A First Look at Model Supply Chain: From the Risk Perspective
Ziqian Chen, Zekai Chen, Susheng Wu, Bihuan Chen, Wenyan Song, Yiheng Huang, Zhuotong Zhou, Yiheng Cao, Xin Peng
摘要
The rapid proliferation of publicly available artificial intelligence models on platforms such Hugging Face has formed a complex model supply chain, where base models are continually transformed, e.g., by fine-tuning, quantization, and merging, into new derived models. Despite its critical importance for reuse, provenance, and risk management, this supply chain remains poorly characterized at scale.
We construct the first comprehensive model supply chain based on models on Hugging Face as of June 25, 2025, which consists of 1.82 million models as well as 0.54 million dependency relations. Then, we conduct the first systematic study to characterize the usage, evolution, quality, and risk of this model supply chain. Finally, we provide actionable implications for model maintainers, consumers, platform designers, and researchers to foster this new direction in the era of AI.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia 等USENIX Security 2024 · 被引用 308 次
- Model-Reuse Attacks on Deep Learning SystemsYujie Ji, Xinyang Zhang, Shouling Ji, Xiapu Luo 等CCS 2018 · 被引用 197 次
- An Empirical Study of Pre-Trained Model Reuse in the Hugging Face Deep Learning Model RegistryWenxin Jiang, Nicholas Synovic, Matt Hyatt, Taylor R. Schorlemmer 等ICSE 2023 · 被引用 62 次
- BadMerging: Backdoor Attacks Against Model MergingJinghuai Zhang, Jianfeng Chi, Zheng Li, Kunlin Cai 等CCS 2024 · 被引用 5 次
- PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-TuningZhen Sun, Tianshuo Cong, Yule Liu, Chenhao Lin 等S&P 2025
相关 Paper
- TensorLock: Recovering Model Dependency for Model Supply ChainSusheng Wu, Ziqian Chen, Chengyuan Li, Kaifeng Huang 等ISSTA 2026
- Securing the AI Supply Chain: What Can We Learn From Developer-Reported Security Issues and Solutions of AI Projects?The Anh Nguyen, Triet Huynh Minh Le, M. Ali BabarICSE 2026 · 被引用 1 次
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu 等CCS 2026 · 被引用 1 次
- Hugging Carbon: Quantifying the Training Carbon Emissions of AI Models at ScaleXinlei Wang, Ruibo Ming, Jing Qiu, Junhua Zhao 等ICML 2026
- Unsupervised Model Tree Heritage RecoveryEliahu Horwitz, Asaf Shul, Yedid HoshenICLR 2025
