Safetensors Concepts
A secure file format for storing AI model weights. Unlike .ckpt files, safetensors cannot contain malicious code, making them the recommended format for sharing models.
Safetensors is the modern, secure way to store and share AI model files.
Why Safetensors?
Security
- Cannot contain executable code
- Safe to load from any source
- Sandboxed parsing
Performance
- Faster loading than .ckpt
- Memory-mapped loading
- Lazy loading possible
Compatibility
- Supported by all major UIs
- Works with models, LoRAs, VAEs
- Cross-platform
File Comparison
| Format | Security | Speed | Size |
|---|---|---|---|
| .safetensors | Safe | Fast | Same |
| .ckpt | Risky | Slower | Same |
| .pt | Risky | Medium | Same |
The .ckpt Risk
Traditional .ckpt files use Python pickle format:
- Can contain arbitrary Python code
- Code runs when file is loaded
- Malicious models exist
- Avoid from untrusted sources
Converting Models
Many tools convert .ckpt to .safetensors:
- Most UIs have built-in conversion
- CLI tools available
- Maintains model quality
Best Practices
- Always prefer .safetensors downloads
- Avoid .ckpt from unknown sources
- Download from reputable sites
- Check file types before loading
- Most new models are .safetensors only