[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125465-en":3,"doc-seo-125465-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125465,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","Machine Learning-Specific Vulnerability Management in Artificial Intelligence Supply Chains","Vulnerability management is established in regulated, high-risk sectors like finance and healthcare, but vulnerability management for artificial intelligence (AI) and machine learning (ML) remains comparatively new and insufficiently studied. This master’s thesis conducts a systematic literature review to clarify what ML-specific vulnerability management in AI supply chains entails and which state-of-the-art approaches exist. Findings indicate that the field is still early: the AI community focuses mainly on identification and mitigation, while monitoring, reporting, and prioritization are largely unexplored. Key gaps remain in asset identification, remediation, and vulnerability classification and scoring, which could improve through broader adoption of IT, software, and systems engineering best practices.","Machine Learning-Specific Vulnerability Management in Artificial Intelligence Supply Chains  \nSergej Weber  \nMaster’s thesis October 2025  \nMaster's Degree Programme in Information Technology, Cyber Security  \nWeber, Sergej  \nMachine Learning-Specific Vulnerability Management in Artificial Intelligence Supply Chains  \nJyväskylä: Jamk University of Applied Sciences, October 2025, 72 pages.  \nDegree Programme in Information Technology, Cyber Security. Masters’s thesis.  \nPermission for open access publication: Yes  \nLanguage of publication: English  \nAbstract  \nAlthough vulnerability management is a well-established field, particularly in regulated and high-risk industries such as finance and healthcare, managing vulnerabilities in artificial intelligence (AI)/machine learning (ML) is a relatively new and under-researched topic. This is despite substantial attention being given to securing AI/ML by the scientific and operational communities. A systematic literature review was conducted to answer the question on what ML-specific vulnerability management in AI supply chains encompasses, and what state-of-the-art approaches exist for managing such vulnerabilities. The results suggest that MLspecific vulnerability management is still in its infancy, with the AI community primarily focused on identifying and mitigating vulnerabilities. Other aspects, particularly monitoring, reporting, and prioritizing vulnerabilities, remain largely uncharted territory. In conclusion, there are a number of issues in terms of asset identification, remediation, and vulnerability classification and scoring. These issues could be more effectively addressed if the operational and scientific communities adopted IT, software, and systems engineering best practices to a greater extent.  \nKeywords/tags  \nAI/ML, Artificial Intelligence, Machine Learning, AI System, AI Supply Chain, AI Lifecycle, AI Security, ML Pipeline, Vulnerability Management  \nMiscellaneous  \nNone  \nContents  \n1 Introduction ................................................................................................................ 3  \n1.1 Research Objective and Questions ................................................................................... 3  \n1.2 Related Work..................................................................................................................... 4  \n1.3 Contributions..................................................................................................................... 9  \n1.4 Thesis Structure................................................................................................................. 9  \n2 Preliminaries ............................................................................................................... 9  \n2.1 Definition of AI and ML ................................................................................................... 10  \n2.2 ML-based AI Systems ...................................................................................................... 10  \n2.3 ML-based AI Supply Chains ............................................................................................. 13  \n2.4 AI Security........................................................................................................................ 15  \n2.5 Vulnerability Management in Traditional Software Engineering ................................... 25  \n3 Research Methodology .............................................................................................. 33  \n3.1 Systematic Literature Review.......................................................................................... 34  \n3.1.1 Paper Search Strategy............................................................................................ 34  \n3.1.2 Paper Selection ...................................................................................................... 36  \n3.1.3 Data Extraction and Data Analysis ..........................","cbCaiaZdvTuHNeBO","https://ap.wps.com/l/cbCaiaZdvTuHNeBO","pdf",2825855,1,72,"English","en",105,"# Introduction\n## Research Objective and Questions\n## Related Work\n## Contributions\n## Thesis Structure\n# Preliminaries\n## Definition of AI and ML\n## ML-based AI Systems\n## ML-based AI Supply Chains\n## AI Security\n## Vulnerability Management in Traditional Software Engineering\n# Research Methodology\n## Systematic Literature Review\n## Threats to validity\n# Results and Discussion\n## RQ1: How are AI/ML-related vulnerabilities discovered?\n## RQ2: How are AI/ML-related vulnerabilities analyzed and prioritized?\n## RQ3: How are AI/ML-related vulnerabilities remediated and mitigated?\n## RQ4: How are AI/ML-related vulnerabilities reported?\n## RQ5: How are AI/ML-related vulnerabilities monitored and detected?\n# Conclusion and Implications\n# Limitations and Future Research\n# References","[{\"question\":\"What does ML-specific vulnerability management in AI supply chains cover according to the thesis?\",\"answer\":\"It focuses on the end-to-end handling of ML-related vulnerabilities across the AI supply chain, including discovery, analysis and prioritization, remediation and mitigation, reporting, and monitoring and detection.\"},{\"question\":\"What state-of-the-art approaches does the thesis identify as most common?\",\"answer\":\"The results show the AI community concentrates mainly on identifying and mitigating vulnerabilities, while other lifecycle aspects such as monitoring, reporting, and prioritization are still underdeveloped.\"},{\"question\":\"What are the main unresolved challenges highlighted in the conclusion?\",\"answer\":\"The thesis points to issues in asset identification, remediation, and vulnerability classification and scoring, suggesting that broader adoption of IT, software, and systems engineering best practices could address them.\"}]","Machine Learning-Specific Vulnerability Management in Artificial Intelligence Supply Chains | PDF",1785899155,181,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"machine-learning-specific-vulnerability-management-in-artificial-intelligence-supply-chains","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-specific-vulnerability-management-in-artificial-intelligence-supply-chains/125465/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What does ML-specific vulnerability management in AI supply chains cover according to the thesis?","Question",{"text":75,"@type":76},"It focuses on the end-to-end handling of ML-related vulnerabilities across the AI supply chain, including discovery, analysis and prioritization, remediation and mitigation, reporting, and monitoring and detection.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What state-of-the-art approaches does the thesis identify as most common?",{"text":80,"@type":76},"The results show the AI community concentrates mainly on identifying and mitigating vulnerabilities, while other lifecycle aspects such as monitoring, reporting, and prioritization are still underdeveloped.",{"name":82,"@type":73,"acceptedAnswer":83},"What are the main unresolved challenges highlighted in the conclusion?",{"text":84,"@type":76},"The thesis points to issues in asset identification, remediation, and vulnerability classification and scoring, suggesting that broader adoption of IT, software, and systems engineering best practices could address them.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]