AIsbom is a specialized security and compliance scanning tool for machine learning models, designed to deeply detect hidden security risks and license issues in PyTorch and other model files. Unlike traditional SBOM tools, AIsbom utilizes deep binary inspection technology to analyze .pt, .pkl, and .safetensors files without loading model weights. The tool can detect malicious code execution risks (such as RCE attacks) and license violations hidden in model headers. Users can quickly scan project directories through a simple command-line interface to receive intuitive security risk ratings and compliance reports. AIsbom also provides a visual report viewer and supports generating SBOM data in CycloneDX v1.6 standard format for easy enterprise integration. As an open-source project, AIsbom includes testing features that allow users to verify scanning effectiveness. This tool is particularly suitable for AI developers and enterprises to secure AI model supply chains and prevent malicious models and license violations from entering production environments.
AIsbom: Security Tool for Detecting PyTorch Model Pickle Bombs
相关推荐
开发者利用 AI 编写安卓通知转发工具,支持多平台智能同步
终结蓝牙音箱自动断连!这款开源工具用“听不到的噪音”欺骗设备保持唤醒
谷歌重磅推出TorchTPU:支持PyTorch在TPU上原生运行,打破硬件生态壁垒
MacOS 菜单栏迎来新开源工具:goldPriceBar 助你实时监控黄金积存金价格
开源新作:基于 B 站音频源的第三方音乐 APP bili-music 发布
华为昇腾重金招募开发者:Torch-NPU适配挑战赛开启,共建AI算力软件生态
域名比价神器TLDhub上线:覆盖全球注册商,实时追踪.AI等后缀底价
开发者推出全能型 AI Prompt 生成工具:免费免登录,覆盖文生图与写作全场景