Definition · AI security
Verify AI artifacts
Verifying AI artifacts means checking the cryptographic checksum or signature of a model file, dataset or other AI artifact before it is used, to confirm the file was not modified by an attacker. MITRE ATLAS lists the control as mitigation AML.M0014 and maps it to AI supply chain compromise and unsafe AI artifacts.
Last reviewed
Key points
- Verification compares an artifact's hash, or a signature over its hashes, with the one fixed when it was published, and treats a mismatch as tampering.
- MITRE ATLAS names the control Verify AI Artifacts (AML.M0014) and maps it to AI supply chain compromise (AML.T0010) and unsafe AI artifacts (AML.T0011.000).
- A signature adds who signed. To verify one, the user tells the tool which signer to accept, such as a public key or the account used to sign.
- Verification proves a file is unchanged since signing, not that it is safe. A model altered before it was signed still verifies.
Verifying an AI artifact means checking, before it is used, that the file is exactly the one its publisher produced.
How it works
Verification compares the file in hand with a value fixed at publication. MITRE ATLAS states the control in one sentence: “Verify the cryptographic checksum of all AI artifacts to verify that the file was not modified by an attacker.” A checksum, or hash, is a short fingerprint computed from the file’s bytes. If the file changes, the fingerprint no longer matches.
A signature adds a name. The OpenSSF model-signing library hashes every file in a model, signs that list, and on verification checks the signature before recomputing the hashes to compare. To verify, the user names the signer to accept: a public key, a certificate, or, with Sigstore, the account and identity provider used to sign, such as a Google or GitHub login.
Why it matters
Loading a model file can run code. ATLAS says an unsafe artifact “may exploit deserialization or another software vulnerability to execute code on the host.” Deserialization is the step that rebuilds a saved model in memory. ATLAS maps verification to AI supply chain compromise, so unsafe artifacts “will not be introduced to the system”, and to unsafe AI artifacts, so they “will not be executed in the system.”
Verification proves that nothing changed, not that the file was safe to begin with. ATLAS’s note on the related Code Signing mitigation (AML.M0013) says a signature guarantees the model “has not been manipulated after signing took place.” An artifact altered before it was signed still verifies. Looking inside the file for unsafe calls is a different mitigation, Vulnerability Scanning (AML.M0016).
In practice
The OpenSSF AI/ML working group released version 1.0 of its model-signing library in April 2025. Its authors note that the team that trains a foundation model is generally not the team that deploys it, and that for open-source models on hubs such as Kaggle and Hugging Face “there is no indication that a model being uploaded there matches what was intended during training.” They recommend checking signatures “each time the model is used”: on upload to a hub, on deployment, and when one model feeds another.
Where definitions disagree
ATLAS words AML.M0014 two ways. Its description asks for a “cryptographic checksum”. Every note mapping it to a technique asks instead for “proper checking of signatures”. A checksum shows the file is unchanged; only a signature also shows who vouched for it. ATLAS keeps signature enforcement as a separate mitigation too, Code Signing (AML.M0013), which calls for “digital signature verification to prevent untrusted code from executing.”
Questions and answers
Does a signed model mean the model is safe?
No. A valid signature shows who signed the model and that it has not changed since. MITRE ATLAS's note on code signing says it guarantees the model "has not been manipulated after signing took place". A model altered before it was signed passes verification, so what the check is worth depends on whether the signer can be trusted.
Which MITRE ATLAS mitigation covers verifying model files?
AML.M0014, Verify AI Artifacts. ATLAS maps it to AI supply chain compromise (AML.T0010), unsafe AI artifacts (AML.T0011.000) and three related techniques. Code Signing (AML.M0013) is a separate mitigation that calls for "digital signature verification to prevent untrusted code from executing".
Sources
- MITRE ATLAS, AML.M0014 Verify AI Artifacts and its mitigates relationships (collection 2026.09)MITRE
- sigstore/model-transparency READMESigstore / OpenSSF AI/ML Working Group
- Launch of Model Signing v1.0: OpenSSF AI/ML Working Group Secures the Machine Learning Supply ChainOpenSSF, 4 Apr 2025