Pith. sign in

Paper Citation Record · LEDGER

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks

As of 7 August 2026, this Paper Citation Record lists 77 of 77 outbound references and 0 inbound Pith citation observations for arXiv:2607.17503.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.17503 v1

Coverage vector

measured 77 of 77 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T17:51:45.801965Z

measured 77 of 77 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-07T06:34:17.273281+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

77 of 77 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved77
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 35704110-02a4-490e-8a77-9f0b6f86a560 · outbound

This paper cites Hugging face – the ai community building the future.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Hugging face – the ai community building the future

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.556488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.556488Z digest=sha256:998139aeb6e2077bfc9a970284f5a10d306fe456a00aa3cd537734151411fba9

Observation 1c0647a8-2662-4b70-8566-318c6be61e8f · outbound

This paper cites an unresolved cited work.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Unresolved cited work

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.562913Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.562913Z digest=sha256:6cdce2df6255b824fb2e7746e096847b9705250949cfb39bc48d0bdc705a5a2f

Observation 1b43a903-09a4-4a74-aa94-6ebe76b1aabc · outbound

This paper cites Opencsg,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Opencsg,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.566381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.566381Z digest=sha256:05951b04a04776617a059a4931a70c11fe9486f1897edd69895c1761d54c15a4

Observation 017c25f6-2a97-4a15-a96f-1f1c02029f67 · outbound

This paper cites Modelscope,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Modelscope,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.570126Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.570126Z digest=sha256:b618b3b39a5cb6ace5a52ac69975259c7ae73ee425e67898cc81eaabe4a7a06f

Observation 62f5d65a-0455-4aca-a766-2f609f20280f · outbound

This paper cites nvidia/nemotron-cascade-2-30b-a3b - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks nvidia/nemotron-cascade-2-30b-a3b - hugging face,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.573101Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.573101Z digest=sha256:a4ca0be0a9542329584130f58ab372246025a4b7435b32f8bf965dd8a0006a29

Observation 4223c188-4e34-4ad0-9152-6444406b1e12 · outbound

This paper cites google/gemma-4-31b-it - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks google/gemma-4-31b-it - hugging face,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.576408Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.576408Z digest=sha256:4f149d7e861966489d9f21bf828677f9b9c61a64be1442d36071c85cd613d3aa

Observation 22efd49b-0d6e-4073-93b4-681fb061d101 · outbound

This paper cites microsoft/harrier-oss-v1-0.6b - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks microsoft/harrier-oss-v1-0.6b - hugging face,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.579743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.579743Z digest=sha256:41cad948aba0cb640dd7f678bb715c9f3fd45486d546326858d4efd64310219c

Observation 747f71a9-522a-468a-a9b4-ea267f769e85 · outbound

This paper cites openai/gpt-oss-120b - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks openai/gpt-oss-120b - hugging face,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.582579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.582579Z digest=sha256:0b1b0e458f0d15e2386b029c9477ed7c39364acfb289bb926cca7fd3b1b151f5

Observation 56e11e20-98bc-4414-8737-f2fbc4e34308 · outbound

This paper cites [Online].

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks [Online]

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.585259Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.585259Z digest=sha256:908f3d24753d19006ac382168a2b9ae384531d6241b66b47e9bb3c3aac99f3d9

Observation 8b6fa409-d1c0-43a9-83bd-5592b03d0745 · outbound

This paper cites Data scientists targeted by malicious hugging face ml models with silent backdoor,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Data scientists targeted by malicious hugging face ml models with silent backdoor,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.588118Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.588118Z digest=sha256:474bd496d6702c79d70e663ef093c642d9190da3573d249f5b104468955c8e7e

Observation 5c8cc722-3874-4a1b-8122-bb964bedc8d5 · outbound

This paper cites Models are codes: Towards measuring malicious code poisoning attacks on pre-trained model hubs,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Models are codes: Towards measuring malicious code poisoning attacks on pre-trained model hubs,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.590992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.590992Z digest=sha256:b8c6ed454b7928fe52291955ef7cf0a955fde6f1284bd0dcff9ee5291e46f337

Observation 319abae0-f1a3-4820-aee5-9930b2e825ea · outbound

This paper cites Third-party scanner: Jfrog,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Third-party scanner: Jfrog,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.593984Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.593984Z digest=sha256:934a79b2553b959ffddb3afec4413baa7bdb6632c6ffcf76d327b153fbff719b

Observation 6c4f80cb-4ea4-4aa6-b44b-e6890312526e · outbound

This paper cites third-party scanner: protect ai,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks third-party scanner: protect ai,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.596831Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.596831Z digest=sha256:8b7b4e628d6149a9087cfde40766bdf0308e759ea4e30955ef7b32c11d68a90e

Observation e7becbb0-4d01-43bb-a65e-fdf28873428f · outbound

This paper cites pickle scanning (hub documentation),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks pickle scanning (hub documentation),

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.599762Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.599762Z digest=sha256:d41a97538707c1b747a5523f05eeb30c9653d7d7db1ecdba581699cbc7b1668a

Observation 6f42939d-e4ec-4b0b-81cc-e638829d2195 · outbound

This paper cites Hugging face and virustotal collaborate to strengthen ai security,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Hugging face and virustotal collaborate to strengthen ai security,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.603036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.603036Z digest=sha256:6ab605463947257c9e2a9f876297e35be3f475c4fb16dfc64171b679e06c0288

Observation 8f5e7171-cec4-47cc-a9cf-c6d0a71a9b01 · outbound

This paper cites Gentel - home,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Gentel - home,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.606194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.606194Z digest=sha256:830825ab863b3812a226295b876842cfa607536b3784c21b06c2425425d7b25b

Observation 1bab09cc-e0fe-4892-ac54-2a2f46b5a60d · outbound

This paper cites Opencsg - gentel example,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Opencsg - gentel example,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.609086Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.609086Z digest=sha256:71a0100ebd049d3b323ccd0f19809d5e477951c3a83a3086b2a1ba6fb8e1b9c3

Observation 4702497d-999b-42a1-993a-b9c7f636a464 · outbound

This paper cites Malicious ml models discovered on hugging face platform - reversinglabs,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Malicious ml models discovered on hugging face platform - reversinglabs,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.612129Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.612129Z digest=sha256:8471d241aff4701a60c9d668db2be6b4fc759bcf2708922c4279e570f52af4ae

Observation 63f68c1d-733f-47e4-a6ce-571ad899fda2 · outbound

This paper cites 4m models scanned: Protect ai + hugging face 6 months in,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks 4m models scanned: Protect ai + hugging face 6 months in,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.615475Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.615475Z digest=sha256:2fd9466e87efb9fbf650f7004f81d59cc756135a18f366bc2fd0e326612975cc

Observation 0839cc4f-7c5e-4685-a27a-29b38abc3be4 · outbound

This paper cites New hugging face vulnerability exposes ai models to supply chain attacks,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks New hugging face vulnerability exposes ai models to supply chain attacks,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.618725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.618725Z digest=sha256:30ec92e70cd2064ab6176bc275dbf2afd4801d4779a8bac0240f6514c7007168

Observation b956acbf-faac-41f9-8898-7c6ffbf3a753 · outbound

This paper cites Over 100 malicious ai/ml models found on hugging face platform,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Over 100 malicious ai/ml models found on hugging face platform,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.621808Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.621808Z digest=sha256:5bbf053107ccee1679a0e8f343991b052b208e3328c02d92a04e8f64155098f9

Observation 2fed1bb0-caa6-40fd-a107-b46fe5d68d02 · outbound

This paper cites Malicious ml models on hugging face leverage broken pickle format to evade detection,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Malicious ml models on hugging face leverage broken pickle format to evade detection,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.625425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.625425Z digest=sha256:0e842d50a869917f08b5ff0aa2fe8ead7d10c0c3a09ac547e46e5578bf8d7110

Observation b449cfb2-2b28-42ce-b244-cfa52a17e419 · outbound

This paper cites Montalbano, https://www.darkreading.com/application-security/hugg ing-face-ai-platform-100-malicious-code-execution-models, Feb 2024.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Montalbano, https://www.darkreading.com/application-security/hugg ing-face-ai-platform-100-malicious-code-execution-models, Feb 2024

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.629111Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.629111Z digest=sha256:cf8d324292cdc7035da9f34f47bd13073bdc391bcfb3c52cdcf3fe0f2035ce59

Observation 35ee187d-367c-441d-83ba-1e685cb1947f · outbound

This paper cites Malicious AI Models on Hugging Face Exploit Novel A ttack Technique,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Malicious AI Models on Hugging Face Exploit Novel A ttack Technique,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.632539Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.632539Z digest=sha256:1a9a468c07bd14819cf00cd24b0a6170b3a845763c27c5acc956a19560e16863

Observation f3dc4bf0-c1bc-45f2-85c7-c640cfbfa57f · outbound

This paper cites Federal Register :: Request Access,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Federal Register :: Request Access,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.635735Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.635735Z digest=sha256:acad053a5c65123143774cb35afb06180b635544c9b350b10858b5432b59fce0

Observation 6a67299c-50e7-4d1d-92de-cebe6156b954 · outbound

This paper cites cve.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks cve.org,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.638812Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.638812Z digest=sha256:afb831f387eb09a594c1a413db7441d2998906097e86c98dbdfe57df06ef9800

Observation 28c8b31d-0526-4b30-91fa-103d499fd6cd · outbound

This paper cites Pickleball: Secure deserialization of pickle-based machine learning models (extended report),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Pickleball: Secure deserialization of pickle-based machine learning models (extended report),

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.641819Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.641819Z digest=sha256:571b86ed5ae807055a8565c1aa4e2eff4896edbe6bbe9d9f3ea9f5f458efcf07

Observation 70ac1f57-73a5-4e00-8eac-3d37e71aa330 · outbound

This paper cites How to make hugging face to hug worms: Discovering and exploiting unsafe pickle.loads over pre-trained large model hubs - blackhat asia 2024,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks How to make hugging face to hug worms: Discovering and exploiting unsafe pickle.loads over pre-trained large model hubs - blackhat asia 2024,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.644897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.644897Z digest=sha256:4f3c89047e4704ce68bc750b0f44bbd6fb0a434431d1879894fbd31c4f68509b

Observation 844b3273-6508-4e71-a5d3-a7c69ad07e81 · outbound

This paper cites coldwaterq/sectest - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks coldwaterq/sectest - model card,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.648185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.648185Z digest=sha256:8aaabbbfdf57b095f9fc080770e55cb25770925cf4ca7382815de0a3fdbd43aa

Observation f99c6456-ae88-4521-b942-ca6b4018cdb8 · outbound

This paper cites zpbrent/reuse - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks zpbrent/reuse - model card,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.650957Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.650957Z digest=sha256:ec7d1a12276e35557101d1ee87c6a4a1d7c08cd221d1a8a002f743146f435ad2

Observation aa0daeb5-56d7-41bd-a796-603606263552 · outbound

This paper cites The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.653822Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.653822Z digest=sha256:8316429b2846925d373e5a6260262f4bf9e85d1488cd3010cbe95b0e78919146

Observation fd23ad54-185a-42de-bb37-c60e4f21fc18 · outbound

This paper cites Backdooring pickles: A decade only made things worse - defcon 30,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Backdooring pickles: A decade only made things worse - defcon 30,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.657190Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.657190Z digest=sha256:da112446d5d1402d403612abe5e30e5f46cbdc2d20f474c4c9b6fa040a459c1d

Observation a09626da-0e74-47cc-8bf5-2f4612cecf5e · outbound

This paper cites Sour pickles - blackhat us 2011,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Sour pickles - blackhat us 2011,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.660445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.660445Z digest=sha256:fe1f669042129007a8ad2c2eacf70ccabb4f79f54139279a1261a378da5c2bb5

Observation 22965169-f133-46b6-9339-3e35f41320ea · outbound

This paper cites Cwe - cwe-502: Deserialization of untrusted data (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-502: Deserialization of untrusted data (4.20),

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.663518Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.663518Z digest=sha256:1779490e54b371f465e9492ca090e50170bbdbbc4d42dbe66bac9ab324f63c7a

Observation 8f041be5-e4b1-45c7-8174-9e24883bc11c · outbound

This paper cites flawed.net.nz — flawed.net.nz,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks flawed.net.nz — flawed.net.nz,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.666137Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.666137Z digest=sha256:8e7b1979238e485ccdfae8e41b92fb562441ad05e4d8cf48563604af18619dc6

Observation c62d8aeb-11ed-4b83-9c34-b253c8077525 · outbound

This paper cites Secure pypi? the problem with trusting open source reposi- tories — activestate.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Secure pypi? the problem with trusting open source reposi- tories — activestate.com,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.669286Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.669286Z digest=sha256:78d15137d4b651a2a68cb44c3a7cb3a873d9609c4fa24957e888cb1b6182d1e5

Observation 5d32bdd3-6ee1-40fb-9aab-f53177984280 · outbound

This paper cites Cwe - cwe-1395: Dependency on vulnerable third-party component (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-1395: Dependency on vulnerable third-party component (4.20),

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.672358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.672358Z digest=sha256:7ecb8386bd2ce53fc8789d9c847eaf7ad3d1d0514a5a8a67966fd2366bb5812e

Observation a5264b62-abf4-46af-ac4d-d6f1c70ca531 · outbound

This paper cites Cwe - cwe-183: Permissive list of allowed inputs (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-183: Permissive list of allowed inputs (4.20),

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.675106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.675106Z digest=sha256:a165d00c7aded44f2e391ebd612f3f7e346acc2a127e3a622c7d0cda8015fbba

Observation 4e30de34-2a8b-458d-8406-a98b42c395ed · outbound

This paper cites Cwe - cwe-184: Incomplete list of disallowed inputs (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-184: Incomplete list of disallowed inputs (4.20),

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.678063Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.678063Z digest=sha256:68a7f198117059dc1fcf4206880ba8e418f7f71c66076dfe15a481dd2c003aa3

Observation 73189794-b6a1-4b39-af6a-5b883ddcb3ed · outbound

This paper cites weights only unpickler.py – pytorch,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks weights only unpickler.py – pytorch,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.680920Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.680920Z digest=sha256:f7d51208a33c52c0aaf0613465dcfb2d0f889ad061f873d6053e218d6eff52e5

Observation 387c2dc7-e00f-4041-b9e1-d9a6827a0cd2 · outbound

This paper cites Zollllldont download this2 - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Zollllldont download this2 - model card,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.683781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.683781Z digest=sha256:b5e2adffdbbb077c62c899a2b5f1299dcefda740ea56074b635e630a8ef6b2c6

Observation 2141c251-faec-40af-b5d3-17bb3e0170e3 · outbound

This paper cites “dont download this.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks “dont download this

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.686757Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.686757Z digest=sha256:b1212f0d0666b10eaa48f8a0bd5219eccc78c2b2ca249f8a6c8dafdbbef67396

Observation a0eec29c-3747-497b-8000-e351109dbf53 · outbound

This paper cites picklescan: Security scanner detecting python pickle files performing suspicious actions,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks picklescan: Security scanner detecting python pickle files performing suspicious actions,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.690224Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.690224Z digest=sha256:7594b207b324ec4baf09c2d82a131f3ad1c7e4855209f26dc3c1d09c761cb965

Observation 123db4fe-8f4f-4b39-baeb-f473081d3753 · outbound

This paper cites Modelscan: Protection against model serialization attacks,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Modelscan: Protection against model serialization attacks,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.694188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.694188Z digest=sha256:3f4f51b71efdde62eb58c6691aff02c67377cca941dfd1d5a4e8154037405f98

Observation 788e046b-46af-4838-a942-57e1876bf66b · outbound

This paper cites A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.697781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.697781Z digest=sha256:6415110f65f3a8c14e57360cdf4045f37a6d64f600106e4ce5bcae35ee5a88c9

Observation 47a9acd4-b60a-406c-bcb7-b351c3497136 · outbound

This paper cites pickletools - tools for pickle developers - docs.python.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks pickletools - tools for pickle developers - docs.python.org,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.701720Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.701720Z digest=sha256:e23cb6fd8c3a7e3d961f120f99374aa752e9f486dff68483068e25c8f6869ec3

Observation 4dbbb40c-1025-4385-b5a4-ea4a22f7e2e2 · outbound

This paper cites zlib — compression compatible with gzip - docs.python.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks zlib — compression compatible with gzip - docs.python.org,

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.705666Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.705666Z digest=sha256:8b86c17531449556689bc132c704ab1c7333cf4b6a7b7eedc7c6ce8e41c61e75

Observation 4332b548-40eb-44ff-8647-de5df7595b8a · outbound

This paper cites Fickling: A python pickling decompiler and static analyzer,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Fickling: A python pickling decompiler and static analyzer,

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.709333Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.709333Z digest=sha256:8b0775f7b92a43be6ce29d96de87166f7f920430a5b7b45bb439f0575e84d0f8

Observation 1fdaa360-8e71-457c-bd8d-5c6df8181065 · outbound

This paper cites an unresolved cited work.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Unresolved cited work

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.712443Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.712443Z digest=sha256:1993dea49d567a73d98edbde2a19ebf8fad779c90af35572c29414a6f8b7258f

Observation 5d30dfb9-bf8a-40d3-ad43-b25a07df1582 · outbound

This paper cites CPython: The python programming language,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks CPython: The python programming language,

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.715300Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.715300Z digest=sha256:f9a9c77325f6c050d360e93bbc1fc246a62eb481b17b53219923d4e8037505ca

Observation 24392e3a-795f-4800-a528-383bcfe9b598 · outbound

This paper cites Dont download this - opencsg - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Dont download this - opencsg - model card,

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.718658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.718658Z digest=sha256:e7369d892e87acda70a2914d04aa81e7a8a27b6223bfd0a4c0504c3217ce1f5b

Observation 7b04ec25-d43d-4182-a703-70a8ca6f19b3 · outbound

This paper cites The python package index — pypi.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks The python package index — pypi.org,

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.722015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.722015Z digest=sha256:2d5fd8deb6c61d7302fadf59d2d5341a358146c9413271ed0a1dd8bb27d80f3f

Observation 3d2d9b78-38e2-4387-84ba-05eb33e4f632 · outbound

This paper cites Moduleguard: Understanding and detecting module conflicts in python ecosystem,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Moduleguard: Understanding and detecting module conflicts in python ecosystem,

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.725028Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.725028Z digest=sha256:4dad5075c2b80a5f844fa2577b19ae62adee0952291d6316cca7dc9dbd553e8c

Observation 36fd50d1-2f57-4886-96c3-a4a4c52a7213 · outbound

This paper cites Reference for ultralytics/utils/patches.py — docs.ultralytics.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Reference for ultralytics/utils/patches.py — docs.ultralytics.com,

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.728268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.728268Z digest=sha256:6fcdb478b12247b8cfd16a0cbfc4a7a3182ae398653f1baf532f773983e9615a

Observation 0a5ac124-b40e-42ec-b819-79581dc5d1c1 · outbound

This paper cites Synthyraesm2-8m hugging face - huggingface.co,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Synthyraesm2-8m hugging face - huggingface.co,

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.731486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.731486Z digest=sha256:d7c001c6db2605c65f6242e1304195c4b6d1e05330d9c7b1ee83df57a7780831

Observation 0eb9cd87-2263-4ac7-80fa-36c9f942f744 · outbound

This paper cites Full text search - hugging face — huggingface.co,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Full text search - hugging face — huggingface.co,

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.734357Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.734357Z digest=sha256:de219e401860f55a4554b1aa12d26d65084e71cd04615c47a604cc10b25c8eb5

Observation 6441c0fa-43bc-4cec-9dc2-f28217d68e91 · outbound

This paper cites fakespot-ai/roberta-base-ai-text-detection-v1 - hugging face — huggingface.co,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks fakespot-ai/roberta-base-ai-text-detection-v1 - hugging face — huggingface.co,

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.737003Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.737003Z digest=sha256:0a6968ac0aa66cd13d8d2045449f1db7ba9b743459b8cd9cf10ff28c3d300a17

Observation 3984b5dc-aeca-49f8-a56e-b9d4988dfbb6 · outbound

This paper cites an unresolved cited work.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Unresolved cited work

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.739857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.739857Z digest=sha256:62d46db3290246173c703404d864671106a67c57b011649f8f2174c332917b5d

Observation b27be28b-98b5-4450-974a-cf0a2fd698cd · outbound

This paper cites Llama3-agentflan-adapter — modelscope.cn,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Llama3-agentflan-adapter — modelscope.cn,

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.742607Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.742607Z digest=sha256:ffc3ec05b3856a8ff08bb5cf11633e9fca793cdf7c156ad26b70824a69f4982f

Observation 5b23d2e4-5290-48c0-8fed-83b4dc42f2b1 · outbound

This paper cites Github - swisskyrepo/payloadsallthethings: A list of use- ful payloads and bypass for web application security and p entest/ctf — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - swisskyrepo/payloadsallthethings: A list of use- ful payloads and bypass for web application security and p entest/ctf — github.com,

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.746215Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.746215Z digest=sha256:bc7b1a11d5353adbb348c44c082a5172293d634124ab10b39a9fc4e8c62695be

Observation 4bc4f04d-82cd-475c-b4eb-8a08531e1670 · outbound

This paper cites Online - reverse shell generator — revshells.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Online - reverse shell generator — revshells.com,

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.749135Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.749135Z digest=sha256:05a0945b8fff811c2f1a1e25597ec9c5b3a6c0f04c800ab4b0cbe2bf2ec8551a

Observation f1fd5f67-0975-4b83-a75e-def0da941d53 · outbound

This paper cites Adds dataflow analysis, generalizes constant opcodes, and cleans up injection by esultanik · pull request #28 · trailofbits/fickling — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Adds dataflow analysis, generalizes constant opcodes, and cleans up injection by esultanik · pull request #28 · trailofbits/fickling — github.com,

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.751873Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.751873Z digest=sha256:4ad72c206ae7338974cb38673ad72d15e7874efb1106671811dbc04c6277d583

Observation 2c25d574-4db3-49f5-91cf-9c39bc6edd25 · outbound

This paper cites Trail of bits — trailofbits.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Trail of bits — trailofbits.com,

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.754610Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.754610Z digest=sha256:2a2ab00da300fafe8569b82ea1bed27371c46c127ffe5927bccaaeb36005b7ea

Observation b469c063-44db-4fa2-a607-bfd9a8dc9a2d · outbound

This paper cites Welcome to fastai – fastai,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Welcome to fastai – fastai,

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.757319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.757319Z digest=sha256:7a4341b5635a458c55cc0a085352992c4b6c30b490c820a8b231fd9f610317b9

Observation 74f7578b-e045-4918-a997-4ec08d5e01d0 · outbound

This paper cites Github - columbia/pickleball: Pickleball protects users from dangerous pickle-based ml models — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - columbia/pickleball: Pickleball protects users from dangerous pickle-based ml models — github.com,

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.760083Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.760083Z digest=sha256:631050e34402b3e216bf0082b143dd03ce2fae5aec55f7e21ea6fcffc66765bb

Observation fa859f60-af0b-406a-8785-21e04845831f · outbound

This paper cites Github - s2e-lab/hf-model-analyzer - modeltracer,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - s2e-lab/hf-model-analyzer - modeltracer,

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.763189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.763189Z digest=sha256:80ff23ccfb4e0cc4d870c089865e6f408aadb90251dcaa1b122a398ac1c0338f

Observation 260adfa9-02e6-4120-9517-4d8a73692fb1 · outbound

This paper cites Raft - pypi,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Raft - pypi,

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.766256Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.766256Z digest=sha256:3288fd4fb2bd476b5e6239aa3128db7490e28bbf1d548f697e3dbc3950bf099f

Observation cb1f781d-2d49-4381-889d-26c3f7ca19a2 · outbound

This paper cites Dont download this model - modelscope - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Dont download this model - modelscope - model card,

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.769921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.769921Z digest=sha256:90a7447b51350fbf8f8998b71ae01f53cc591745f3693b6a7df63df0e99f1573

Observation f9c6e17c-7d8d-4e91-bedf-d179f9bfe996 · outbound

This paper cites Shadowpickle-bench/dont download this - github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Shadowpickle-bench/dont download this - github.com,

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.773856Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.773856Z digest=sha256:2ab0d8c0aca0f26efc9ee5c5fc5ceff778bda933a8c0f7f0c89a04f62c4dcdb3

Observation fee03c52-7a55-40db-80f5-c8281c99a6e2 · outbound

This paper cites Github - dashingsoft/pyarmor: A tool used to obfuscate python scripts , bind obfuscated scripts to fixed machine or expire obfus- cated scripts. — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - dashingsoft/pyarmor: A tool used to obfuscate python scripts , bind obfuscated scripts to fixed machine or expire obfus- cated scripts. — github.com,

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.777605Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.777605Z digest=sha256:bea0e91de4dd51a11d8f48600ea9e92b2d628bdc4e6ff51fc6cdd4231bc2d59c

Observation b3f79214-8a8d-41ae-aada-c8b7d3d76287 · outbound

This paper cites Github - nyudenkov/pysentry: Scan your python depen- dencies for known security vulnerabilities with rust-powered scanner - github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - nyudenkov/pysentry: Scan your python depen- dencies for known security vulnerabilities with rust-powered scanner - github.com,

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.781231Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.781231Z digest=sha256:88824f30adef284e616bd8f5ee91051bfbf32b89d907846fc484f99040707388

Observation 6013a5f3-d46c-4216-855d-fe8cdc428a6b · outbound

This paper cites Github - splitline/pickora: A toy compiler that can convert python scripts to pickle bytecode,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - splitline/pickora: A toy compiler that can convert python scripts to pickle bytecode,

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.784734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.784734Z digest=sha256:8be9b4c0166c4542e71e668952a42208d19bdc4548c6b21ad8fce665a2eda430

Observation df7a2e59-9936-4225-a56b-ea0b06d4fc48 · outbound

This paper cites Github - security-pride/malhug,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - security-pride/malhug,

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.788078Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.788078Z digest=sha256:928deed2b0cf6872809dcd6e376d8294262714b9e9e041a7f29e3b05dc7ea41d

Observation 26a7b358-4799-4eec-aa52-385bb33bfd3e · outbound

This paper cites /bin/bash.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks /bin/bash

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.792127Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.792127Z digest=sha256:c262ff2c4893a4adcd55ccfbd8b85c986492ad347f7663c8be030bb245fa9659

Observation e9daeb42-040c-4fcc-899c-ca99ac5c6657 · outbound

This paper cites The collected payloads are Pickled into self-contained files, such that they can be directly injected into PyTorch models, as they are both binary data with the same set of opcodes.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks The collected payloads are Pickled into self-contained files, such that they can be directly injected into PyTorch models, as they are both binary data with the same set of opcodes

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.795575Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.795575Z digest=sha256:8fe07cd1dd3bfd470669c7c521a960f12a26bc5a3099071051e48a2475d23ae6

Observation a690f43c-2654-45c0-96cd-abb0b5fe9c03 · outbound

This paper cites We then edit the memory addresses of the injecting Pickle file to be greater than TABLE XVII: Open-source SOTA’s performance on SHADOWPICKLEvs.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks We then edit the memory addresses of the injecting Pickle file to be greater than TABLE XVII: Open-source SOTA’s performance on SHADOWPICKLEvs

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.798789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.798789Z digest=sha256:4679bd14ba18af29a8a470bc1ed42be14773df293d85551e28455c9b11639591

Observation e27e960a-f36e-4cda-874d-be4afda9b60d · outbound

This paper cites cat /etc/passwd.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks cat /etc/passwd

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.801965Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.801965Z digest=sha256:9d8e4a19f8afc5947b964f7cde3fbf55f63ee6d53c637dfbe9816b74227b8335

Pith citing papers

No inbound Pith citation observations are available.