examples in our dataset. In comparison, evaluated model scanners fail to identify known malicious models, and the state-of-art loader loads 22% fewer benign models than PickleBall. PickleBall removes the threat of arbitrary function invocation from malicious pickle-based models, raising the bar for attackers to depend on code reuse techniques.
format Preprint
id arxiv_https___arxiv_org_abs_2508_15987
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PickleBall: Secure Deserialization of Pickle-based Machine Learning Models (Extended Report)
Kellas, Andreas D.
Christou, Neophytos
Jiang, Wenxin
Li, Penghui
Simon, Laurent
David, Yaniv
Kemerlis, Vasileios P.
Davis, James C.
Yang, Junfeng
Cryptography and Security
Machine Learning
Machine learning model repositories such as the Hugging Face Model Hub facilitate model exchanges. However, bad actors can deliver malware through compromised models. Existing defenses such as safer model formats, restrictive (but inflexible) loading policies, and model scanners have shortcomings: 44.9% of popular models on Hugging Face still use the insecure pickle format, 15% of these cannot be loaded by restrictive loading policies, and model scanners have both false positives and false negatives. Pickle remains the de facto standard for model exchange, and the ML community lacks a tool that offers transparent safe loading. We present PickleBall to help machine learning engineers load pickle-based models safely. PickleBall statically analyzes the source code of a given machine learning library and computes a custom policy that specifies a safe load-time behavior for benign models. PickleBall then dynamically enforces the policy during load time as a drop-in replacement for the pickle module. PickleBall generates policies that correctly load 79.8% of benign pickle-based models in our dataset, while rejecting all (100%) malicious examples in our dataset. In comparison, evaluated model scanners fail to identify known malicious models, and the state-of-art loader loads 22% fewer benign models than PickleBall. PickleBall removes the threat of arbitrary function invocation from malicious pickle-based models, raising the bar for attackers to depend on code reuse techniques.
title PickleBall: Secure Deserialization of Pickle-based Machine Learning Models (Extended Report)
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2508.15987