S0054RS3-T13-S0054-Z · Full risk code

Opaque Model Provenance Chain

模型來源鏈不透明

Design & Development
Risk Description

When an organization obtains a model through an integrator, described as based on a well-known foundation model; due to unmitigated control gaps, in practice its behavior does not match expectations, and when traced, no party in the chain can provide a complete record of modifications, triggering external stakeholder impacts and causing the organization has no way to know what adjustments the model actually underwent.

Framework Mappings

OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST AI 600-1Value Chain and Component Integration
ISO/IEC 42001Annex A.10.3
ISO/IEC 5338設計與開發

Risk Treatment & Implementation Guidance

Require provenance records—base model, modification history, data sources—at every supply-chain link, rejecting suppliers who cannot provide them; Audit integrators to verify claims match deliverables; Compare delivered models against the claimed base with behavioral baseline testing