Research

Watch · narrated walkthroughs

Model Supply-Chain Attacks: Trusting the Artifact

A model file is executable-adjacent code and a trust boundary most teams skip. From pickle deserialization to adapter tampering, the artifact itself is an attack surface. This threat lab maps the artifact threat model, deserialization and loader code execution, weight and adapter tampering, distribution and typosquatting on model hubs, and signing plus provenance for verification at load — each paired with a hardening. Grounded in the primary supply-chain security standards and literature.

Murali Chillakuru·5 episodes
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5