TensorLock: Recovering Model Dependency for Model Supply Chain
Susheng Wu, Ziqian Chen, Chengyuan Li, Kaifeng Huang, Zekai Chen, Yijian Wu, Bihuan Chen, Yiheng Cao, Zhuotong Zhou, Yiheng Huang, Xin Peng
Abstract
The public models on the model hosting platforms have undergone exponential growth, allowing developers to build upon existing models rather than training from scratch. These models are continuously reused, modified, and re-distributed similar to traditional software components, breeding a dense and rapidly evolving model supply chain. However, while enjoying the benefits of model reuse, developers also inherit supply chain risks ranging from legal liabilities to security threats. To mitigate these risks, a well-established model dependency graph can significantly benefit supply chain risk governance. Unfortunately, although model hosting platforms offer mechanisms for dependency disclosure, such declarations are optional and frequently missing. To address this challenge, we propose a novel model dependency recovering framework Tensorlock. It works in two phases; i.e., (1) model clustering, and (2) type-aware dependency identification within these clusters. In the first phase, Tensorlock performs connectivity-based clustering to accommodate the open-ended dependency topology, grouping models with dependency relations. In the second phase, Tensorlock employs a divide-and-conquer strategy, leveraging distinct type-specific fingerprints to first identify data-free dependencies (Quantization and Merging), and then resolve data-driven Fine-Tuning dependencies. Our evaluation demonstrates that Tensorlock substantially outperforms state-of-the-art approaches, achieving an ARI of 0.96 in clustering and a DF 1 of 0.82 in dependency identification, improving over the best baselines by at least 39% and 193%, respectively. Additionally, we apply Tensorlock to 289 supposedly isolated models and recover 189 previously missing model dependencies, with 42 model authors confirming our findings.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 1d644e8c-9ca7-43de-b120-c039b836ebcaRelated papers
- A First Look at Model Supply Chain: From the Risk PerspectiveZiqian Chen, Zekai Chen, Susheng Wu, Bihuan Chen et al.ICSE 2026 · 1 citation
- TensorGuard: Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family ClassificationZehao Wu, Yanjie Zhao, Haoyu WangASE 2025
- Differential Testing of Cross Deep Learning Framework APIs: Revealing Inconsistencies and VulnerabilitiesZizhuang Deng, Guozhu Meng, Kai Chen, Tong Liu et al.USENIX Security 2023
- Unsupervised Model Tree Heritage RecoveryEliahu Horwitz, Asaf Shul, Yedid HoshenICLR 2025
- An In-Depth Study on Deep Learning Model CloningBin Hu, Xiancong Pan, Dongjin Yu, Tianyi HuICML 2026
