One of the reasons I'm not a huge fan of PyTorch.
One of the reasons I'm not a huge fan of PyTorch.
It isn't like a multi gigabyte game for example, where knowing if there is any malicious code could easily be a multi-month reverse engineering project to get to the answer of 'probably not, but we don't have time to check every byte with a fine tooth comb'
In practice, who's going to bother checking the language model? All the code that runs Stable Diffusion or other Hugging Face models that I've seen just downloads the model dynamically, then uses it without asking question. That's a pretty low-hanging supply chain attack waiting to happen, I believe.
Some solutions for checking: https://huggingface.co/docs/hub/security-pickle
or run them in an isolated env.