Skip to content

pose_estimation_pytorch torch.load warning #2725

@dlhagger

Description

@dlhagger

Is there an existing issue for this?

  • I have searched the existing issues

Bug description

When running analyze_videos on rc4, a future warning that seems reasonable to update is presenting:

FutureWarning: You are using torch.load with weights_only=False (the current default value), which uses the default pickle module implicitly. It is possible to construct malicious pickle data which will execute arbitrary code during unpickling (See https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models for more details). In a future release, the default value for weights_only will be flipped to True. This limits the functions that could be executed during unpickling. Arbitrary objects will no longer be allowed to be loaded via this mode unless they are explicitly allowlisted by the user via torch.serialization.add_safe_globals. We recommend you start setting weights_only=True for any use case where you don't have full control of the loaded file. Please open an issue on GitHub for any issues related to this experimental feature.
snapshot = torch.load(snapshot_path, map_location=device)

Is it possible to add the files to the allowlist by default or load with weights_only in the future? Many of us are on security managed compute by our institutes or corporations, so might be worth while to address before a public release?

Thanks!

David

Operating System

operating system

MacOS 14.6.1

DeepLabCut version

dlc version

pytorch rc4

DeepLabCut mode

single animal

Device type

gpu

Steps To Reproduce

No response

Relevant log output

No response

Anything else?

No response

Code of Conduct

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions