ML Supply Chain Security
Untrusted weights and datasets, deserialisation risk, dependency and registry attacks, and signing artefacts.
5concepts
62flashcards
35minutes of reading
- 01 Securing the Training Pipeline Why the training environment is a high-value target with unusually broad access, the specific credential and isolation failures that recur, and the controls proportionate to what a compromise would yield.
- 02 Signing, Attestation and SBOMs for Models How software supply chain frameworks map onto model artefacts, what a model bill of materials should contain, and why the interesting claims are about the training process rather than the file.