safetensors
safetensors 权重格式CommonA safe, fast-loading file format from Hugging Face for storing model weights.
safetensors is a tensor-storage format developed and open-sourced by Hugging Face. A file consists of a JSON header — recording each tensor's name, shape, data type, and byte offset — followed by contiguous raw data. It was designed to fix a security problem with PyTorch's usual .pt/.bin files, which are based on Python's pickle format and can execute arbitrary code when loaded; safetensors also supports memory-mapping and reading individual tensors on demand, making large models load faster. Most open weights on Hugging Face today, including many VLA model checkpoints, are released as .safetensors, and libraries such as transformers and LeRobot can read them directly.
ExampleA VLA model's download includes a model.safetensors file; calling safetensors.torch.load_file reads out the parameter dictionary directly, with no risk of the file hiding malicious code.
- Also called
- .safetensors
- Related
- Checkpoint · PyTorch · Hugging Face · Hugging Face Transformers · Open-weight Model
- Sources
- huggingface/safetensors (GitHub)
Safetensors 文档 (Chinese)