DEF CON 33 - Unveiling the  Perils of the TorchScript Engine in PyTorch - Jian Zhou, Lishuo Song @DEFCONConference
DEF CON 33 - Unveiling the  Perils of the TorchScript Engine in PyTorch - Jian Zhou, Lishuo Song  @DEFCONConference
Uploaded October 2025 | Updated September 2026, 3 weeks ago
PyTorch is a machine learning library based on the Torch library, used for applications such as computer vision and natural language processing. It is one of the most popular deep learning frameworks.

However, beneath its powerful capabilities lies a potential security risk. Initially, PyTorch used pickle to save models, but due to the insecurity of pickle deserialization, there was a risk of Remote Code Execution (RCE) when loading models. Subsequently, PyTorch introduced the weights_only parameter to enhance security. The official documentation states that weights_only=True is considered safe and recommends using it over weights_only=False.

For years, the security of weights_only=True remained unchallenged. Our research, however, uncovered unsettling truths. We discovered that torch.load with weights_only=True supports TorchScript, leading us to delve into TorchScript's inner workings. After a period of research, we discovered several vulnerabilities and ultimately achieved RCE. We promptly reported this finding to PyTorch, who acknowledged the vulnerability and assigned us CVE-2025-32434. This revelation overturns established understandings and has profound implications for numerous AI applications. We will provide an in-depth analysis of the impact of this vulnerability.

In this sharing, we will introduce how we gained inspiration and discovered this interesting vulnerability. Meanwhile, our findings once again confirm the statement, "The Safe Harbor you once thought was actually Hostile Waters."
DEF CON 33 - Unveiling the  Perils of the TorchScript Engine in PyTorch - Jian Zhou, Lishuo SongDEF CON 33 - DC101 Panel - Alethe Denis, Nikita Kronenberg , zziks, Nicole Schwartz, Nina AlliDEF CON 32 - Locksport Competitions: Compete in the Olympics of Locks  -Matt BurroughDEF CON 33 - Preventing One of The Largest Supply-Chain Attacks in History - Maksim ShudrakDEF CON 33 - Hacking Context for Auto Root Cause and Attack Flow Discovery - Ezz TahounDEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin  YuDEF CON 3 3 - Exploiting Vulns in EV Charging Comms - Jan Berens, Marcell Szakály, Sebastian KöhlerDEF CON 32 - Social Engineering Like you’re Picard - Jayson E  StreetDEF CON 32 - Encrypted newspaper ads in the 19th century - Elonka Dunin, Klaus SchmehDEF CON 32 - Physical OSINT - Lukas McCulloughDEF CON 33 - Building the first open source hackable Quantum Sensor - Mark Carney, Victoria  KumaranDEF CON 33 - Private, Private, Private   Access Everywhere - Meghan Jacquot
DEFCONConference |

DEF CON 33 - Unveiling the Perils of the TorchScript Engine in PyTorch - Ji'an Zhou, Lishuo Song

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER