Lune

ISSTA2026Top-tier venue

TensorLock: Recovering Model Dependency for Model Supply Chain

Susheng Wu, Ziqian Chen, Chengyuan Li, Kaifeng Huang, Zekai Chen, Yijian Wu, Bihuan Chen, Yiheng Cao, Zhuotong Zhou, Yiheng Huang, Xin Peng

2026Year

Abstract

The public models on the model hosting platforms have undergone exponential growth, allowing developers to build upon existing models rather than training from scratch. These models are continuously reused, modified, and re-distributed similar to traditional software components, breeding a dense and rapidly evolving model supply chain. However, while enjoying the benefits of model reuse, developers also inherit supply chain risks ranging from legal liabilities to security threats. To mitigate these risks, a well-established model dependency graph can significantly benefit supply chain risk governance. Unfortunately, although model hosting platforms offer mechanisms for dependency disclosure, such declarations are optional and frequently missing. To address this challenge, we propose a novel model dependency recovering framework Tensorlock. It works in two phases; i.e., (1) model clustering, and (2) type-aware dependency identification within these clusters. In the first phase, Tensorlock performs connectivity-based clustering to accommodate the open-ended dependency topology, grouping models with dependency relations. In the second phase, Tensorlock employs a divide-and-conquer strategy, leveraging distinct type-specific fingerprints to first identify data-free dependencies (Quantization and Merging), and then resolve data-driven Fine-Tuning dependencies. Our evaluation demonstrates that Tensorlock substantially outperforms state-of-the-art approaches, achieving an ARI of 0.96 in clustering and a DF 1 of 0.82 in dependency identification, improving over the best baselines by at least 39% and 193%, respectively. Additionally, we apply Tensorlock to 289 supposedly isolated models and recover 189 previously missing model dependencies, with 42 model authors confirming our findings.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 1d644e8c-9ca7-43de-b120-c039b836ebca

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines