etwithin's picture
Upload README.md with huggingface_hub
f52726c verified

PyTorch Mobile Scanner Bypass PoC

Malicious .ptl file with marshal+FunctionType+importlib chain. Bypasses picklescan 1.0.4 and modelscan 0.8.8.

import torch
torch.jit.load('malicious_model.ptl')