Over the past several years, with the rise of ChatGPT, there has been a paradigm shift in the way large language models (LLMs) have accelerated the growth of technology, captured public imagination, and propelled the promise of attaining artificial general intelligence (AGI). However, such advancements have also simultaneously brought with them techniques in which such models can be altered and exploited by malicious actors for harm. With both large organizations, from finance to healthcare, and nonprofits and government organizations adopting such technologies at an unprecedented rate, it becomes imperative for them to secure their LLM pipelines end-to-end. This study delves into how organizations can take control of the situation and secure their LLM pipelines. It requires them to focus on the entire LLM lifecycle from data acquisition and model training to deployment and post-production monitoring. The text covers methods for protecting the LLM pipelines through techniques rooted in zero trust principles and effective data governance to make them more robust against any sort of adversarial attacks. It also focuses on deploying strategies such as secure-by-design and model verification to ensure the integrity of the LLM supply chain. The text also covers ways in which organizations can protect their AI investments through implementing proper access controls and adopting secure MLOps practices. Audit and compliance oversight of LLM models have also been thoroughly analyzed. The document further discusses research on the resultant outcomes of such security breaches, and the future implications specifically from a societal impact perspective.
Paper
Full text
Securing the LLM Supply Chain: Analyzing Threats and Mitigation Strategies
Semantic Scholar · 2026
Abstract
Over the past several years, with the rise of ChatGPT, there has been a paradigm shift in the way large language models (LLMs) have accelerated the growth of technology, captured public imagination, and propelled the promise of attaining artificial general intelligence (AGI). However, such advancements have also simultaneously brought with them techniques in which such models can be altered and exploited by malicious actors for harm. With both large organizations, from finance to healthcare, and nonprofits and government organizations adopting such technologies at an unprecedented rate, it becomes imperative for them to secure their LLM pipelines end-to-end. This study delves into how organizations can take control of the situation and secure their LLM pipelines. It requires them to focus on the entire LLM lifecycle from data acquisition and model training to deployment and post-production monitoring. The text covers methods for protecting the LLM pipelines through techniques rooted in zero trust principles and effective data governance to make them more robust against any sort of adversarial attacks. It also focuses on deploying strategies such as secure-by-design and model verification to ensure the integrity of the LLM supply chain. The text also covers ways in which organizations can protect their AI investments through implementing proper access controls and adopting secure MLOps practices. Audit and compliance oversight of LLM models have also been thoroughly analyzed. The document further discusses research on the resultant outcomes of such security breaches, and the future implications specifically from a societal impact perspective.