paper-with-me

홈 › Papers

Securing the AI Supply Chain: What Can We Learn From Developer-Reported Security Issues and Solutions of AI Projects?

2025-12-29 · The Anh Nguyen, Triet Huynh Minh Le, M. Ali Babar arxiv

The rapid growth of Artificial Intelligence (AI) models and applications has led to an increasingly complex security landscape. Developers of AI projects must contend not only with traditional software supply chain issues but also with novel, AI-specific security threats. However, little is known about what security issues are commonly encountered and how they are resolved in practice. This gap hinders the development of effective security measures for each component of the AI supply chain. We bridge this gap by conducting an empirical investigation of developer-reported issues and solutions, based on discussions from Hugging Face and GitHub. To identify security-related discussions, we develop a pipeline that combines keyword matching with an optimal fine-tuned distilBERT classifier, which achieved the best performance in our extensive comparison of various deep learning and large language models. This pipeline produces a dataset of 312,868 security discussions, providing insights into the security reporting practices of AI applications and projects. We conduct a thematic analysis of 753 posts sampled from our dataset and uncover a fine-grained taxonomy of 32 security issues and 24 solutions across four themes: (1) System and Software, (2) External Tools and Ecosystem, (3) Model, and (4) Data. We reveal that many security issues arise from the complex dependencies and black-box nature of AI components. Notably, challenges related to Models and Data often lack concrete solutions. Our insights can offer evidence-based guidance for developers and researchers to address real-world security threats across the AI supply chain.

📄 PDF Abstract BibTeX arXiv:2512.23385

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Quantitative Analysis of Implementation Challenges of IoT-Based Digital Supply Chain (Supply Chain 0/4)

2022-06-17 · Hamed Nozari, Mohammad Ebrahim Sadeghi, Javid Ghahremani nahr, Seyyed Esmaeil Najafi

Over the past thirty years, logistics has undergone tremendous change from a purely operational performance that led to sales or production and focused on securing supply and delivery lines to customers, with the transfo…

What if? Causal Machine Learning in Supply Chain Risk Management

2024-08-24 · Mateusz Wyrembek, George Baryannis, Alexandra Brintrup

The penultimate goal for developing machine learning models in supply chain management is to make optimal interventions. However, most machine learning models identify correlations in data rather than inferring causation…

Decision MakingManagement

Advancing the cybersecurity of the healthcare system with self-optimising and self-adaptative artificial intelligence (part 2)

2022-08-30 · Petar Radanliev, David De Roure

This article advances the knowledge on teaching and training new artificial intelligence algorithms, for securing, preparing, and adapting the healthcare system to cope with future pandemics. The core objective is to dev…

A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models

2024-10-06 · Beatrice Casey, Joanna C. S. Santos, Mehdi Mirakhorli

The development of machine learning (ML) techniques has led to ample opportunities for developers to develop and deploy their own models. Hugging Face serves as an open source platform where developers can share and down…

Supply Chain Digital Twin Framework Design: An Approach of Supply Chain Operations Reference Model and System of Systems

2021-07-19 · Jie Zhang, Alexandra Brintrup, Anisoara Calinescu, Edward Kosasih 외

Digital twin technology has been regarded as a beneficial approach in supply chain development. Different from traditional digital twin (temporal dynamic), supply chain digital twin is a spatio-temporal dynamic system. T…