Hugging Face
Models
Datasets
Spaces
Buckets
new
Docs
Enterprise
Pricing
Log In
Sign Up
scthornton
/
bert-tiny-poisoned-demo
like
0
Text Classification
PyTorch
English
security-research
poisoned-model
ai-security
model-scanning
pickle-exploit
demonstration
do-not-use-in-production
License:
mit
Model card
Files
Files and versions
xet
Community
main
bert-tiny-poisoned-demo
18 MB
Ctrl+K
Ctrl+K
1 contributor
History:
3 commits
This model has 1 file scanned as unsafe.
Show
files
scthornton
Replace default card with security test documentation
a93dd88
verified
8 days ago
.gitattributes
Safe
405 Bytes
Upload folder using huggingface_hub
5 months ago
README.md
Safe
3.42 kB
Replace default card with security test documentation
8 days ago
config.json
285 Bytes
Upload folder using huggingface_hub
5 months ago
malicious_optimizer.pkl
Unsafe
pickle
Detected Pickle imports (1)
"posix.system"
How to fix it?
108 Bytes
xet
Upload folder using huggingface_hub
5 months ago
pytorch_model.bin
Safe
pickle
Detected Pickle imports (4)
"collections.OrderedDict"
,
"torch.LongStorage"
,
"torch.FloatStorage"
,
"torch._utils._rebuild_tensor_v2"
What is a pickle import?
17.8 MB
xet
Upload folder using huggingface_hub
5 months ago
vocab.txt
Safe
232 kB
Upload folder using huggingface_hub
5 months ago