A First Look at Model Supply Chain: From the Risk Perspective
Ziqian Chen, Zekai Chen, Susheng Wu, Bihuan Chen, Wenyan Song, Yiheng Huang, Zhuotong Zhou, Yiheng Cao, Xin Peng
Abstract
The rapid proliferation of publicly available artificial intelligence models on platforms such Hugging Face has formed a complex model supply chain, where base models are continually transformed, e.g., by fine-tuning, quantization, and merging, into new derived models. Despite its critical importance for reuse, provenance, and risk management, this supply chain remains poorly characterized at scale.
We construct the first comprehensive model supply chain based on models on Hugging Face as of June 25, 2025, which consists of 1.82 million models as well as 0.54 million dependency relations. Then, we conduct the first systematic study to characterize the usage, evolution, quality, and risk of this model supply chain. Finally, we provide actionable implications for model maintainers, consumers, platform designers, and researchers to foster this new direction in the era of AI.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3a17d11d-467f-485b-b476-dafc883f4f5cBuilds on5
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia et al.USENIX Security 2024 · 308 citations
- Model-Reuse Attacks on Deep Learning SystemsYujie Ji, Xinyang Zhang, Shouling Ji, Xiapu Luo et al.CCS 2018 · 197 citations
- An Empirical Study of Pre-Trained Model Reuse in the Hugging Face Deep Learning Model RegistryWenxin Jiang, Nicholas Synovic, Matt Hyatt, Taylor R. Schorlemmer et al.ICSE 2023 · 62 citations
- BadMerging: Backdoor Attacks Against Model MergingJinghuai Zhang, Jianfeng Chi, Zheng Li, Kunlin Cai et al.CCS 2024 · 5 citations
- PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-TuningZhen Sun, Tianshuo Cong, Yule Liu, Chenhao Lin et al.S&P 2025
Related papers
- TensorLock: Recovering Model Dependency for Model Supply ChainSusheng Wu, Ziqian Chen, Chengyuan Li, Kaifeng Huang et al.ISSTA 2026
- Securing the AI Supply Chain: What Can We Learn From Developer-Reported Security Issues and Solutions of AI Projects?The Anh Nguyen, Triet Huynh Minh Le, M. Ali BabarICSE 2026 · 1 citation
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu et al.CCS 2026 · 1 citation
- Hugging Carbon: Quantifying the Training Carbon Emissions of AI Models at ScaleXinlei Wang, Ruibo Ming, Jing Qiu, Junhua Zhao et al.ICML 2026
- Unsupervised Model Tree Heritage RecoveryEliahu Horwitz, Asaf Shul, Yedid HoshenICLR 2025
