---
title: AI/ML Supply Chain
slug: aiml-supply-chain
docTags: 
createdAt: 2024-11-20T16:53:48.239Z
---

## Overview

AI supply chain attacks occur when attackers modify or replace machine learning libraries, models, or associated data used by systems. Such vulnerabilities can lead to unauthorized system access or behavior manipulation.

To start working with the APIs, visit the [Supply Chain Attacks Guide](https://docs.boschaishield.com/api-docs/lesspostgreater-supply-chain-attacks).

***

## Key Features

### Report Generation

- Produces detailed reports classifying risks as **Low**, **Medium**, **High**, or **Critical**.

### Repository Integration

- Seamlessly integrates with GitHub, Huggingface, and AWS S3 for automated scanning of repositories and detecting vulnerabilities.

### Model Format Support

Supported frameworks and file formats include:

| Framework                     | File Format     | Deserialization Risks | Backdoor Risks | Runtime Risks |
| ----------------------------- | --------------- | --------------------- | -------------- | ------------- |
| TensorFlow                    | .pb             | ✅                     | ✅              |               |
| Tensorflow                    | .h5             | ✅                     | ✅              | ✅             |
| TensorFlow/PyTorch Checkpoint | .ckpt           | ✅                     |                |               |
| Keras                         | .keras          | ✅                     | ✅              |               |
| Keras                         | .h5             | ✅                     | ✅              |               |
| PyTorch                       | .pt, .pth, .bin | ✅                     |                |               |
| ONNX                          | .onnx           |                       |                | ✅             |
| Scikit-Learn                  | .pkl            | ✅                     |                |               |
| GGUF                          | .gguf           |                       |                | ✅             |
| SafeTensor                    | .safetensor     | ✅                     |                |               |
| Misc                          | .zip            | ✅                     |                |               |

### Additional File Formats

| Framework        | File Format | Detections                                               |
| ---------------- | ----------- | -------------------------------------------------------- |
| Jupyter Notebook | .ipynb      | Hardcoded secrets,Passwords PII, Tokens(API, Web, other) |
| Python           | .py         | Hardcoded secrets,Passwords PII, Tokens(API, Web, other) |

### AI Software Bill of Materials (SBOM)

| File Format                        | Detections                      |
| ---------------------------------- | ------------------------------- |
| Requirements File (Autodiscovered) | Libraries, Unsafe Library Flags |
| Jupyter Notebook (Autodiscovered)  | Libraries, Unsafe Library Flags |

***

## Risk Analysis

### 1. Deserialization Risks

Occurs when unverified data is used to rebuild objects. Attackers may exploit these to introduce malicious code, compromising system integrity.

- **Activation:** Serialization attacks exploit the process of saving and loading machine learning models, specifically targeting vulnerabilities in the serialization and deserialization mechanisms. These attacks often involve malicious payloads embedded within serialized model files.&#x20;
- **Purpose:&#x20;**&#x54;he primary goal of serialization attacks is to gain unauthorized access, execute arbitrary code, or manipulate the system in unintended ways. Attackers leverage the trust developers place in model files and frameworks, embedding harmful code that executes during deserialization to compromise environments, exfiltrate sensitive data, or alter system functionality.&#x20;
- **Detection:&#x20;**&#x53;erialization attack detection involves examining serialized files for suspicious code patterns and loading models in isolated environments, such as sandboxes, to monitor for unexpected behaviors or executions during deserialization.

### 2. Backdoor Risks

Hidden pathways allow attackers to manipulate model behavior through specific triggers. These covert exploits remain undetected during normal operations.

- **Activation:** Backdoor threats involve hidden pathways or triggers embedded in the model’s architecture that activate only when a specific input or condition is provided.
- **Purpose:** Backdoors are designed to manipulate model outputs for specific scenarios, enabling attackers to produce targeted malicious outputs without disrupting normal operations.
- **Detection:** Backdoor risks are harder to detect as they appear dormant in normal use but can be identified by analyzing model architecture for unusual pathways or using specialized tools like Netron for visual inspection and security scanners to detect presence of unusual code.

### 3. Runtime Risks

Activated during model inference or task execution, runtime risks involve malicious code execution, leading to unauthorized access or manipulation.

- **Activation:** These risks involve malicious code that executes during the model’s inference or runtime. The threat typically resides in the model files, and the malicious code is triggered as the model processes input data.
- **Purpose:** The aim is to compromise the system at runtime, such as gaining unauthorized access, stealing data, or altering the model’s behavior dynamically.
- **Detection:** Runtime risks often exploit code execution features in formats like TensorFlow’s SavedModel or Keras’ custom objects.&#x20;

***

## Benefits

1. **Real-Time Scanning**: Quickly identifies vulnerabilities in AI/ML models and notebooks.
2. **Comprehensive Framework Support**: Compatible with diverse model frameworks.
3. **Dynamic Risk Identification**: Adapts to evolving security threats.
4. **Thorough Assessments**: Provides a full spectrum of vulnerability analysis.
5. **Standards Compliance**: Aligns with OWASP, MITRE, and CWE standards.
6. **Scalability**: Automated workflows ensure efficient scaling.
7. **Seamless Integration**: Effortless compatibility with popular AI/ML platforms.
8. **Detailed Reports**: Helps prioritize vulnerabilities and allocate resources.
9. **Competitive Advantage**: Showcases commitment to security, appealing to stakeholders and clients.

***

## Parameters

| Parameter                          | Data Type | Description                                                                                                                            | Remarks                                                                                                                                                                                                                                                                             |
| ---------------------------------- | --------- | -------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `repo_type`                        | String    | The type of repository to scan                                                                                                         | (e.g.,  github, <br />gitlab, bitbucket, <br />huggingface, <br />s3\_bucket, <br />azure\_blob, <br />gcp\_storage<br />).                                                                                                                                                         |
| `repo_url`                         | String    | URL of the repository to be scanned.                                                                                                   | Formats accepted -<br />Hugginface - [https://huggingface.co/\<\<username>>/\<\<reponame>>](https://huggingface.co/\<\<username>>/\<\<reponame>>)<br />Github - [https://github.com/\<\<username>>/\<\<reponame.git>>](https://github.com/\<\<username>>/\<\<reponame.git>>)        |
| `branch_name`                      | String    | Name of the branch in the repository to be scanned                                                                                     | (e.g., main , dev).                                                                                                                                                                                                                                                                 |
| `depth`                            | Integer   | Number of recent commits to scan from the specified branch                                                                             | e.g., depth: 10<br /> scans the latest 10 commits.                                                                                                                                                                                                                                  |
| `username`<br />                   | String    | Username used for authenticating access to private repositories when required.                                                         |  (e.g., GitHub, GitLab, Bitbucket, huggingface)                                                                                                                                                                                                                                     |
| `pat`                              | String    | Personal Access Token used for authenticating access to private repositories                                                           |  (e.g., GitHub, GitLab, Bitbucket, huggingface)<br />The Personal Access Token must have sufficient permissions to read repository contents, metadata, and history—typically including <br />repo (for GitHub), <br />api  (for GitLab), or equivalent scopes for other platforms.  |
| `model_id`                         | String    | Required if repo\_type  is file; identifier returned by the model ID generation API, used to locate the uploaded file for scanning.    | Obtainable during [\<POST> Generate Model ID](docId\:ZQwTFEscleVi_vAP5AntH)                                                                                                                                                                                                         |
| `aws_access_key_id`                | String    | AWS access key ID used to authenticate and access S3 buckets when **repo\_type  is&#x20;**<br />**s3\_bucket**.                        | It pairs with the **aws\_secret\_access\_key&#x20;**&#x74;o ensure secure access and authorization.                                                                                                                                                                                 |
| `aws_secret_access_key`            | String    | AWS secret access key paired with aws\_access\_key\_id<br /> for authenticating access to S3 resources.                                | It works with the **aws\_access\_key\_id&#x20;**&#x74;o securely validate access permissions.                                                                                                                                                                                       |
| `region`                           | String    | The AWS region where the S3 bucket is hosted                                                                                           | e.g., us-east-1, <br />ap-south-1<br />                                                                                                                                                                                                                                             |
| `bucket_name`                      | String    | Required if repo\_type<br /> is  s3\_bucket  or <br />gcp\_storage ; specifies the name of the cloud storage bucket to be scanned      | if not provided, all accessible buckets will be auto-detected and scanned (requires list and read permissions)                                                                                                                                                                      |
| `azure_connection_string`<br />    | String    | Connection string used to authenticate and access Azure Blob Storage when <br />**repo\_type  is  azure\_blob**.                       | must have permissions to list containers and read blobs (e.g., via Storage Blob Data Reader  or Contributor<br /> roles).                                                                                                                                                           |
| `container_name`<br />             | String    | Name of the Azure Blob Storage container to be scanned; required when <br />**repo\_type  is azure\_blob**.<br />                      | if not provided, all accessible containers will be auto-detected and scanned (requires list and read permissions).                                                                                                                                                                  |
| `service_account_json_file`<br />  | File      | File containing the JSON key for a GCP service account; required for authentication when <br />**repo\_type  is gcp\_storage**.<br />  | must have permissions like <br />storage.buckets.list, storage.viewer, storage.objectViewer<br /> for proper scanning access.                                                                                                                                                       |

***

## Sample Artifact

- Refer to the [Vulnerability Report](https://aisdocs.blob.core.windows.net/reference/Reports/supply-chain/VulnerabilityReport.pdf) for detailed insights.

***

## Appendix

### Glossary

- **Deserialization Risks**: Vulnerabilities arising during object reconstruction from untrusted data or files.
- **Backdoor Risks**: Undetected pathways that allow behavior manipulation.
- **Runtime Risks**: Threats triggered during inference or file execution.

For further queries, contact [Support](#).
