DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits".
Elias: The gist The first sentence stands alone as a one-line summary of the paper's subject and finding: DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs,
Nadia: First, who's behind it and why it matters.
Paper summary: Elias: So, wrapping up this discussion on DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits, the core idea is using a stack-based, context-aware scanner to reliably catch security issues in Pickle models.
Nadia: That’s right. It uses a trace generator that safely emulates the PVM and an intention analyzer that performs semantic analysis on critical states to determine if model behavior is legitimate or malicious.
Priya: And it achieved one hundred percent scanning coverage and zero false negative rate, with a low average false positive rate of zero point seven percent on their PickleBench dataset.
Elias: The authors found that DITTO consistently achieved an F1 score of zero point nine six six on PickleBench, which they said is better than the state-of-the-art scanners' F1 score of zero point seven seven six.
Nadia: This paper gives us a practical solution for promoting actionable security audits for PTM reuse by providing a method that focuses on only the most relevant parts of the deserialization process.
Priya: It’s about moving past just recording every single step and focusing only on what actually matters for security, which is what makes this system useful in practice.
Conclusion: Nadia: So, DITTO is this new scanner they put out, right? It’s called "DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits."
Elias: Yeah, it’s trying to tackle that big problem with Pickle models. The authors are the ones who built it.
Priya: So, what’s the main point they’re making about this whole scanner thing? What did they actually prove?
Nadia: They showed that this DITTO tool can scan every single model in their test set without missing anything dangerous. It found zero false negatives.
Elias: And the false positives are kept really low, only about zero point seven percent on their specific benchmark called PickleBench. That’s a big number for a scanner like this.
Priya: So, for someone just listening to the show, what does that actually mean in terms of security? What's the practical takeaway?
Nadia: It means developers who use these models can actually trust if they are reusing them safely. It gives them a way to audit those complex model files without having to run every single operation themselves.
Elias: The paper’s focusing on how they built the "trace generator" and the "intention analyzer." They’re basically building a safe way to look inside that messy Pickle code without letting anything actually run.
Priya: It sounds like it shifts the focus from just checking if a file is okay, to understanding *how* it’s supposed to be behaving. That makes sense for privacy researchers too, because you need context for that kind of analysis.
Nadia: Exactly. It moves beyond simple scanning and tries to figure out the actual security intent behind what's happening in the code structure.
Elias: It’s about making sure that when you reuse these pre-trained models, you’re not accidentally opening a backdoor just because of how they were serialized.
Priya: So, it seems like this work is pointing toward a way to make model reuse safer for everyone working in the machine learning space. But what happens next with these kinds of tools?
Qiaolin Qin, Wanpeng Li, Benoit Baudry, Lorenzo De Carli, Heng Li, Ettore Merlo
Polytechnique Montreal, Montreal, Canada · University of Liverpool, Liverpool, England
cs.CR, cs.SE
Submitted: 2026-10-07
Updated: 2026-10-07
Code: https://github.com/IsabelleQin/DITTO-A-Context-aware-Pickle-based-P
License: http://creativecommons.org/licenses/by/4.0/
The gist: The gist The first sentence stands alone as a one-line summary of the paper's subject and finding: DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs, achieves 100% scanning
Key concepts
- Pickle-based PTMs
- These are pre-trained models that use the Pickle format for saving their structure and data. While convenient, Pickle is insecure because it can be exploited during loading to execute malicious code.
- Trace Generator
- This component safely records the steps of how a model loads without actually running dangerous operations. It emulates the virtual machine used by Pickle to capture all security-sensitive loading behaviors for later analysis.
- Intention Analyzer
- This part examines the recorded trace to determine if the model's actions are legitimate or malicious. It focuses on how security-critical data is used in context, rather than just looking at the data itself.
- PickleBench
- This is a custom testing dataset containing both safe and malicious Pickle models. It was created to rigorously test scanners like DITTO, allowing researchers to measure performance metrics like coverage and false positive rates.
Terminology
Summary
The gist The first sentence stands alone as a one-line summary of the paper's subject and finding: DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs, achieves 100% scanning coverage, 0% false negative rate, and a 0.7% false positive rate on PickleBench.
Motivation and Problem Statement
Pre-trained models are widely distributed as serialized binaries, but their reuse often exposes software supply chains to deserialization attacks. Despite safer serialization formats, the unsafe Pickle format remains prevalent in public PTMs. Our analysis of over 10,023 popular Hugging Face repositories reveals that 9.3% rely on Pickle and these models include highly downloaded PTMs and models published by major organizations such as NVIDIA, IBM, and OpenAI. Pickle is unsafe because it can trigger attacker-controlled behavior with three types of security-sensitive deserialization operations: import, invoke, and alter. Existing defenses primarily rely on restricted loaders or model scanners which suffer from a coverage–precision gap. This gap means scanners can fail to capture security-sensitive deserialization behavior while generating excessive false alerts. The paper identifies three key challenges in designing a reliable model scanner: C1, how can a scanner faithfully capture security-sensitive deserialization behavior? C2, how can a scanner distinguish malicious behavior from legitimate model reconstruction? and C3, how can context-aware analysis remain practical and reliable?
DITTO Architecture
DITTO is introduced as the first stack-based, context-aware scanner for Pickle-based PTMs. It comprises two major components: a trace generator and an intention analyzer. To address C1, the trace generator implements framework-consistent model loading and emulates the stack-based Pickle virtual machine (PVM) to generate a deserialization trace without dynamically executing security-sensitive operations. To address C2, the intention analyzer extracts security-critical states from the trace and performs automated semantic analysis over their usage context to reason about their legitimacy. This design enables DITTO to safely track and reason about deserialization behaviors and support downstream audits.
Trace Generator Details
The trace generator addresses C1 by following the intended framework loading path and safely emulating Pickle deserialization to capture security-sensitive PVM state transitions. It uses framework-consistent loading, where DITTO relies on the intended framework loader rather than independently locating Pickle content in the PTM. Before native Pickle deserialization executes security-sensitive PVM operations, DITTO intercepts the corresponding Pickle-loading interface and redirects the stream to its trace generator. It emulates routine reconstruction opcodes according to their PVM semantics, but it does not directly execute the security-sensitive import, invocation, or alteration operations summarized in Table I.
Intention Analyzer and Contextual Analysis
The intention analyzer transforms the generated trace into a security assessment through two stages. First, security-critical state extraction reduces the trace to states and dependencies needed for security analysis by suppressing routine states rooted exclusively in allowlisted objects. Second, context-aware intention analysis reasons about how these retained security-sensitive objects are used, rather than judging them from global identity alone. The semantic analyzer considers arguments, target objects, invocations, alterations, derived states, and relevant dependencies to determine whether the observed behavior is consistent with legitimate model reconstruction or indicates malicious intent.
Evaluation and Results
To systematically evaluate DITTO with state-of-the-art scanners, a benchmark called PickleBench was constructed. This benchmark comprises 959 benign real-world Pickle-based PTMs and 92 representative malicious models, including previously studied attacks. Under its default configuration, DITTO successfully scans all models and detects all malicious instances, maintaining a 100% scanning coverage and a 0% false negative rate across three independent runs. At the same time, it produces only 0.7% false positives on average, resulting in an F1 score of 0.966. This significantly outperforms the state-of-the-art scanners' F1 score of 0.776 on the same benchmark. DITTO achieves a 100% scanning coverage on PickleBench, detects all 92 malicious PTMs and reduces the average FPR to 0.7%, achieving an F1 score of 0.966.
Key Contributions
The study makes four main contributions. First, a large-scale study of recent Pickle usage identifies that 9,544 Pickle-based PTMs were found across 929 repositories (9.3%). Second, the discovery of Extension Registry Exploitation uncovers a previously unexamined blind spot in Pickle’s EXT operations where registry manipulation can redirect extension opcodes to risky globals without being tracked by scanners. Third, the construction of PickleBench provides a benchmark of 959 benign and 92 malicious models that combines rigorously validated real-world PTMs with representative deserialization attacks. Fourth, DITTO presents the first stack-based, context-aware scanner for Pickle-based PTMs which consistently achieved a 100% scanning coverage, 0% FNR, and a 0.7% FPR on PickleBench.
Conclusion
DITTO provides a practical solution that promotes actionable security audits for PTM reuse. DITTO implements a framework-consistent model loading strategy and faithfully traces security-sensitive states without executing potentially malicious operations. DITTO also integrates a security-critical state extractor that facilitates automated, semantic-based PTM intention reasoning and downstream security audits. On our PickleBench dataset, DITTO achieves 100% scanning coverage, 0% FNR, and 0.7% FPR. It obtained an F1 score of 0.966, outperforming baselines. DITTO provides a practical solution that promotes actionable security audits for PTM reuse >
How it works
-
Trace Generator: The trace generator combines framework-consistent loading, safe PVM emulation, and state-aware operation tracking to capture security-sensitive deserialization behavior without executing the underlying operations. It uses Var objects to represent symbolic results of operations, recording the operation and operands that produced each state.
-
Intention Analyzer: The intention analyzer performs two stages. First, security-critical state extraction reduces the trace by extracting the dependency closure of security-sensitive and unresolved states by suppressing routine states rooted exclusively in allowlisted objects. Second, context-aware intention analysis reasons about how these retained security-sensitive objects are used to distinguish legitimate model reconstruction from malicious behavior.
Evaluation Metrics
The evaluation uses scanning coverage (SC), false-positive rate (FPR), falsenegative rate (FNR), and F1 score. SC measures the proportion of PTMs for which a scanner successfully completes its analysis and produces a valid security assessment. FPR, FNR, and F1 score are calculated only on successfully scanned PTMs.
Ablation Studies
The ablation study shows that DITTO’s security-critical state extraction promotes its scanning performance by removing redundant reconstruction states. Removing the state extractor reduces scanning coverage from 100% to 99.2% and increases false positives from 7 to 50, reducing F1 from 0.966 to 0.785. This supports C3 by showing that retaining only security-relevant reconstruction context is more practical than directly analyzing the complete deserialization trace.
Semantic Analyzer Sensitivity
The analysis shows that analyzer selection can substantially affect classification behavior. DITTOGPT reduces false positives from 7 to 3 but introduces 24 false negatives, decreasing F1 from 0.966 to 0.830. DITTO-Gemini correctly classifies all PTMs in the evaluation and achieves an F1 score of 1.000.
Ethical Considerations
The study involves several stakeholders, including PTM users and developers, modelhub operators, model-scanner developers, and the broader ML software supply-chain community. The work responsibly disclosed two previously unexamined extension-registry exploitation paths to affected parties before publication. DITTO’s semantic-analysis stage can use remotely hosted semantic models, and it extracts only the security-critical states required for analysis rather than submitting the complete deserialization trace. The goal is to characterize systematic weaknesses in existing defenses rather than attribute malicious intent to stakeholders.
Related Work
Previous work on PTM-based software supply chain security identifies three typical ML-specific supply chain attacks, namely downstream variable overwrite, vulnerability injection, and system defense bypassing.
Improvements for AI systems
-
textbf Ensure 100% Scanning Coverage via Framework-Consistent Loading: DITTO's strategy
relies on the intended framework loader rather than independently locating Pickle content in the PTM,
which allows it to achieve100% SC for various PTM loading logic and packaging structures.
-
textbf Implement State-Aware Operation Tracking: The system should utilize the mechanism where
Variables produced by these operations are retained as state arguments if they are associated with a security-critical state,
ensuring that the trace captureshow security-sensitive values are imported, transformed, invoked, or altered without invoking their underlying implementations.
-
textbf Contextual Intention Reasoning: The AI system must perform
context-aware intention analysis
by reasoning about usage context rather than just global identity alone to distinguishlegitimate model reconstruction from malicious behavior,
as demonstrated by DITTO distinguishing between benign uses ofbuiltins.getattr
and malicious invocations on attacker-controlled code strings. -
textbf Optimize Context Management via State Extraction: The system should employ the
security-critical state extraction
algorithm, which suppresses routine states rooted exclusively in allowlisted objects to reduce context size, thereby improving bothscanning effectiveness and efficiency.
-
textbf Enhance Semantic Analysis Robustness with Analyzer Selection: The system can leverage different semantic analyzers (like DITTO-Gemini) to achieve superior classification; for instance, DITTO-Gemini
correctly classifies all PTMs in our evaluation and achieves an F1 score of 1.000,
even when other variants like DITTO-GPT show lower performance.
Abstract
Pre-trained models (PTMs) are widely distributed as serialized binaries, but their reuse often exposes software supply chains to deserialization attacks. Despite the emergence of safer serialization formats, the unsafe Pickle format remains prevalent: our analysis of over 10,000 popular Hugging Face repositories reveals that 9.3% rely on Pickle. While many defense mechanisms have been proposed, state-of-the-art model scanners suffer from a coverage-precision gap, missing security-sensitive behaviors and generating excessive false alerts. In this paper, we introduce DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs. DITTO faithfully tracks Pickle virtual machine state transitions and performs context-aware semantic analysis to infer model intentions. We also present PickleBench, a benchmark of 959 benign and 92 malicious real-world models, including extension registry attacks previously missed by existing tools. Across multiple evaluations, DITTO achieves 100% scanning coverage, a 0% false-negative rate, and a 0.7% false-positive rate, yielding an F1 score of 0.966, significantly outperforming state-of-the-art scanners. By minimizing false alerts while preserving detection accuracy, DITTO generates actionable security reports with contextual evidence, enabling safe PTM reuse and strengthening software supply chain integrity.
Sources
- Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain
- Machine Learning Models Have a Supply Chain Problem
- A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models
- The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs