Safe model serialization: Support saving pytorch model via torch.export.save#19692
Merged
WeichenXu123 merged 17 commits intomlflow:masterfrom Jan 15, 2026
Merged
Safe model serialization: Support saving pytorch model via torch.export.save#19692WeichenXu123 merged 17 commits intomlflow:masterfrom
torch.export.save#19692WeichenXu123 merged 17 commits intomlflow:masterfrom
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR adds support for safe PyTorch model serialization using torch.export.save, which addresses security vulnerabilities associated with the CloudPickle format by tracing models as computation graphs rather than pickling Module instances.
Key Changes:
- Adds new
export_modelboolean parameter tomlflow.pytorch.log_model()andmlflow.pytorch.save_model()functions - Implements model export logic with dynamic shape inference support
- Updates model loading to handle both traditional pickle-based and exported (pt2) model formats
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 8 comments.
| File | Description |
|---|---|
mlflow/pytorch/__init__.py |
Implements core functionality for exporting models via torch.export.save, adds validation logic, and updates model loading to detect and handle exported models |
tests/pytorch/test_pytorch_model_export.py |
Adds comprehensive test coverage for exported model saving/loading, dynamic dimension handling, and device compatibility checks |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Contributor
|
Documentation preview for 46690f9 is available at: More info
|
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
BenWilson2
approved these changes
Jan 14, 2026
Member
BenWilson2
left a comment
There was a problem hiding this comment.
A few nits on error message text to make it a little more clear about why we don't support portability. Otherwise, LGTM for pt serde support!
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
harupy
pushed a commit
to harupy/mlflow
that referenced
this pull request
Jan 28, 2026
…ort.save` (mlflow#19692) Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
harupy
pushed a commit
to harupy/mlflow
that referenced
this pull request
Jan 28, 2026
…ort.save` (mlflow#19692) Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
harupy
pushed a commit
that referenced
this pull request
Jan 28, 2026
…ort.save` (#19692) Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
ridgupta26
pushed a commit
to ridgupta26/mlflow-ridz
that referenced
this pull request
Jan 29, 2026
…ort.save` (mlflow#19692) Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🛠 DevTools 🛠
Install mlflow from this PR
For Databricks, use the following command:
Related Issues/PRs
#xxxWhat changes are proposed in this pull request?
Support saving pytorch model via
torch.export.saveThis is a safe serialization format, it avoids pickling
Moduleinstance, instead, it traces the module as graph , and then serialize the graph and the state_dict (weights / buffers).A new param
export_modelfor pytorch flavorlog_model/save_modelis addedHow is this PR tested?
Does this PR require documentation update?
Release Notes
Is this a user-facing change?
Safe model serialization: Support saving pytorch model via
torch.export.saveWhat component(s), interfaces, languages, and integrations does this PR affect?
Components
area/tracking: Tracking Service, tracking client APIs, autologgingarea/models: MLmodel format, model serialization/deserialization, flavorsarea/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registryarea/scoring: MLflow Model server, model deployment tools, Spark UDFsarea/evaluation: MLflow model evaluation features, evaluation metrics, and evaluation workflowsarea/gateway: MLflow AI Gateway client APIs, server, and third-party integrationsarea/prompts: MLflow prompt engineering features, prompt templates, and prompt managementarea/tracing: MLflow Tracing features, tracing APIs, and LLM tracing functionalityarea/projects: MLproject format, project running backendsarea/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev serverarea/build: Build and test infrastructure for MLflowarea/docs: MLflow documentation pagesHow should the PR be classified in the release notes? Choose one:
rn/none- No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" sectionrn/breaking-change- The PR will be mentioned in the "Breaking Changes" sectionrn/feature- A new user-facing feature worth mentioning in the release notesrn/bug-fix- A user-facing bug fix worth mentioning in the release notesrn/documentation- A user-facing documentation change worth mentioning in the release notesShould this PR be included in the next patch release?
Yesshould be selected for bug fixes, documentation updates, and other small changes.Noshould be selected for new features and larger changes. If you're unsure about the release classification of this PR, leave this unchecked to let the maintainers decide.What is a minor/patch release?
Bug fixes, doc updates and new features usually go into minor releases.
Bug fixes and doc updates usually go into patch releases.