SBTB 2023: Mihai Maruseac, Model transparency for AI/ML security
ai.bythebay.io Nov 2025, Oakland, full-stack AI conference AI models (especially LLMs) are now being released at a never seen before frequency. At the same time, supply chain attacks increase YoY by more than 700%. Coupling these two facts together reveals a shocking perspective: it is very possible for bad actors to infect unsuspecting hosts that want to benefit from the AI explosion. And this is not theoretical, as we have already seen examples of malicious LLMs being released. Looking at the traditional software development life cycle and associated supply chain risks we see that there are solutions (e.g., artifact signing, generating provenance, generating software bill of materials) that would enforce transparency, entailing a reduction in supply chain compromises. We can do the same for ML models, across different ML frameworks and model hubs, by drawing analogies between training AI models and building traditional software artifacts. This results in a model transparency suit of tools which represents one pilar of Google's Secure AI Framework (SAIF). More details available here: https://www.scale.bythebay.io/post/mihai-maruseac-model-transparency-for-ai-ml-security