DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits
summary
The gist
The gist The first sentence stands alone as a one-line summary of the paper's subject and finding: DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs, achieves 100% scanning
In short
DITTO is a new scanner designed to find security risks in models that use Pickle, a common but unsafe serialization format. It works by tracing how the model loads and then analyzing the context of critical operations to distinguish safe reconstruction from malicious behavior. DITTO achieved 100% scanning coverage and zero false negatives on a benchmark.
Key concepts
- Pickle-based PTMs
- These are pre-trained models that use the Pickle format for saving their structure and data. While convenient, Pickle is insecure because it can be exploited during loading to execute malicious code.
- Trace Generator
- This component safely records the steps of how a model loads without actually running dangerous operations. It emulates the virtual machine used by Pickle to capture all security-sensitive loading behaviors for later analysis.
- Intention Analyzer
- This part examines the recorded trace to determine if the model's actions are legitimate or malicious. It focuses on how security-critical data is used in context, rather than just looking at the data itself.
- PickleBench
- This is a custom testing dataset containing both safe and malicious Pickle models. It was created to rigorously test scanners like DITTO, allowing researchers to measure performance metrics like coverage and false positive rates.
Terminology used across episodes
This episode discusses
- DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits · Paper Radio
- Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain
- Machine Learning Models Have a Supply Chain Problem
- A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models
- The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
The paper
DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits · Read on arXiv
Qiaolin Qin, Wanpeng Li, Benoit Baudry, Lorenzo De Carli, Heng Li, Ettore Merlo
Polytechnique Montreal, Montreal, Canada · University of Liverpool, Liverpool, England
Pre-trained models (PTMs) are widely distributed as serialized binaries, but their reuse often exposes software supply chains to deserialization attacks. Despite the emergence of safer serialization formats, the unsafe Pickle format remains prevalent: our analysis of over 10,000 popular Hugging Face repositories reveals that 9.3% rely on Pickle. While many defense mechanisms have been proposed, state-of-the-art model scanners suffer from a coverage-precision gap, missing security-sensitive behaviors and generating excessive false alerts. In this paper, we introduce DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs. DITTO faithfully tracks Pickle virtual machine state transitions and performs context-aware semantic analysis to infer model intentions. We also present PickleBench, a benchmark of 959 benign and 92 malicious real-world models, including extension registry attacks previously missed by existing tools. Across multiple evaluations, DITTO achieves 100% scanning coverage, a 0% false-negative rate, and a 0.7% false-positive rate, yielding an F1 score of 0.966, significantly outperforming state-of-the-art scanners. By minimizing false alerts while preserving detection accuracy, DITTO generates actionable security reports with contextual evidence, enabling safe PTM reuse and strengthening software supply chain integrity.
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits".
Elias: The gist The first sentence stands alone as a one-line summary of the paper's subject and finding: DITTO, the first stack-based, context-aware scanner for Pickle-based PTMs,
Nadia: First, who's behind it and why it matters.
Paper summary: Elias: So, wrapping up this discussion on DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits, the core idea is using a stack-based, context-aware scanner to reliably catch security issues in Pickle models.
Nadia: That’s right. It uses a trace generator that safely emulates the PVM and an intention analyzer that performs semantic analysis on critical states to determine if model behavior is legitimate or malicious.
Priya: And it achieved one hundred percent scanning coverage and zero false negative rate, with a low average false positive rate of zero point seven percent on their PickleBench dataset.
Elias: The authors found that DITTO consistently achieved an F1 score of zero point nine six six on PickleBench, which they said is better than the state-of-the-art scanners' F1 score of zero point seven seven six.
Nadia: This paper gives us a practical solution for promoting actionable security audits for PTM reuse by providing a method that focuses on only the most relevant parts of the deserialization process.
Priya: It’s about moving past just recording every single step and focusing only on what actually matters for security, which is what makes this system useful in practice.
Conclusion: Nadia: So, DITTO is this new scanner they put out, right? It’s called "DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits."
Elias: Yeah, it’s trying to tackle that big problem with Pickle models. The authors are the ones who built it.
Priya: So, what’s the main point they’re making about this whole scanner thing? What did they actually prove?
Nadia: They showed that this DITTO tool can scan every single model in their test set without missing anything dangerous. It found zero false negatives.
Elias: And the false positives are kept really low, only about zero point seven percent on their specific benchmark called PickleBench. That’s a big number for a scanner like this.
Priya: So, for someone just listening to the show, what does that actually mean in terms of security? What's the practical takeaway?
Nadia: It means developers who use these models can actually trust if they are reusing them safely. It gives them a way to audit those complex model files without having to run every single operation themselves.
Elias: The paper’s focusing on how they built the "trace generator" and the "intention analyzer." They’re basically building a safe way to look inside that messy Pickle code without letting anything actually run.
Priya: It sounds like it shifts the focus from just checking if a file is okay, to understanding *how* it’s supposed to be behaving. That makes sense for privacy researchers too, because you need context for that kind of analysis.
Nadia: Exactly. It moves beyond simple scanning and tries to figure out the actual security intent behind what's happening in the code structure.
Elias: It’s about making sure that when you reuse these pre-trained models, you’re not accidentally opening a backdoor just because of how they were serialized.
Priya: So, it seems like this work is pointing toward a way to make model reuse safer for everyone working in the machine learning space. But what happens next with these kinds of tools?
More episodes
- 2610.10597-Certified Corruption Budgets: Anytime-Valid Leaderboard Claims under Adaptive Rigging
- 2610.10608-From Investigation Failures to Reliable SOC Agents: Understanding and Improving LLM-Based Alert Triage
- 2610.10612-PyCache Trap: The Inspection-Execution Gap in Agent Skill Scanners
- 2610.10644-SoK: Failure Modes in Common Criteria Product Evaluation - A Taxonomy and Design-for-Evaluability Guidance
- 2610.10617-MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking
- 2610.10620-When AI Finds Hidden Messages, Does It Report?
- 2610.10625-Safe at One Loop, Risky at Another: Aligning Safety Across Recurrent Depths in Looped Language Models
- 2610.10992-The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical Study across the Three FIPS 204 Parameter Sets
- 2610.10659-Applying Security by Design at the Point of Execution: How Governed Security Requirements Affect the Security of AI-Generated Code
- 2610.10742-BRANCH: Bypassing Multi-Scanner AI Guardrails