SE Radio 729: Garth Mollett on AI Supply Chain Security Red Hat Senior Principal Product Security Engineer Garth Mollett discussed AI supply chain security on Software Engineering Radio, detailing how it differs from conventional software supply chains and covering common attacks targeting model weights, inference, credentials, and resources. The episode also explored SPIFFE, SPIRE, attestation, and workload identity in the context of AI. Garth Mollet , Senior Principal Product Security Engineer and Technical Advisor for Product Security at Red Hat, joins host Robert Blumen for a discussion of AI supply chain security. They start with the basics of supply chain security, including the key components of the AI supply chain, and how it differs from the conventional software supply chain. Garth discusses whether the attacks target model weights or inference, and describes the most common attacks and what’s in it for the attacker, whether exfiltration, credentials, sabotage, or resources. The episode also considers SPIFFE, SPIRE, attestation, workload identity, and whether AI has the equivalent of “reproducible builds.” Brought to you by IEEE Computer Society https://computer.org and IEEE Software https://computer.org/software magazine. Show Notes Related Episodes - SE Radio 606: Charlie Jones on Third-Party Software Supply Chain Risks https://se-radio.net/2024/03/se-radio-606-charlie-jones-on-third-party-software-supply-chain-risks/ - SE Radio 575: Nir Valtman on Pipelineless Security https://se-radio.net/2023/08/se-radio-575-nir-valtman-on-pipelineless-security/ - SE Radio 541: Jordan Harband and Donald Fischer on Securing the Supply Chain https://se-radio.net/2022/12/episode-541-jordan-harband-and-donald-fischer-on-securing-the-supply-chain/ - SE Radio 535: Dan Lorenc on Supply Chain Attacks https://se-radio.net/2022/10/episode-535-dan-lorenc-on-supply-chain-attacks/ - SE Radio 630: Luis Rodriguez on the SSH Backdoor Attack https://se-radio.net/2024/08/se-radio-630-luis-rodriguez-on-the-ssh-backdoor-attack/ AI/ML Security - SE Radio 680: Luke Hinds on Privacy and Security of AI Coding Assistants https://se-radio.net/2025/08/se-radio-680-luke-hinds-on-privacy-and-security-of-ai-coding-assistants/ - SE Radio 395: Katharine Jarmul on Security and Privacy in Machine Learning https://se-radio.net/2020/01/episode-395-katharine-jarmul-on-security-and-privacy-in-machine-learning/ Container Security