AI Supply Chain Compromise
AI supply chain compromise is when hackers sneak into a system by tampering with the specialized parts used to build an AI, such as the raw information it learns from or the physical chips it runs on, rather than just attacking the final program directly.
AI supply chain compromise refers to an adversary gaining initial access to a system by exploiting vulnerabilities in the AI development lifecycle. This involves injecting malicious elements into the AI supply chain, such as compromised hardware, tainted training data, or backdoored software components, which may require subsequent secondary access to fully execute the intended attack.
AI supply chain compromise is an initial access technique where adversaries subvert the integrity of the AI development pipeline. By compromising unique supply chain vectors—specifically hardware (AML.T0010.000), data and annotations (AML.T0010.002), the AI software stack (AML.T0010.001), or the model artifacts (AML.T0010.003)—attackers establish a foothold. In many operational contexts, this compromise serves as a prerequisite that necessitates secondary access or lateral movement to achieve full execution of the adversarial objective.