
This artifact is associated with the paper "PickleBall: Secure Deserialization of Pickle-based Machine Learning Models" to appear at ACM CCS 2025. It contains: PickleBall source code and scripts: pickleball.tar.gz Dataset of malicious models: malicious.tar.gz Dataset of benign models: benign.tar.gz.partaa, benign.tar.gz.partab, ... benign.tar.gz.partba Abridged dataset of bengin models: benign-abridged.tar.gz Survey dataset: data.tar.gz Evaluators should refer to the Artifact Appendix distributed with the PickleBall paper, as well as the README files in the `pickleball.tar.gz` repository: `README.md`, `evaluation/README.md`, and `surveys/README.md`.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
