Understanding the Supply Chain and Risks of Large Language Model Applications
Fuente:
arXiv
Saved in:
| Main Authors: | Ma, Yujie, Quan, Lili, Xie, Xiaofei, Hu, Qiang, Yu, Jiongchi, Zhang, Yao, Chen, Sen |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Large Language Model Supply Chain: Open Problems From the Security Perspective
by: Hu, Qiang, et al.
Published: (2024)
by: Hu, Qiang, et al.
Published: (2024)
Chimera: Harnessing Multi-Agent LLMs for Automatic Insider Threat Simulation
by: Yu, Jiongchi, et al.
Published: (2025)
by: Yu, Jiongchi, et al.
Published: (2025)
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026)
by: Ma, Yujie, et al.
Published: (2026)
CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality Shift
by: Yu, Jiongchi, et al.
Published: (2025)
by: Yu, Jiongchi, et al.
Published: (2025)
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
by: Weng, Shihao, et al.
Published: (2026)
by: Weng, Shihao, et al.
Published: (2026)
An Empirical Study on the Effectiveness of Large Language Models for Binary Code Understanding
by: Shang, Xiuwei, et al.
Published: (2025)
by: Shang, Xiuwei, et al.
Published: (2025)
Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World Exploits
by: Wang, Yuelin, et al.
Published: (2026)
by: Wang, Yuelin, et al.
Published: (2026)
Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications
by: Sheh, Raymond K., et al.
Published: (2025)
by: Sheh, Raymond K., et al.
Published: (2025)
Threat Modelling and Risk Analysis for Large Language Model (LLM)-Powered Applications
by: Tete, Stephen Burabari
Published: (2024)
by: Tete, Stephen Burabari
Published: (2024)
How Far Have We Gone in Binary Code Understanding Using Large Language Models
by: Shang, Xiuwei, et al.
Published: (2024)
by: Shang, Xiuwei, et al.
Published: (2024)
FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection
by: Song, Shiwen, et al.
Published: (2025)
by: Song, Shiwen, et al.
Published: (2025)
Exploiting LLM Agent Supply Chains via Payload-less Skills
by: Liu, Xinyu, et al.
Published: (2026)
by: Liu, Xinyu, et al.
Published: (2026)
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
by: Wang, Weizhe, et al.
Published: (2025)
by: Wang, Weizhe, et al.
Published: (2025)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
by: Liu, Raphina, et al.
Published: (2024)
by: Liu, Raphina, et al.
Published: (2024)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
by: Huang, Youwei, et al.
Published: (2025)
by: Huang, Youwei, et al.
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
by: Ruan, Bonan, et al.
Published: (2025)
by: Ruan, Bonan, et al.
Published: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
LLM4Fuzz: Guided Fuzzing of Smart Contracts with Large Language Models
by: Shou, Chaofan, et al.
Published: (2024)
by: Shou, Chaofan, et al.
Published: (2024)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
by: Cesarano, Carmine, et al.
Published: (2025)
by: Cesarano, Carmine, et al.
Published: (2025)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
by: Przymus, Piotr, et al.
Published: (2025)
by: Przymus, Piotr, et al.
Published: (2025)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications
by: Jedrzejewski, Felix Viktor, et al.
Published: (2025)
by: Jedrzejewski, Felix Viktor, et al.
Published: (2025)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
by: Seshadri, Bharathi, et al.
Published: (2024)
by: Seshadri, Bharathi, et al.
Published: (2024)
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
by: Nong, Yu, et al.
Published: (2024)
by: Nong, Yu, et al.
Published: (2024)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
by: He, Hao, et al.
Published: (2025)
by: He, Hao, et al.
Published: (2025)
On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
by: Jin, Monica, et al.
Published: (2025)
by: Jin, Monica, et al.
Published: (2025)
Similar Items
-
Large Language Model Supply Chain: Open Problems From the Security Perspective
by: Hu, Qiang, et al.
Published: (2024) -
Chimera: Harnessing Multi-Agent LLMs for Automatic Insider Threat Simulation
by: Yu, Jiongchi, et al.
Published: (2025) -
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026) -
CAShift: Benchmarking Log-Based Cloud Attack Detection under Normality Shift
by: Yu, Jiongchi, et al.
Published: (2025) -
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
by: Weng, Shihao, et al.
Published: (2026)