Pith. sign in

Paper Citation Record · LEDGER

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks

As of 19 August 2026, this Paper Citation Record lists 77 of 77 outbound references and 0 inbound Pith citation observations for arXiv:2607.17503.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.17503 v1

Coverage vector

measured 77 of 77 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T17:51:45.801965Z

measured 77 of 77 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

77 of 77 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved77
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 35704110-02a4-490e-8a77-9f0b6f86a560 · outbound

This paper cites Hugging face – the ai community building the future.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Hugging face – the ai community building the future

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.556488Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.556488Z digest=sha256:bf0b12fec0baec6d8148b96eb852e3022743b9364d3df455cc137b1edb774665

Observation 1c0647a8-2662-4b70-8566-318c6be61e8f · outbound

This paper cites an unresolved cited work.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Unresolved cited work

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.562913Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.562913Z digest=sha256:43f31099918782eb28253a198bfdff02701a5c72fab300862731bcbb5633b80f

Observation 1b43a903-09a4-4a74-aa94-6ebe76b1aabc · outbound

This paper cites Opencsg,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Opencsg,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.566381Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.566381Z digest=sha256:a35dede807b4c2ef5a7a2331bea63076d7fc6045d85e093dca159ecf47bd3451

Observation 017c25f6-2a97-4a15-a96f-1f1c02029f67 · outbound

This paper cites Modelscope,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Modelscope,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.570126Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.570126Z digest=sha256:5b47a4a441882e576405ef3044f144084edc8694002be0570f6d0f7b40f5898e

Observation 62f5d65a-0455-4aca-a766-2f609f20280f · outbound

This paper cites nvidia/nemotron-cascade-2-30b-a3b - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks nvidia/nemotron-cascade-2-30b-a3b - hugging face,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.573101Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.573101Z digest=sha256:bc1c6d0b3eaa6104804a0123b40c8936bc1c9fa9b4d9de69b076509cffb3f34c

Observation 4223c188-4e34-4ad0-9152-6444406b1e12 · outbound

This paper cites google/gemma-4-31b-it - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks google/gemma-4-31b-it - hugging face,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.576408Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.576408Z digest=sha256:e2a969e62eabbe7c5dead794a14db3201005ddec4d00584ff880f508033967c5

Observation 22efd49b-0d6e-4073-93b4-681fb061d101 · outbound

This paper cites microsoft/harrier-oss-v1-0.6b - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks microsoft/harrier-oss-v1-0.6b - hugging face,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.579743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.579743Z digest=sha256:db518207aee9521b11d126679bde0b005ce529ddddb3be6b050e551f68290280

Observation 747f71a9-522a-468a-a9b4-ea267f769e85 · outbound

This paper cites openai/gpt-oss-120b - hugging face,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks openai/gpt-oss-120b - hugging face,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.582579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.582579Z digest=sha256:d5a479c8424b55ac44d85f3bd6bbf12342a1e912362b75b4596a282822ceabe3

Observation 56e11e20-98bc-4414-8737-f2fbc4e34308 · outbound

This paper cites [Online].

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks [Online]

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.585259Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.585259Z digest=sha256:3a6ae1197ff78b04e03b5cff050a87ef536b63aa6568fafb28228ee171a02b60

Observation 8b6fa409-d1c0-43a9-83bd-5592b03d0745 · outbound

This paper cites Data scientists targeted by malicious hugging face ml models with silent backdoor,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Data scientists targeted by malicious hugging face ml models with silent backdoor,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.588118Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.588118Z digest=sha256:12c237bbfb881eeb8012a5e0dcea42df6020f1849366cb6645e7a4688467f1e0

Observation 5c8cc722-3874-4a1b-8122-bb964bedc8d5 · outbound

This paper cites Models are codes: Towards measuring malicious code poisoning attacks on pre-trained model hubs,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Models are codes: Towards measuring malicious code poisoning attacks on pre-trained model hubs,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.590992Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.590992Z digest=sha256:2ed7944b46ec1ae49f9db146082661e537ed8d8e901ff6278fc42ef4e4fb5732

Observation 319abae0-f1a3-4820-aee5-9930b2e825ea · outbound

This paper cites Third-party scanner: Jfrog,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Third-party scanner: Jfrog,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.593984Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.593984Z digest=sha256:3e786195e6a3b5c09906cb3b709f3ef9e94ddee90953ee58ea44fa9f36a23475

Observation 6c4f80cb-4ea4-4aa6-b44b-e6890312526e · outbound

This paper cites third-party scanner: protect ai,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks third-party scanner: protect ai,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.596831Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.596831Z digest=sha256:da0547613a4bdeb043a24a1887158a79d669550681f676f8088c9c3cf9799616

Observation e7becbb0-4d01-43bb-a65e-fdf28873428f · outbound

This paper cites pickle scanning (hub documentation),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks pickle scanning (hub documentation),

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.599762Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.599762Z digest=sha256:9ab7d38572fe7093a37df5ce9c0a8cf63c4fd5929a332e84d11414eca54903ef

Observation 6f42939d-e4ec-4b0b-81cc-e638829d2195 · outbound

This paper cites Hugging face and virustotal collaborate to strengthen ai security,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Hugging face and virustotal collaborate to strengthen ai security,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.603036Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.603036Z digest=sha256:75651387896e8e6337cf3fd549a8db1f0f5aa8c815ccd36f5061fa0c8ceb52ed

Observation 8f5e7171-cec4-47cc-a9cf-c6d0a71a9b01 · outbound

This paper cites Gentel - home,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Gentel - home,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.606194Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.606194Z digest=sha256:14edc99eb8c872b9c02ee313da35adc43d368e5ff866bf02eafaab0e07982f5f

Observation 1bab09cc-e0fe-4892-ac54-2a2f46b5a60d · outbound

This paper cites Opencsg - gentel example,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Opencsg - gentel example,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.609086Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.609086Z digest=sha256:ac641a8e925f01b95bde4b68aa9cf11073f74060eddff9dbb7c139fcc0e6df5a

Observation 4702497d-999b-42a1-993a-b9c7f636a464 · outbound

This paper cites Malicious ml models discovered on hugging face platform - reversinglabs,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Malicious ml models discovered on hugging face platform - reversinglabs,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.612129Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.612129Z digest=sha256:0d79749de301efe8e75d3b92177925eac910a93642d09653fed26facc3c23f38

Observation 63f68c1d-733f-47e4-a6ce-571ad899fda2 · outbound

This paper cites 4m models scanned: Protect ai + hugging face 6 months in,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks 4m models scanned: Protect ai + hugging face 6 months in,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.615475Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.615475Z digest=sha256:490dac11f45636d6c409b85d7eb72342095b63497a9afb69392ba684352793d9

Observation 0839cc4f-7c5e-4685-a27a-29b38abc3be4 · outbound

This paper cites New hugging face vulnerability exposes ai models to supply chain attacks,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks New hugging face vulnerability exposes ai models to supply chain attacks,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.618725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.618725Z digest=sha256:b35a13785c21dc1ee694298d1faddf0698d8d5f3a713eb93a1ab86e3addde39a

Observation b956acbf-faac-41f9-8898-7c6ffbf3a753 · outbound

This paper cites Over 100 malicious ai/ml models found on hugging face platform,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Over 100 malicious ai/ml models found on hugging face platform,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.621808Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.621808Z digest=sha256:ed2ba9ead9d7cdb6b9461c312952425478b79d7c045eb29f37cfd968cb9be2ec

Observation 2fed1bb0-caa6-40fd-a107-b46fe5d68d02 · outbound

This paper cites Malicious ml models on hugging face leverage broken pickle format to evade detection,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Malicious ml models on hugging face leverage broken pickle format to evade detection,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.625425Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.625425Z digest=sha256:16561d527113ae3d12c95f1c4eb2c82457eac018d0411d9b6991d27ed49481d8

Observation b449cfb2-2b28-42ce-b244-cfa52a17e419 · outbound

This paper cites Montalbano, https://www.darkreading.com/application-security/hugg ing-face-ai-platform-100-malicious-code-execution-models, Feb 2024.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Montalbano, https://www.darkreading.com/application-security/hugg ing-face-ai-platform-100-malicious-code-execution-models, Feb 2024

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.629111Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.629111Z digest=sha256:00751d37696b2cdbac5f4bcb89a2a354026e607295faf3a5f26e44b647768fa6

Observation 35ee187d-367c-441d-83ba-1e685cb1947f · outbound

This paper cites Malicious AI Models on Hugging Face Exploit Novel A ttack Technique,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Malicious AI Models on Hugging Face Exploit Novel A ttack Technique,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.632539Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.632539Z digest=sha256:acbf6b0d2a7dc3b32dcac34b7ce4fd8db138d8f39bd97628206dec1fb6542c6c

Observation f3dc4bf0-c1bc-45f2-85c7-c640cfbfa57f · outbound

This paper cites Federal Register :: Request Access,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Federal Register :: Request Access,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.635735Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.635735Z digest=sha256:71187671b6451db80958e15dcbc2ecb01ce2d98f6fba2a0840e5a3c59315ee04

Observation 6a67299c-50e7-4d1d-92de-cebe6156b954 · outbound

This paper cites cve.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks cve.org,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.638812Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.638812Z digest=sha256:b6e2daec52eac3b7f5d8074a20af2a41bc2fe28d0f9d4b65240f30224528b2b9

Observation 28c8b31d-0526-4b30-91fa-103d499fd6cd · outbound

This paper cites Pickleball: Secure deserialization of pickle-based machine learning models (extended report),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Pickleball: Secure deserialization of pickle-based machine learning models (extended report),

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.641819Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.641819Z digest=sha256:9f21c41239357a7101f4a72f425c048ac98cc919021c8ce33981db024a8ab298

Observation 70ac1f57-73a5-4e00-8eac-3d37e71aa330 · outbound

This paper cites How to make hugging face to hug worms: Discovering and exploiting unsafe pickle.loads over pre-trained large model hubs - blackhat asia 2024,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks How to make hugging face to hug worms: Discovering and exploiting unsafe pickle.loads over pre-trained large model hubs - blackhat asia 2024,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.644897Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.644897Z digest=sha256:aab68d77891f9f22bc30177361ab31cbce72d94de5e180076878873614c8d536

Observation 844b3273-6508-4e71-a5d3-a7c69ad07e81 · outbound

This paper cites coldwaterq/sectest - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks coldwaterq/sectest - model card,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.648185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.648185Z digest=sha256:899cb3d22f757f0e3619e1cac659a4f3c96ce72ed270cf8cde4bb2f05a2634f9

Observation f99c6456-ae88-4521-b942-ca6b4018cdb8 · outbound

This paper cites zpbrent/reuse - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks zpbrent/reuse - model card,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.650957Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.650957Z digest=sha256:3b26be50ff3978ccb212a574f446a8be4ff8e13a1776d413caa3f0d0d1a01dec

Observation aa0daeb5-56d7-41bd-a796-603606263552 · outbound

This paper cites The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.653822Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.653822Z digest=sha256:f02ded6ffc30203146fc2ce11d97bd2a7d5490a18b8c7403c335871903a03426

Observation fd23ad54-185a-42de-bb37-c60e4f21fc18 · outbound

This paper cites Backdooring pickles: A decade only made things worse - defcon 30,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Backdooring pickles: A decade only made things worse - defcon 30,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.657190Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.657190Z digest=sha256:b3b04c62f182a02d1cae2590101bee241ec491e3941e01674c4304ded5f089fd

Observation a09626da-0e74-47cc-8bf5-2f4612cecf5e · outbound

This paper cites Sour pickles - blackhat us 2011,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Sour pickles - blackhat us 2011,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.660445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.660445Z digest=sha256:b4e174979d767eb274128bfed626fa8390af1f49e3cbb45b7390554e858a1fee

Observation 22965169-f133-46b6-9339-3e35f41320ea · outbound

This paper cites Cwe - cwe-502: Deserialization of untrusted data (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-502: Deserialization of untrusted data (4.20),

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.663518Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.663518Z digest=sha256:49291a6b6193ef97297e3ccdf73b4c5edb0d52416d2ead04b9999fb16fae0c8f

Observation 8f041be5-e4b1-45c7-8174-9e24883bc11c · outbound

This paper cites flawed.net.nz — flawed.net.nz,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks flawed.net.nz — flawed.net.nz,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.666137Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.666137Z digest=sha256:f4b16a32e789e55e64d2008f69703e3c44d4f96580dab1b0038ca1b8c6d5b189

Observation c62d8aeb-11ed-4b83-9c34-b253c8077525 · outbound

This paper cites Secure pypi? the problem with trusting open source reposi- tories — activestate.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Secure pypi? the problem with trusting open source reposi- tories — activestate.com,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.669286Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.669286Z digest=sha256:1ee82f3f6e168b54d80d676bff1ecc30edb6468b719ee4d35f947ddd97eb17ec

Observation 5d32bdd3-6ee1-40fb-9aab-f53177984280 · outbound

This paper cites Cwe - cwe-1395: Dependency on vulnerable third-party component (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-1395: Dependency on vulnerable third-party component (4.20),

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.672358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.672358Z digest=sha256:740e0b057d8b269e5ce403a1ae154bc168503e26fc6db3b7149ba01b52063d11

Observation a5264b62-abf4-46af-ac4d-d6f1c70ca531 · outbound

This paper cites Cwe - cwe-183: Permissive list of allowed inputs (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-183: Permissive list of allowed inputs (4.20),

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.675106Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.675106Z digest=sha256:1f575b70549484c96e4583b68212ee2a82113eb1643f9f8f8447e94b2f9dda30

Observation 4e30de34-2a8b-458d-8406-a98b42c395ed · outbound

This paper cites Cwe - cwe-184: Incomplete list of disallowed inputs (4.20),.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Cwe - cwe-184: Incomplete list of disallowed inputs (4.20),

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.678063Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.678063Z digest=sha256:b8a1fbb678db72682838a95e100109edccde9204daaed9aa8a984825cf599458

Observation 73189794-b6a1-4b39-af6a-5b883ddcb3ed · outbound

This paper cites weights only unpickler.py – pytorch,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks weights only unpickler.py – pytorch,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.680920Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.680920Z digest=sha256:756d95486eb51176597562df6bb50b93e1c96e12c6943ca9505d71249ca6ffc5

Observation 387c2dc7-e00f-4041-b9e1-d9a6827a0cd2 · outbound

This paper cites Zollllldont download this2 - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Zollllldont download this2 - model card,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.683781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.683781Z digest=sha256:f06b1a4586cd8b6f26481697aacf096fb17d331d876648191f2074664de91aad

Observation 2141c251-faec-40af-b5d3-17bb3e0170e3 · outbound

This paper cites “dont download this.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks “dont download this

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.686757Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.686757Z digest=sha256:59ba0b415d24af41a5eefbf24c5d3e30fef2be26bbf854c4599294417ad49275

Observation a0eec29c-3747-497b-8000-e351109dbf53 · outbound

This paper cites picklescan: Security scanner detecting python pickle files performing suspicious actions,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks picklescan: Security scanner detecting python pickle files performing suspicious actions,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.690224Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.690224Z digest=sha256:d2e25e328ea329fffe0ce0283dee4ff09fc529ad1968a44eee617ec9a221f868

Observation 123db4fe-8f4f-4b39-baeb-f473081d3753 · outbound

This paper cites Modelscan: Protection against model serialization attacks,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Modelscan: Protection against model serialization attacks,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.694188Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.694188Z digest=sha256:21406af4e0da8c9e7b7b7d568434c4a83242fa05373f4ad2ac71777424d8570d

Observation 788e046b-46af-4838-a942-57e1876bf66b · outbound

This paper cites A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.697781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.697781Z digest=sha256:01cd800154433769eb756d32e3b7880ffbff9477388faa6d820829a4341d7908

Observation 47a9acd4-b60a-406c-bcb7-b351c3497136 · outbound

This paper cites pickletools - tools for pickle developers - docs.python.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks pickletools - tools for pickle developers - docs.python.org,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.701720Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.701720Z digest=sha256:f95240d715cef8d29fd190a3f1ec02050c3926285f8b43a4597f8f3acbb55fb0

Observation 4dbbb40c-1025-4385-b5a4-ea4a22f7e2e2 · outbound

This paper cites zlib — compression compatible with gzip - docs.python.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks zlib — compression compatible with gzip - docs.python.org,

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.705666Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.705666Z digest=sha256:6111c294bfa5a6911beced58f63438e7b0020d4b471862985940111e6938f246

Observation 4332b548-40eb-44ff-8647-de5df7595b8a · outbound

This paper cites Fickling: A python pickling decompiler and static analyzer,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Fickling: A python pickling decompiler and static analyzer,

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.709333Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.709333Z digest=sha256:d673635cd5008fabaf919f24a97a2a137dcacfba8f3b05e663e7792f3e043c87

Observation 1fdaa360-8e71-457c-bd8d-5c6df8181065 · outbound

This paper cites an unresolved cited work.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Unresolved cited work

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.712443Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.712443Z digest=sha256:5cdc77dacf741b9a45432c96cc7ec0cd3d322db0acdb17ce962f27ec072d5138

Observation 5d30dfb9-bf8a-40d3-ad43-b25a07df1582 · outbound

This paper cites CPython: The python programming language,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks CPython: The python programming language,

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.715300Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.715300Z digest=sha256:97764fa3ddca60566800c18eb026172c94302e15a91b0088ef145f197a38c6c4

Observation 24392e3a-795f-4800-a528-383bcfe9b598 · outbound

This paper cites Dont download this - opencsg - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Dont download this - opencsg - model card,

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.718658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.718658Z digest=sha256:b76b964998f4e0d1345c379072c1bb673dddb1abc1fe6dbe64ebccd995ebde9e

Observation 7b04ec25-d43d-4182-a703-70a8ca6f19b3 · outbound

This paper cites The python package index — pypi.org,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks The python package index — pypi.org,

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.722015Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.722015Z digest=sha256:f598d04d537fd467727db8df49e8b5f4c31f438b26c12814404d90b9866c9897

Observation 3d2d9b78-38e2-4387-84ba-05eb33e4f632 · outbound

This paper cites Moduleguard: Understanding and detecting module conflicts in python ecosystem,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Moduleguard: Understanding and detecting module conflicts in python ecosystem,

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.725028Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.725028Z digest=sha256:3978d58c93b588b5654aa47295a2a64036dfae8f12fa5aec26de4e97badb2440

Observation 36fd50d1-2f57-4886-96c3-a4a4c52a7213 · outbound

This paper cites Reference for ultralytics/utils/patches.py — docs.ultralytics.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Reference for ultralytics/utils/patches.py — docs.ultralytics.com,

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.728268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.728268Z digest=sha256:bc312e8ef382773f437a4ac5066764454d1fe9c1eb0e52b8c98ca6a8f6aff259

Observation 0a5ac124-b40e-42ec-b819-79581dc5d1c1 · outbound

This paper cites Synthyraesm2-8m hugging face - huggingface.co,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Synthyraesm2-8m hugging face - huggingface.co,

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.731486Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.731486Z digest=sha256:0b76ecb0de988dac9a78fdf1676fa725ae2d8254a3f8afc78d966f931a711b61

Observation 0eb9cd87-2263-4ac7-80fa-36c9f942f744 · outbound

This paper cites Full text search - hugging face — huggingface.co,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Full text search - hugging face — huggingface.co,

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.734357Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.734357Z digest=sha256:ec5c7ec386c3347b2901c3dbcdfc2fe409f978af84380f5ab788aeee9b12193b

Observation 6441c0fa-43bc-4cec-9dc2-f28217d68e91 · outbound

This paper cites fakespot-ai/roberta-base-ai-text-detection-v1 - hugging face — huggingface.co,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks fakespot-ai/roberta-base-ai-text-detection-v1 - hugging face — huggingface.co,

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.737003Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.737003Z digest=sha256:346c9c3db1139a4a2c3c04a6186f1cb9f24f562906476dd1201aa19f29f2be99

Observation 3984b5dc-aeca-49f8-a56e-b9d4988dfbb6 · outbound

This paper cites an unresolved cited work.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Unresolved cited work

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.739857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.739857Z digest=sha256:0bcb438e386027075aebd630d445e566b7e4051050971e36305484aca77179a9

Observation b27be28b-98b5-4450-974a-cf0a2fd698cd · outbound

This paper cites Llama3-agentflan-adapter — modelscope.cn,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Llama3-agentflan-adapter — modelscope.cn,

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.742607Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.742607Z digest=sha256:a9587f19bf0d23a9d25445db188bf60362b71988f7be58f4d21281d3f881221a

Observation 5b23d2e4-5290-48c0-8fed-83b4dc42f2b1 · outbound

This paper cites Github - swisskyrepo/payloadsallthethings: A list of use- ful payloads and bypass for web application security and p entest/ctf — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - swisskyrepo/payloadsallthethings: A list of use- ful payloads and bypass for web application security and p entest/ctf — github.com,

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.746215Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.746215Z digest=sha256:369d7ad03bf955f53da2fafca5dce90a5a61828ffc37fb0c923c4ef0a79d3bfb

Observation 4bc4f04d-82cd-475c-b4eb-8a08531e1670 · outbound

This paper cites Online - reverse shell generator — revshells.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Online - reverse shell generator — revshells.com,

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.749135Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.749135Z digest=sha256:548fe19c53300e74c27cca0eea57b57e37e343c2923c31fbece69b62ad14cb05

Observation f1fd5f67-0975-4b83-a75e-def0da941d53 · outbound

This paper cites Adds dataflow analysis, generalizes constant opcodes, and cleans up injection by esultanik · pull request #28 · trailofbits/fickling — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Adds dataflow analysis, generalizes constant opcodes, and cleans up injection by esultanik · pull request #28 · trailofbits/fickling — github.com,

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.751873Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.751873Z digest=sha256:5676a045a9cf7515bce2dbc85e8dc49f894686fcfca4da43c8fe56284c91650c

Observation 2c25d574-4db3-49f5-91cf-9c39bc6edd25 · outbound

This paper cites Trail of bits — trailofbits.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Trail of bits — trailofbits.com,

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.754610Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.754610Z digest=sha256:ec276c6e0e075fe8c91e20a55e16ac965efd58bdcc13540e84f47cdf2dfbae6f

Observation b469c063-44db-4fa2-a607-bfd9a8dc9a2d · outbound

This paper cites Welcome to fastai – fastai,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Welcome to fastai – fastai,

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.757319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.757319Z digest=sha256:eae29c79089e59408654f8210bf8ffca52e1e80a400a93474b90f9142f8405f0

Observation 74f7578b-e045-4918-a997-4ec08d5e01d0 · outbound

This paper cites Github - columbia/pickleball: Pickleball protects users from dangerous pickle-based ml models — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - columbia/pickleball: Pickleball protects users from dangerous pickle-based ml models — github.com,

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.760083Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.760083Z digest=sha256:1e21c6c15aac4540c9d706d5e20118e965c3fe0c0eaab699cdab1b7e6290bd26

Observation fa859f60-af0b-406a-8785-21e04845831f · outbound

This paper cites Github - s2e-lab/hf-model-analyzer - modeltracer,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - s2e-lab/hf-model-analyzer - modeltracer,

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.763189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.763189Z digest=sha256:7230d6c568511d4bb5d3bacc1866ca0813bdeed9eb416a70b9e68c7b4fdf40fe

Observation 260adfa9-02e6-4120-9517-4d8a73692fb1 · outbound

This paper cites Raft - pypi,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Raft - pypi,

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.766256Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.766256Z digest=sha256:48a804e1a11d6655c8ea9fe5bc841a00d46a32ae699ac7d8e4025f20d01a5218

Observation cb1f781d-2d49-4381-889d-26c3f7ca19a2 · outbound

This paper cites Dont download this model - modelscope - model card,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Dont download this model - modelscope - model card,

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.769921Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.769921Z digest=sha256:7d1aca79edbd24e3c81e9b6d94240090453fb5ec534113bf8a2383299a177013

Observation f9c6e17c-7d8d-4e91-bedf-d179f9bfe996 · outbound

This paper cites Shadowpickle-bench/dont download this - github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Shadowpickle-bench/dont download this - github.com,

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.773856Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.773856Z digest=sha256:daaf13b84151adbc9e490222b7d80bdd43209487be46031b12467c125a0c3ea8

Observation fee03c52-7a55-40db-80f5-c8281c99a6e2 · outbound

This paper cites Github - dashingsoft/pyarmor: A tool used to obfuscate python scripts , bind obfuscated scripts to fixed machine or expire obfus- cated scripts. — github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - dashingsoft/pyarmor: A tool used to obfuscate python scripts , bind obfuscated scripts to fixed machine or expire obfus- cated scripts. — github.com,

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.777605Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.777605Z digest=sha256:412ea2280c1867a3d94768bdaff08803bd956128334cbdb33461fccd253036d1

Observation b3f79214-8a8d-41ae-aada-c8b7d3d76287 · outbound

This paper cites Github - nyudenkov/pysentry: Scan your python depen- dencies for known security vulnerabilities with rust-powered scanner - github.com,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - nyudenkov/pysentry: Scan your python depen- dencies for known security vulnerabilities with rust-powered scanner - github.com,

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.781231Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.781231Z digest=sha256:f28e3fd195d678b89469e22d30f262d7254c9c0c6a52596dfca13c2202b373e3

Observation 6013a5f3-d46c-4216-855d-fe8cdc428a6b · outbound

This paper cites Github - splitline/pickora: A toy compiler that can convert python scripts to pickle bytecode,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - splitline/pickora: A toy compiler that can convert python scripts to pickle bytecode,

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.784734Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.784734Z digest=sha256:c16325040354d9bcbd8ad7f8b145772e2fd287d4ad7725d26673a48e750f50c2

Observation df7a2e59-9936-4225-a56b-ea0b06d4fc48 · outbound

This paper cites Github - security-pride/malhug,.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks Github - security-pride/malhug,

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.788078Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.788078Z digest=sha256:f047eaa22e6b31bc5efd2b1467d5c5e62ab5e87c79b081e0282162fb950cba6b

Observation 26a7b358-4799-4eec-aa52-385bb33bfd3e · outbound

This paper cites /bin/bash.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks /bin/bash

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.792127Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.792127Z digest=sha256:7cb9366c8be8fbd68f78412b3e29482fcdd45397d82f29b501f3f2a386bad77d

Observation e9daeb42-040c-4fcc-899c-ca99ac5c6657 · outbound

This paper cites The collected payloads are Pickled into self-contained files, such that they can be directly injected into PyTorch models, as they are both binary data with the same set of opcodes.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks The collected payloads are Pickled into self-contained files, such that they can be directly injected into PyTorch models, as they are both binary data with the same set of opcodes

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.795575Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.795575Z digest=sha256:58f87c4d3f6fc17b7c3c2f8c922646f95c8c5ee16e76c9c20680d2f220de7354

Observation a690f43c-2654-45c0-96cd-abb0b5fe9c03 · outbound

This paper cites We then edit the memory addresses of the injecting Pickle file to be greater than TABLE XVII: Open-source SOTA’s performance on SHADOWPICKLEvs.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks We then edit the memory addresses of the injecting Pickle file to be greater than TABLE XVII: Open-source SOTA’s performance on SHADOWPICKLEvs

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.798789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.798789Z digest=sha256:278edf7e988831c2f932371a72666b8ede329af7d30492a6f2ed284482d0b661

Observation e27e960a-f36e-4cda-874d-be4afda9b60d · outbound

This paper cites cat /etc/passwd.

ShadowPickle: Evading Machine Learning Model Scanners via Stealthy Pickle Deserialization Attacks cat /etc/passwd

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-01T17:51:45.801965Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T17:51:45.801965Z digest=sha256:4b8a9b0c1d0b81fecbebeab10804d50076b3518bdf3be2c89704093bb4c8ae86

Pith citing papers

No inbound Pith citation observations are available.