AI Supply Chain Security
AI supply chain security means verifying the provenance of third-party models, datasets, and framework dependencies before trusting them.
Overview
An AI system depends on more third-party artifacts than typical software: pretrained model weights, training datasets, and a fast-moving set of framework libraries — each a potential point where something untrusted enters the system.
Where It Fits
Third-Party Artifacts
Model weights, datasets, framework dependencies.
Provenance Verification
Trusted or Rejected
Key Points
- Model provenance
- Downloading a pretrained model from an unverified source carries the same category of risk as running unverified code.
- Dependency risk
- The AI framework ecosystem moves fast and pulls in many dependencies, expanding the surface for a compromised package.
- Dataset trust
- Training or fine-tuning on an unvetted external dataset can introduce quality issues or, in adversarial cases, deliberately poisoned examples.
Interview Question
What’s different about supply chain security for an AI system compared to a typical software supply chain?
A typical software supply chain worries mainly about code dependencies. An AI system adds two more artifact types with their own provenance questions — pretrained model weights and training datasets — either of which could be tampered with or poisoned in ways that are much harder to detect by inspection than a malicious code dependency.
Explain It in 30 Seconds
AI supply chain security extends typical dependency security to also cover pretrained model weights and training datasets — third-party artifacts that can’t be reviewed like code, but can still introduce risk if their provenance isn’t verified.