Formal evaluation demonstrates reliable rollback planning across compromised model lineages, highlighting viable remediation despite incomplete supply chain graphs.
AI supply chain security has matured on the prevention side: model signing, provenance documentation, and static scanning all answer whether an artifact is what it claims to be at the moment of adoption. None answers the question that arises when that trust is later overturned -- given an artifact now known to be compromised, which deployed models descend from it, and what can be done about each one. We argue this is a graph reachability problem rather than a cryptographic one. Signed provenance can encode derivation relationships; what artifact authentication does not provide is the collection, indexing and querying of them, nor any account of what happens when the record is incomplete. We give a formal model of compromise propagation over a typed lineage DAG, prove that a blast radius computed over an incompletely recorded graph is a sound lower bound on true exposure, and add a recovery planner that classifies each affected artifact by whether rollback to a clean signed ancestor exists. A second proof shows that any rollback target it proposes lies outside the true blast radius, though the planner never sees that graph. Evaluating over independently regenerated lineages, the two measures of the planner's costly error diverge: the rate of falsely-unrecoverable verdicts grows superlinearly in the detection miss rate (exponent 1.30, CI [1.12, 1.51]) while the count grows sublinearly (0.68, CI [0.52, 0.88]), so claims about operational cost are claims about the count. Validating each proposed plan against true dependencies rather than comparing verdicts, the dangerous error -- a rebuild that reuses a compromised input -- is rare rather than absent: 9 unsafe verdicts against 18,160, from five artifact-in-lineage cases. Finally, an adversary who withholds attestations near the compromise rather than losing them at random halves recall at an identical budget (0.325 against 0.734).
No takes yet. Share an insight, caveat, or question.
Apoorve Bhargava (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: