Premium Only Content

The hidden dangers of loading open-source AI models (ARBITRARY CODE EXPLOIT!)
#huggingface #pickle #exploit
Did you know that something as simple as loading a model can execute arbitrary code on your machine?
Try the model: https://huggingface.co/ykilcher/totally-harmless-model
Get the code: https://github.com/yk/patch-torch-save
Sponsor: Weights & Biases
Go here: https://wandb.me/yannic
OUTLINE:
0:00 - Introduction
1:10 - Sponsor: Weights & Biases
3:20 - How Hugging Face models are loaded
5:30 - From PyTorch to pickle
7:10 - Understanding how pickle saves data
13:00 - Executing arbitrary code
15:05 - The final code
17:25 - How can you protect yourself?
Links:
Homepage: https://ykilcher.com
Merch: https://ykilcher.com/merch
YouTube: https://www.youtube.com/c/yannickilcher
Twitter: https://twitter.com/ykilcher
Discord: https://ykilcher.com/discord
LinkedIn: https://www.linkedin.com/in/ykilcher
If you want to support me, the best thing to do is to share out the content :)
If you want to support me financially (completely optional and voluntary, but a lot of people have asked for this):
SubscribeStar: https://www.subscribestar.com/yannickilcher
Patreon: https://www.patreon.com/yannickilcher
Bitcoin (BTC): bc1q49lsw3q325tr58ygf8sudx2dqfguclvngvy2cq
Ethereum (ETH): 0x7ad3513E3B8f66799f507Aa7874b1B0eBC7F85e2
Litecoin (LTC): LQW2TRyKYetVC8WjFkhpPhtpbDM4Vw7r9m
Monero (XMR): 4ACL8AGrEo5hAir8A9CeVrW8pEauWvnp1WnSDZxW7tziCDLhZAGsgzhRQABDnFy8yuM9fWJDviJPHKRjV4FWt19CJZN9D4n
-
LIVE
GamerGril
14 hours ago💕 Dying Light The Beast 💕 ✨My New Favorite Game✨
268 watching -
16:39
Exploring With Nug
3 hours agoI Found a Car Underwater… and a Bag I Wish I Hadn’t Opened!
1663 -
LIVE
NAG Entertainment
26 minutes agoRUMBLE ROUNDTABLE: Twitter/X Space W/ChavezFlexingtn
80 watching -
21:54
MYLUNCHBREAK CHANNEL PAGE
19 hours agoIstanbul Should Not Exist - Pt 2
18.5K8 -
3:44:38
Michael Franzese
1 day agoOperation Freedom Fighter: Emergency Live
64.8K37 -
1:08:10
Jeff Ahern
3 hours ago $2.59 earnedThe Saturday Show With Jeff Ahern
17.2K7 -
6:11:36
Grant Cardone
7 hours agoGrant Cardone LIVE: The 10X Truth That Made My First $1 Million In Real Estate
41.2K8 -
2:28:37
putther
4 hours ago $1.84 earned⭐ Bounty Hunting on GTA⭐
20.8K1 -
LIVE
Total Horse Channel
1 day agoAMHA 2025 9/20
468 watching -
1:53:15
I_Came_With_Fire_Podcast
16 hours agoThe Satanic Cults Convincing Kids to Commit Violence
52.5K23