Skip to content

Supply Chain Attacks

Model supply chain, plugin, and dependency attacks

Resources
18

Newest first · 5 reviewed on this page

Search instead
paper2026Unreviewed

Trustworthy AI LLM Scalability Risk Index (LSRI): A Cybersecurity Framework Assessing Agentic-AI Security & Software Model Supply Chain Safety Boosting AI-Generated Malware Defense & Explainability Mitigating Emerging Risks of Generative AI

Kiarash Ahi, Vaibhav Agrawal, Saeed Valizadeh

As AI shifts from human-in-the-loop interfaces to autonomous multi-agent systems capable of real-time code execution and tool integration through protocols like the Model Context Protocol (MCP), traditional SAST, DAST, and legacy AI safety methods fail to detect modern…

paper2026Unreviewed

VEX-Bench: Benchmarking LLM Agents for Assessing Exploitability of Software Supply Chain Vulnerabilities

Jiahao Shi, Edward Tsien, Yifeng Di +10

The software supply chain has become an increasingly exposed attack surface because of its reliance on intricate yet fragile dependencies. Existing defenses such as GitHub Dependabot often raise many false alerts because their coarse-grained matching cannot determine whether a…

paper2025International Conferences on Computing AdvancementsUnreviewed

Agentic AI for Autonomous Defense in Software Supply Chain Security: Beyond Provenance to Vulnerability Mitigation

Toqeer Ali Syed, M. R. Belgaum, Salman Jan +2

Software supply chain attacks increasingly target trusted development and delivery processes, making conventional post-build integrity mechanisms insufficient. Existing frameworks like SLSA, SBOM, and in-toto mainly provide provenance and traceability but cannot actively…