Without protection, a single pickle.load () or torch.load () call can be the entry point for a supply-chain attack. This workflow solves that problem without requiring changes to your existing model ...