Open cardosec

Case E8D215 · AI security · L3 Applied

AI Supply Chain Risk

Practise as: Explain it · Interview

Interview questionYour team wants to download open models from a public hub. What supply chain risks exist and what controls would you require?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Pickle-based formats (.bin/.pt) run code on load; prefer safetensors, or weights_only=True on PyTorch 2.6+ (CVE-2025-32434).
  2. Model hub risks: typosquatted or hijacked repos, malicious LoRA adapters, trust_remote_code=True running repo code.
  3. Pin models by commit hash, mirror to an internal registry, and scan with tools that detect unsafe pickle opcodes.
  4. Dependencies matter too: CUDA, inference servers and Python packages carry normal software supply chain risk.
  5. Track provenance with an ML-BOM (e.g. CycloneDX) listing model, dataset, license and version for each deployment.

If the interviewer pushes back

  • How do you verify a model file has not been tampered with between the publisher and your production cluster?
  • What risk remains even when a model is in safetensors format from a trusted publisher?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.