ml-security
Safeguard articles tagged "ml-security" — guides, analysis, and best practices for software supply chain and application security.
9 articles
The Notebook Nobody Reviewed Is Running on a Schedule
It pulls customer records, holds a password in cell four, installs packages at runtime, and has run nightly for eighteen months. The format hides both the state and the data, and nothing gated the moment it became infrastructure.
How data poisoning attacks corrupt LLM behavior during tr...
A single expired domain and $60 can poison a training set. Here's how data poisoning attacks corrupt LLM behavior — and how Safeguard verifies training data before it ships.
The Python pickle security model, explained
Python's own docs warn that unpickling can execute arbitrary code — yet pickle is still the default weight format behind millions of ML model downloads.
AI Data Poisoning Defense: Protecting Models from Tainted Data
You do not need to corrupt most of a training set to backdoor a model — recent research suggests a small, near-constant number of poisoned documents can be enough. Defense starts with treating data as a dependency.
PyTorch Lightning PyPI Compromise: A Software Supply Chain Attack Built to Drain ML Credentials
In April 2026, attackers pushed malicious versions of the lightning PyPI package and an npm intercom-client release, harvesting cloud, CI/CD, and GitHub credentials. Here is what happened and why ML tooling is now a prime supply chain target.
Adversarial Images: How They Fool ML Models
What adversarial images are, why a few invisible pixels can flip a model's prediction, and the defenses that reduce the risk in production.
AI-BOMs: Extending Bill-of-Materials Thinking to Machine ...
AI-BOMs extend SBOM discipline to machine learning models—tracking training data, weights, and lineage. Here's what they contain and why regulators now require them.
AI Data Quality: Why It Matters for Model Security
Poor AI data quality is not just an accuracy problem — it's an attack surface. Here's how data integrity, provenance, and validation shape the security of the models you ship.
AI Explainability: Why It Matters for Security and Trust
AI explainability is the ability to understand why a model produced a given output. In security, it is the difference between an alert you can act on and one you cannot.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.