Search⌘ K
AI Features

Supply Chain and Provenance Risks in Models and Datasets

Explore the risks and trust boundaries associated with supply chain artifacts in ML systems. Learn to identify threats from malicious models, compromised distribution, and unsafe loading, and build threat models that incorporate provenance evidence to assess and defend ML pipelines.

A deployed LLM application often has a step that looks harmless because it reads like data plumbing.

Dependency map of an LLM application
Dependency map of an LLM application

The key detail is that the pipeline crosses a trust boundary at download and again at load(). Some artifact formats and loader ecosystems reconstruct rich objects from bytes, and that reconstruction can trigger evaluation of embedded instructions, import hooks, or other active behaviors. Provenance is the decision about whether that boundary crossing is acceptable for a given upstream source.

What counts as supply chain here

In this context, supply chain means the upstream sources your system depends on to ...