TensorLock: Recovering Model Dependency for Model Supply Chain
Susheng Wu, Ziqian Chen, Chengyuan Li, Kaifeng Huang, Zekai Chen, Yijian Wu, Bihuan Chen, Yiheng Cao, Zhuotong Zhou, Yiheng Huang, Xin Peng
摘要
The public models on the model hosting platforms have undergone exponential growth, allowing developers to build upon existing models rather than training from scratch. These models are continuously reused, modified, and re-distributed similar to traditional software components, breeding a dense and rapidly evolving model supply chain. However, while enjoying the benefits of model reuse, developers also inherit supply chain risks ranging from legal liabilities to security threats. To mitigate these risks, a well-established model dependency graph can significantly benefit supply chain risk governance. Unfortunately, although model hosting platforms offer mechanisms for dependency disclosure, such declarations are optional and frequently missing. To address this challenge, we propose a novel model dependency recovering framework Tensorlock. It works in two phases; i.e., (1) model clustering, and (2) type-aware dependency identification within these clusters. In the first phase, Tensorlock performs connectivity-based clustering to accommodate the open-ended dependency topology, grouping models with dependency relations. In the second phase, Tensorlock employs a divide-and-conquer strategy, leveraging distinct type-specific fingerprints to first identify data-free dependencies (Quantization and Merging), and then resolve data-driven Fine-Tuning dependencies. Our evaluation demonstrates that Tensorlock substantially outperforms state-of-the-art approaches, achieving an ARI of 0.96 in clustering and a DF 1 of 0.82 in dependency identification, improving over the best baselines by at least 39% and 193%, respectively. Additionally, we apply Tensorlock to 289 supposedly isolated models and recover 189 previously missing model dependencies, with 42 model authors confirming our findings.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- A First Look at Model Supply Chain: From the Risk PerspectiveZiqian Chen, Zekai Chen, Susheng Wu, Bihuan Chen 等ICSE 2026 · 被引用 1 次
- TensorGuard: Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family ClassificationZehao Wu, Yanjie Zhao, Haoyu WangASE 2025
- Differential Testing of Cross Deep Learning Framework APIs: Revealing Inconsistencies and VulnerabilitiesZizhuang Deng, Guozhu Meng, Kai Chen, Tong Liu 等USENIX Security 2023
- Unsupervised Model Tree Heritage RecoveryEliahu Horwitz, Asaf Shul, Yedid HoshenICLR 2025
- An In-Depth Study on Deep Learning Model CloningBin Hu, Xiancong Pan, Dongjin Yu, Tianyi HuICML 2026
