S0092RS3-T13-S0092-Z · Full risk code

Hijacking of the Update Channel

更新推送通道遭劫持

Deployment
Risk Description

When an organization configures automatic model updates to maintain performance; due to unmitigated control gaps, after the update channel is compromised, a malicious version is deployed automatically to all nodes overnight and is noticed only the following day due to anomalous behavior, by which time it has processed a large volume of production requests, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST AI 600-1Information Security
ISO/IEC 42001Annex A.6.2.5
ISO/IEC 5338部署

Risk Treatment & Implementation Guidance

Require signature verification for automatic updates, blocking unverified versions; Deploy in stages—canary then fleet—with automatic rollback on anomalies; Control and monitor the update channel, alerting on compromise