Safetensors
Safetensors is a format for storing AI model weights without executing arbitrary code when a file is loaded.
Safetensors is a file format and open-source library introduced by Hugging Face in 2022 for storing tensors, the numerical arrays used as AI model weights. It is designed to load data without executing arbitrary code from the file.
Loading objects serialized with pickle can execute arbitrary code. Safetensors focuses on storing weight data, whereas ONNX can also represent a model's computational structure.
This entry is based on AIPOST articles and widely known facts. If something is wrong, please send us a correction request.
Articles covering this entry
Prefer safer model serialization formats such as Safetensors or ONNX instead of sharing pickle files.