Supply Chain Attack (AI)

An attack that targets vulnerabilities in the AI development supply chain, such as compromised pre-trained models, poisoned datasets or malicious third-party libraries.

In Plain Language

Attacking AI by compromising something it depends on. A pre-trained model downloaded from the internet, a third-party dataset or an open-source library. Poisoning the ingredients rather than the final dish.

Why This Matters

AI supply chain risks are often underestimated. Your governance framework should include due diligence on third-party models, datasets and libraries, as well as verification processes to ensure the integrity of AI components.