logo

Taming the Wild West of ML: Practical Model Signing with Sigstore

ID: bdf5ee8c-b87a-5704-80e6-307eda1bfb8c

STIX ID: report--bdf5ee8c-b87a-5704-80e6-307eda1bfb8c

Feed Name: Google Online Security Blog

Date Published: 2025-04-04

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

Google, in partnership with NVIDIA and HiddenLayer under the OpenSSF, announces the v1.0 release of a model signing library that uses Sigstore to enable cryptographic signing and verification of ML models at scale. The post highlights ML supply chain risks such as model tampering, backdoors, and serialization-based code execution, and positions signing and transparency logs as key defenses to ensure integrity and provenance across training, finetuning, and deployment. The library supports CLI and Python integration for large model artifacts, with future plans to extend signing to datasets and tamper-proof metadata, and invites community collaboration via OpenSSF and CoSAI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.