Hijacking of the Update Channel
更新推送通道遭劫持
Deployment
Risk Description
When an organization configures automatic model updates to maintain performance; due to unmitigated control gaps, after the update channel is compromised, a malicious version is deployed automatically to all nodes overnight and is noticed only the following day due to anomalous behavior, by which time it has processed a large volume of production requests, triggering compliance exposure and operational reputational costs.
Framework Mappings
OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST AI 600-1Information Security
ISO/IEC 42001Annex A.6.2.5
ISO/IEC 5338部署
Risk Treatment & Implementation Guidance
Require signature verification for automatic updates, blocking unverified versions; Deploy in stages—canary then fleet—with automatic rollback on anomalies; Control and monitor the update channel, alerting on compromise