AI Supply Chain Security
An attacker can poison your AI supply chain by compromising dependencies, model checkpoints, or deployment pipelines. Supply chain attacks target the weakest link: trusted but unvetted sources.
See the workflow →The Four Phases
An attack follows a repeatable, documented process.
- Dependency scanning
- Checkpoint verification
- Pipeline hardening
- Incident response
Core Concepts
The foundations of understanding these vulnerabilities and controls.
The Supply Chain Attack Surface
Three critical entry points exist in AI systems: package dependencies (npm, PyPI, GitHub), model checkpoints (pretrained weights, snapshots), and deployment pipelines (CI/CD, container registries). Each can be poisoned.
- Dependency poisoning: malicious packages masquerading as legitimate
- Model checkpoint tampering: weights substitution or backdoor insertion
- Registry compromise: container images with embedded malware
- Typosquatting: similar names to popular packages
Supply Chain Hardening Strategy
Hardening requires cryptographic verification at every step: signed releases, checksummed dependencies, attestations on model provenance, and locked versions. Trust nothing; verify everything.
- Cryptographic signing of dependencies and models
- SBOM (Software Bill of Materials) and model cards
- Provenance attestation and reproducible builds
- Isolation and sandboxing during import/deployment
The Implementation Workflow
Each phase is methodical and repeatable. No phase is skipped; each has clear objectives.
Audit supply chain inventory
Catalog all dependencies, models, and data sources. Identify origins and update frequencies.
Implement cryptographic verification
Require signed checksums, attestations, and certificates for all upstream sources.
Harden deployment pipeline
Lock versions, restrict registry access, scan for known vulnerabilities.
Monitor and respond
Track changes, detect anomalies, establish incident response for compromised sources.
Related Pages
Deep dives into related attack and defense topics.
Model Extraction & Privacy Attacks
Protecting model checkpoints from theft and tampering.
Data Poisoning and Backdoors
Training-time attacks that persist through supply chain.
AI Governance & EU AI Act
Regulatory requirements for model provenance and audit trails.
OWASP LLM Top 10
Supply chain security as a foundational control.