A model download may look like a collection of numbers. The loader decides how those bytes are interpreted. Hugging Face warns that loading a pickle file can execute arbitrary code. It also describes pickle as a common format for PyTorch model weights. A checkpoint can therefore carry instructions that run when it is opened.
Why pickle changes the risk
Pickle stores a sequence of instructions for rebuilding Python objects. During loading, those instructions can import modules and call functions. In Hugging Face’s example, malicious code runs and the expected data is still returned. Check the checkpoint format before calling a loader.
PyTorch’s torch.load documentation says the function uses an unpickler and warns against loading data from an untrusted source. Its weights_only=True option restricts the objects the unpickler may create. That restriction is useful when a PyTorch checkpoint is necessary. It does not establish whether you can trust the publisher.
What a scan can tell you
Hugging Face says its Hub scans pickled files and displays imports it finds. That gives you information to review before loading a file. The same guidance says the scanner is not foolproof. A clean looking result should not settle the decision by itself.
A signed commit can help establish who published a file. Hugging Face explicitly says the signature does not guarantee the file is safe. Format and provenance answer different questions: what the loader will do with the bytes, and whose bytes you received.
What to do
- Check the model repository’s file list before downloading or loading a checkpoint. If it offers
.safetensorsweights that your software supports, choose them. Safetensors documentation describes it as a format for storing tensors safely, as opposed to pickle. - If you need a pickle checkpoint, verify that you trust its publisher and review the Hub’s import scan. Treat a signature as evidence of origin, then make your own trust decision.
- When loading a suitable PyTorch checkpoint, pass
weights_only=Trueexplicitly, as shown in the PyTorch documentation. If loading fails because the file needs broader object support, do not disable that restriction for a file whose publisher you have not verified.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.