Case E8D215 · AI security · L3 Applied
AI Supply Chain Risk
Practise as: Explain it · Interview
Interview questionYour team wants to download open models from a public hub. What supply chain risks exist and what controls would you require?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Pickle-based formats (.bin/.pt) run code on load; prefer safetensors, or weights_only=True on PyTorch 2.6+ (CVE-2025-32434).
- Model hub risks: typosquatted or hijacked repos, malicious LoRA adapters, trust_remote_code=True running repo code.
- Pin models by commit hash, mirror to an internal registry, and scan with tools that detect unsafe pickle opcodes.
- Dependencies matter too: CUDA, inference servers and Python packages carry normal software supply chain risk.
- Track provenance with an ML-BOM (e.g. CycloneDX) listing model, dataset, license and version for each deployment.
If the interviewer pushes back
- How do you verify a model file has not been tampered with between the publisher and your production cluster?
- What risk remains even when a model is in safetensors format from a trusted publisher?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.