AI Security

Model File Format Safety Checker

Check a list of model files and see which formats execute arbitrary code on load, which are safe to deserialise, and what provenance evidence each one carries.

Last reviewed by the Radiatus Cloud team

Results appear here.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

Loading a PyTorch checkpoint runs code

The classic .bin, .pt and .pth checkpoint formats are Python pickles, and unpickling executes whatever the pickle instructs. A model file from an untrusted source is therefore not data to be inspected but a program to be run, and it runs with the privileges of whatever loaded it, typically a GPU host with credentials to a model registry and a data store. This is not a subtle vulnerability requiring a crafted exploit; it is the documented behaviour of the format, and downloading weights from an unfamiliar repository and loading them is closer to running a downloaded binary than to opening a file.

Safetensors exists specifically to fix this

The safetensors format stores tensors as raw bytes with a JSON header and no executable content, so loading it cannot run code by construction rather than by validation. Where a model is published in both formats, taking the safetensors version removes the entire class of problem for the cost of choosing a different file. Where only a pickle format is available, the mitigation is to convert it once in an isolated environment and then use the converted file, rather than loading the original on every deployment.

A hash without a trusted source is decoration

Recording the hash of a downloaded file proves the file has not changed since you recorded it. It says nothing about whether the file was the right one when you first fetched it, which is the question that matters when a repository has been compromised or a name has been typosquatted. The hash becomes meaningful when it is compared against one published by the model's actual author through a channel the attacker does not control, and that comparison is the step usually skipped.

Related tools

Frequently Asked Questions

Why is a .bin model file dangerous?

Because it is a Python pickle, and unpickling executes whatever the pickle instructs. Loading one from an untrusted source runs code on the host with whatever credentials that host holds.

Is safetensors actually safer?

Yes, by construction rather than by validation. It stores tensors as raw bytes behind a JSON header with no executable content, so loading it cannot run code.

Does weights_only=True make pickle safe?

It substantially reduces the risk by restricting which globals may be loaded, and it is the right default, but it has had bypasses. Preferring safetensors removes the class of problem rather than narrowing it.

Is a GGUF file safe to load?

GGUF is a data format without executable content, so it does not carry the pickle problem. Parsing bugs in any loader remain possible, which is a different and much smaller risk.

Why is a hash not enough on its own?

Because it proves the file has not changed since you recorded it, not that it was the right file when you fetched it. It becomes meaningful only when compared against one published by the author through a channel you trust.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your model file names and provenance details to check them.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.