Is this a ShowHN ?
It looks nice, but I don't feel safe using untrusted pickle weights of pretrained models, as they can allow for arbitrary code execution.
It looks nice, but I don't feel safe using untrusted pickle weights of pretrained models, as they can allow for arbitrary code execution.
I fully understand your concerns, but I don't know how to guarantee that the pkl is ok. Don't run it on your computer, but in some isolated environment, like Colab.
I'd argue that running untrusted code in a Colab is even worse, as you'd risk your account instead of just your computer.
I don't think pickle files can be loaded safely, it's better to use a numpy archive npz to store the weights which can be loaded without a security risk by using allow_pickle=false when loading (the default since numpy 1.16.3)