Schedule icon
Webhook icon
Request icon
Script icon
If icon
SlackIncomingWebhook icon
Log icon

Hugging Face Model Safetensors Security and Serialization Guard

Verify Hugging Face model serialization security, ensure safetensors compliance, and alert Slack if pickle weights exist.

Categories
AIInfrastructure

Deploying open-weights AI models into enterprise environments requires strict supply chain security. Traditional PyTorch weights (.bin, .pt, .pkl) rely on Python pickle serialization, which is susceptible to arbitrary code execution attacks upon deserialization. The modern industry standard is safetensors, a fast and zero-copy safe serialization format.

This blueprint acts as an automated security and compliance gate for Hugging Face model repositories. It inspects repository file trees, verifies that model weights adhere to safe serialization standards, checks for essential architectural configs and model cards, and halts model promotion via Slack alerts if risky pickle files are detected.

How it works

  1. fetch_model_metadata queries the Hugging Face Hub API for repository tree metadata.
  2. audit_weights_security analyzes all siblings to distinguish safe formats (.safetensors, .gguf, .onnx) from vulnerable pickle formats (.bin, .pt, .pkl).
  3. evaluate_security_gate uses an If task to check whether any security violations occurred.
  4. If violations exist, alert_insecure_model dispatches an urgent Slack alert halting automated inference promotion.
  5. If all weights are verified, log_model_verified logs approved telemetry for downstream deployment pipelines.
  6. The errors block alerts Slack if API communication or authentication fails.
  7. Dual triggers provide scheduled weekday verification and webhook-driven on-demand audit capability.

Prerequisites

  • A Hugging Face User Access Token (read scope) if inspecting gated or private models.
  • A Slack Incoming Webhook URL.

Secrets

  • HF_TOKEN: Hugging Face User Access Token.
  • SLACK_WEBHOOK_URL: Slack Incoming Webhook URL for security alerts.

Quick start

  1. Add HF_TOKEN and SLACK_WEBHOOK_URL to your Kestra namespace secrets.
  2. Set model_id to your target model (e.g. mistralai/Mistral-7B-Instruct-v0.2 or google/gemma-2-2b).
  3. Execute the workflow manually to inspect the audit_report output.
  4. Connect the webhook trigger to your ML deployment pipeline to ensure every model update is vetted before loading into production GPUs.

How to extend

  • Trigger downstream model downloading and quantization workflows upon successful audit.
  • Integrate with container scanning tools to verify base model container layers.
  • Record verified model commit hashes into an internal Model Registry (MLflow or S3) to maintain an audit trail.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.