SafeTensor and PickleTensor, both models are exactly the same, but they yield slightly different results.