Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain
Fuente:
arXiv
Saved in:
| Main Authors: | Huang, Kaifeng, Chen, Bihuan, Lu, You, Wu, Susheng, Wang, Dingji, Huang, Yiheng, Jiang, Haowen, Zhou, Zhuotong, Cao, Junming, Peng, Xin |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026)
by: Huang, Yiheng, et al.
Published: (2026)
TigAug: Data Augmentation for Testing Traffic Light Detection in Autonomous Driving Systems
by: Lu, You, et al.
Published: (2025)
by: Lu, You, et al.
Published: (2025)
VulWeaver: Weaving Broken Semantics for Grounded Vulnerability Detection
by: Cao, Yiheng, et al.
Published: (2026)
by: Cao, Yiheng, et al.
Published: (2026)
DynNPC: Finding More Violations Induced by ADS in Simulation Testing through Dynamic NPC Behavior Generation
by: Lu, You, et al.
Published: (2024)
by: Lu, You, et al.
Published: (2024)
Argus: Resilience-Oriented Safety Assurance Framework for End-to-End ADSs
by: Wang, Dingji, et al.
Published: (2025)
by: Wang, Dingji, et al.
Published: (2025)
AutoMerge: Search-Based Model Merging Framework for Effective Model Reuse
by: Lu, You, et al.
Published: (2026)
by: Lu, You, et al.
Published: (2026)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
Scalable and Precise Application-Centered Call Graph Construction for Python
by: Huang, Kaifeng, et al.
Published: (2023)
by: Huang, Kaifeng, et al.
Published: (2023)
RoadGen: Generating Road Scenarios for Autonomous Vehicle Testing
by: Yang, Fan, et al.
Published: (2024)
by: Yang, Fan, et al.
Published: (2024)
Bridging Generation and Training: A Systematic Review of Quality Issues in LLMs for Code
by: He, Kaifeng, et al.
Published: (2026)
by: He, Kaifeng, et al.
Published: (2026)
A Survey of Fuzzing Open-Source Operating Systems
by: Hu, Kun, et al.
Published: (2025)
by: Hu, Kun, et al.
Published: (2025)
Understanding the Supply Chain and Risks of Large Language Model Applications
by: Ma, Yujie, et al.
Published: (2025)
by: Ma, Yujie, et al.
Published: (2025)
Large Language Model Supply Chain: A Research Agenda
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
Understanding Large Language Model Supply Chain: Structure, Domain, and Vulnerabilities
by: Hu, Yanzhe, et al.
Published: (2025)
by: Hu, Yanzhe, et al.
Published: (2025)
LLMs Meet Library Evolution: Evaluating Deprecated API Usage in LLM-based Code Completion
by: Wang, Chong, et al.
Published: (2024)
by: Wang, Chong, et al.
Published: (2024)
Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future
by: Xia, Boming, et al.
Published: (2023)
by: Xia, Boming, et al.
Published: (2023)
A Preliminary Study on the Robustness of Code Generation by Large Language Models
by: Li, Zike, et al.
Published: (2025)
by: Li, Zike, et al.
Published: (2025)
Cascaded Vulnerability Attacks in Software Supply Chains
by: Baird, Laura, et al.
Published: (2026)
by: Baird, Laura, et al.
Published: (2026)
The Grand Software Supply Chain of AI Systems
by: Cesarano, Carmine, et al.
Published: (2026)
by: Cesarano, Carmine, et al.
Published: (2026)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
Financial Twin Chain, a Platform to Support Financial Sustainability in Supply Chains
by: Galante, Giuseppe, et al.
Published: (2025)
by: Galante, Giuseppe, et al.
Published: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
Exploiting LLM Agent Supply Chains via Payload-less Skills
by: Liu, Xinyu, et al.
Published: (2026)
by: Liu, Xinyu, et al.
Published: (2026)
EFACT: an External Function Auto-Completion Tool to Strengthen Static Binary Lifting
by: Zhang, Yilei, et al.
Published: (2024)
by: Zhang, Yilei, et al.
Published: (2024)
Towards Sustainable and Secure Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain
by: Reid, Brittany Anne, et al.
Published: (2025)
by: Reid, Brittany Anne, et al.
Published: (2025)
An LLM-based Quantitative Framework for Evaluating High-Stealthy Backdoor Risks in OSS Supply Chains
by: Yan, Zihe, et al.
Published: (2025)
by: Yan, Zihe, et al.
Published: (2025)
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Guided Tensor Lifting
by: Li, Yixuan, et al.
Published: (2025)
by: Li, Yixuan, et al.
Published: (2025)
Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications
by: Sheh, Raymond K., et al.
Published: (2025)
by: Sheh, Raymond K., et al.
Published: (2025)
The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
by: Dong, Liming, et al.
Published: (2025)
by: Dong, Liming, et al.
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Automated Functional Testing for Malleable Mobile Application Driven from User Intent
by: Wang, Yuying, et al.
Published: (2026)
by: Wang, Yuying, et al.
Published: (2026)
Automatic Smart Contract Comment Generation via Large Language Models and In-Context Learning
by: Zhao, Junjie, et al.
Published: (2023)
by: Zhao, Junjie, et al.
Published: (2023)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
by: Tamanna, Mahzabin, et al.
Published: (2024)
by: Tamanna, Mahzabin, et al.
Published: (2024)
Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines
by: Dhandapani, Sowmiya
Published: (2025)
by: Dhandapani, Sowmiya
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Similar Items
-
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026) -
TigAug: Data Augmentation for Testing Traffic Light Detection in Autonomous Driving Systems
by: Lu, You, et al.
Published: (2025) -
VulWeaver: Weaving Broken Semantics for Grounded Vulnerability Detection
by: Cao, Yiheng, et al.
Published: (2026) -
DynNPC: Finding More Violations Induced by ADS in Simulation Testing through Dynamic NPC Behavior Generation
by: Lu, You, et al.
Published: (2024) -
Argus: Resilience-Oriented Safety Assurance Framework for End-to-End ADSs
by: Wang, Dingji, et al.
Published: (2025)