Section 01
Introduction: Core Insights from Open-Source Large Model Supply Chain Risk Assessment
This article, based on a supply chain risk assessment of three open-source large language models on the HuggingFace platform, reveals key risk dimensions in AI model deployment, including access control, file format security, and publisher traceability. The rapid adoption of open-source large models has introduced new attack surfaces, and their supply chain security differs fundamentally from traditional software—providing critical references for CISOs and security decision-makers.