Research

Watch · narrated whiteboard episodesL3

Model Supply-Chain Attacks: Trusting the Artifact

A model file is executable-adjacent code and a trust boundary most teams skip. From pickle deserialization to adapter tampering, the artifact itself is an attack surface. This threat lab maps the artifact threat model, deserialization and loader code execution, weight and adapter tampering, distribution and typosquatting on model hubs, and signing plus provenance for verification at load — each paired with a hardening. Grounded in the primary supply-chain security standards and literature.

Murali Chillakuru·5 episodes
  1. 11 min Episode 1The Artifact Threat Model: What a Downloaded Checkpoint Can Do at Load TimeA moderator and an expert map out why loading a machine learning checkpoint is an active security event — the artifact author can embed behavior that executes at load time, turning a dependency relationship into an attack surface.
  2. 10 min Episode 2Deserialization and Loader Attacks: Pickle Code Execution and Why safetensors HelpsA moderator and an expert examine why the Python pickle format turns loading a model into running the author's program — and how the safetensors format was designed to eliminate that code path entirely.
  3. 16 min Episode 3Weight and Adapter Tampering: Malicious Merges and Detecting Behavioral DriftA moderator and a security expert examine the subtlest link in the model supply chain — attacks that live inside the weights and adapters themselves, where there's no malicious code to scan, only numbers that behave badly on a secret trigger.
  4. 17 min Episode 4Distribution and Typosquatting: Model-Hub Trust and Dependency ConfusionA moderator and a security expert examine how name confusion, typosquatting, and dependency confusion turn a trusted model reference into an attacker's artifact — and why verifying a file's contents means nothing if you fetched the wrong file to begin with.
  5. 17 min Episode 5Signing and Provenance: Model Signatures, SLSA Attestations, and Verification at LoadA moderator and a security expert close the series by showing how the entire model supply-chain threat model collapses to a single discipline done well — sign the artifact, attest how it was built, and verify both at the moment you load.