Session

The AI Supply Chain Nobody Is Watching

We already know how dangerous a compromised software dependency can be. AI applications quietly introduce a much larger supply chain.

A modern LLM application may depend on open-source packages, pretrained models, model weights, datasets, embedding models, adapters, plugins, external APIs and container images. Any of those components can become a security or integrity problem long before the application reaches production.

This session maps the attack surface of a modern AI application from source code to model runtime. We will examine practical risks around untrusted models, dependency compromise, model provenance, poisoned datasets, vulnerable components and AI-specific supply chain failures.

Through a controlled demonstration, we will follow a seemingly harmless AI dependency from ingestion to execution and identify where traditional software supply chain controls stop being sufficient.

We will then build a practical AI supply chain security checklist covering provenance, dependency inventory, model integrity, SBOMs, verification, access controls and monitoring.

The goal is simple: if your application has a software bill of materials, what should you have when part of your application is a model, dataset or AI component?

Monica R

Software Development Engineer @ Autodesk - Speaks AI, Tech & Careers

Bengaluru, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top