# ML supply chain

Published articles for ML supply chain.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## New Chainguard Academy course: Securing the AI/ML Supply Chain

DevFeed: [New Chainguard Academy course: Securing the AI/ML Supply Chain](<https://devfeed.tech/articles/new-chainguard-academy-course-securing-the-ai-ml-supply-chain-13172.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-academy-course-securing-the-ai-ml-supply-chain>)

Published: 2024-07-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [developers](<https://devfeed.tech/tags/developers.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

Chainguard is launching a hands-on, self-paced Chainguard Academy course on securing the AI/ML supply chain. The course covers supply-chain components, cyberattacks, regulations, standards, risk-mitigation tools, vulnerability scanning, SBOMs, digital signatures, provenance, and Chainguard AI Images such as PyTorch.

### Source excerpt

Learn to secure your AI/ML supply chain with Chainguard's new course, designed to help you mitigate risks and build safer AI/ML systems.

## Securing the ML supply chain with new Chainguard AI Images

DevFeed: [Securing the ML supply chain with new Chainguard AI Images](<https://devfeed.tech/articles/securing-the-ml-supply-chain-with-new-chainguard-ai-images-13225.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-ml-supply-chain-with-new-chainguard-ai-images>)

Published: 2023-08-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [conda-image](<https://devfeed.tech/tags/conda-image.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [kubeflow-image](<https://devfeed.tech/tags/kubeflow-image.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [open-ai-image](<https://devfeed.tech/tags/open-ai-image.md>), [openai-image](<https://devfeed.tech/tags/openai-image.md>), [python-image](<https://devfeed.tech/tags/python-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>)

### AI overview

Chainguard announces a Chainguard Images AI bundle for securing the ML supply chain across the AI workload lifecycle. The collection includes development, workflow management, deployment, and vector database images, with software signatures, SBOMs, and CVE remediation.

### Source excerpt

Chainguard AI Images: Your pathway to a secure ML supply chain with hardened, efficient AI/ML lifecycle solutions.

## Good MLOps is good ML supply chain security

DevFeed: [Good MLOps is good ML supply chain security](<https://devfeed.tech/articles/good-mlops-is-good-ml-supply-chain-security-13070.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/good-mlops-is-good-ml-supply-chain-security>)

Published: 2023-07-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [MLOps](<https://devfeed.tech/topics/mlops.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [ml-ops](<https://devfeed.tech/tags/ml-ops.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [mlops](<https://devfeed.tech/tags/mlops.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tensorflow](<https://devfeed.tech/tags/tensorflow.md>)

### AI overview

The article explains how MLOps and ML supply chain security share a common infrastructure philosophy. It identifies training data, data delivery, software dependencies, model code, training environments, build steps, and production deployment as parts of the machine learning supply chain whose security and correctness must be addressed together.

### Source excerpt

Uncover the symbiosis of good MLOps and ML supply chain security with Chainguard's expert insights.

## Threat Modeling Thursday: Machine Learning

DevFeed: [Threat Modeling Thursday: Machine Learning](<https://devfeed.tech/articles/threat-modeling-thursday-machine-learning-37081.md>)

Original publisher: [Read original article](<https://shostack.org/blog/tmt-machine-learning/>)

Author: Adam

Published: 2020-01-02T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Security](<https://devfeed.tech/topics/security.md>), [Adversarial attacks](<https://devfeed.tech/topics/adversarial-attacks.md>), [Reverse Dependencies](<https://devfeed.tech/topics/reverse-dependencies.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

The article reviews Microsoft documents on threat modeling AI and machine learning systems, including their engineering challenges, categorized attacks, failure modes, and dependencies. It supports combining attacks and failures into a framework while arguing that additional ways to distinguish different security concerns are needed.

### Source excerpt

For my first blog post of 2020, I want to look at threat modeling machine learning systems.