As AI adoption accelerates, so does a largely underestimated attack surface — the AI supply chain. Unlike traditional software, an AI system's supply chain spans training datasets, pre-trained models, ML frameworks, third-party packages, and inference pipelines. Each layer is a potential entry point for adversaries.
This talk maps the full AI supply chain and examines real-world attack vectors: data poisoning, backdoored models distributed via public hubs, malicious ML packages, unsafe model deserialization, and prompt injection through compromised data sources. We'll look at documented incidents and emerging research that show these are not theoretical risks.
The highlight is a live demo of OpenSSF Model Signing (OMS) — an industry standard developed by the OpenSSF AI/ML Working Group, backed by Google, NVIDIA, and HiddenLayer. The demo will show how to sign a model at training time and verify its integrity before deployment — a critical step when the team training a model is rarely the same one deploying it.