AI Supply Chain Security

An attacker can poison your AI supply chain by compromising dependencies, model checkpoints, or deployment pipelines. Supply chain attacks target the weakest link: trusted but unvetted sources.

See the workflow →

The Four Phases

An attack follows a repeatable, documented process.

  • Dependency scanning
  • Checkpoint verification
  • Pipeline hardening
  • Incident response

Core Concepts

The foundations of understanding these vulnerabilities and controls.

The Supply Chain Attack Surface

Three critical entry points exist in AI systems: package dependencies (npm, PyPI, GitHub), model checkpoints (pretrained weights, snapshots), and deployment pipelines (CI/CD, container registries). Each can be poisoned.

  • Dependency poisoning: malicious packages masquerading as legitimate
  • Model checkpoint tampering: weights substitution or backdoor insertion
  • Registry compromise: container images with embedded malware
  • Typosquatting: similar names to popular packages

Supply Chain Hardening Strategy

Hardening requires cryptographic verification at every step: signed releases, checksummed dependencies, attestations on model provenance, and locked versions. Trust nothing; verify everything.

  • Cryptographic signing of dependencies and models
  • SBOM (Software Bill of Materials) and model cards
  • Provenance attestation and reproducible builds
  • Isolation and sandboxing during import/deployment

The Implementation Workflow

Each phase is methodical and repeatable. No phase is skipped; each has clear objectives.

Audit supply chain inventory

Catalog all dependencies, models, and data sources. Identify origins and update frequencies.

Implement cryptographic verification

Require signed checksums, attestations, and certificates for all upstream sources.

Harden deployment pipeline

Lock versions, restrict registry access, scan for known vulnerabilities.

Monitor and respond

Track changes, detect anomalies, establish incident response for compromised sources.

Related Pages

Deep dives into related attack and defense topics.

Model Extraction & Privacy Attacks

Protecting model checkpoints from theft and tampering.

Data Poisoning and Backdoors

Training-time attacks that persist through supply chain.

AI Governance & EU AI Act

Regulatory requirements for model provenance and audit trails.

OWASP LLM Top 10

Supply chain security as a foundational control.