fickling
A Python pickling decompiler and static analyzer (by trailofbits)
safer_unpickle
By kir-gadjello
Our great sponsors
fickling | safer_unpickle | |
---|---|---|
7 | 1 | |
327 | 5 | |
22.3% | - | |
8.4 | 10.0 | |
2 days ago | over 1 year ago | |
Python | Python | |
GNU Lesser General Public License v3.0 only | MIT License |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
fickling
Posts with mentions or reviews of fickling.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-06-30.
- Fickling – A Python pickling decompiler and static analyzer
- ⚠️WARNING⚠️ never open a .ckpt file without knowing exactly what's inside (especially SDXL)
-
Facebook LLAMA is being openly distributed via torrents
You're right! You should probably use Trail of Bits Fickling tool to investigate. https://github.com/trailofbits/fickling
-
Safety of downloading random checkpoints
I tested the Anything V3 pruned from Hugging Face, and indeed nothing funny in its pickle. I used the Fickling library to decompile it. I do not use Windows so my interests in .ckpt security are largely related to Pickle exploits— which could extract malicious code from a data file and then do something with it, but the data files themselves are not executed. I will edit this comment with lines referencing that data file.
-
Draw Things, Stable Diffusion in your pocket, 100% offline and free
I've been using Diffusion Bee on my Mac, and it's just gained the ability to import models (which it converts), but it is unpickling to do so— but barely. It unpickles, figures out what sort of data is in every data file and then computes what it wants from them on its own. I would love it to not use unpickling at all, so my intention is if I can figure it out, to write a script to decode the pickle file (with Fickling or otherwise) and then just do the weight calculation/assignment.
- Novel AI models allegedly leaked.
-
Never a dill moment: Exploiting machine learning pickle files
Something you won't gather from skim-reading the headline is that this is that the author has also created a tool, Fickling: https://github.com/trailofbits/fickling - to aid in playing around with pickle files.
From the article: [Fickling] can help you reverse engineer, test, and even create malicious pickle files.
safer_unpickle
Posts with mentions or reviews of safer_unpickle.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-03-03.
-
Facebook LLAMA is being openly distributed via torrents
A few months ago I made a small library to sanitize pytorch checkpoints, here it is: https://github.com/kir-gadjello/safer_unpickle
The usage boils down to
What are some alternatives?
When comparing fickling and safer_unpickle you can also consider the following projects:
swift-diffusion
llama - Inference code for Llama models
diffusionbee-stable-diffusion-ui - Diffusion Bee
petals - 🌸 Run LLMs at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading
sd-webui-model-converter - model convert extension for stable-diffusion-webui. supports convert fp16/bf16 no-ema/ema-only safetensors
FlexGen - Running large language models on a single GPU for throughput-oriented scenarios.
llama-cpu - Fork of Facebooks LLaMa model to run on CPU