(C07) (INCYBER) Sécuriser la chaîne d’approvisionnement du Logiciel et de l'IA: L'approche de Google

(C07) (INCYBER) Sécuriser la chaîne d’approvisionnement du Logiciel et de l'IA: L'approche de Google

🎙 INCYBER 👥 7K 📅 April 8, 2026 ⏱ 46 min 👁 104 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

supply chainsoftware securityAI securitySLSASBOM

Summary

This presentation from the INCYBER Forum 2026, given by Google Cloud security experts, focuses on securing the software and AI supply chain. The speakers, Tiébo and Slim, share Google’s internal approach, starting with the software supply chain. They illustrate the risks at each stage of the development pipeline, citing attacks like XZ Utils, SolarWinds, and PHP compromise. They introduce Google’s hardware root of trust (Titan chip) and the SLSA framework for supply chain security. They also discuss tools like Sigstore, OSV, and GUAC, and emphasize the importance of SBOMs and binary authorization for scaling security. The second part addresses AI supply chain, highlighting similarities and differences, such as the need to secure data and models. They mention a research paper on AI supply chain and discuss challenges like model dependencies and fine-tuning. The talk concludes with a Q&A session.

139 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides valuable insights into Google’s internal practices for securing the software supply chain, including concrete examples of attacks and mitigation strategies. The argumentation is solid, based on real-world incidents and Google’s own engineering experience. The speakers effectively explain complex concepts like SLSA and binary authorization, making them accessible to a technical audience. The discussion of AI supply chain is forward-looking and highlights emerging challenges. However, the talk is primarily an expert opinion, and while it references frameworks and tools, it does not provide detailed evidence or comparative analysis.

99 words

Title / Content Match

The title accurately reflects the content: the presentation covers securing the software and AI supply chain from Google's perspective.

Quality & Reliability

8/10

The presentation is given by Google Cloud security experts, providing an internal perspective on supply chain security. It references well-known attacks and frameworks (SLSA, SBOM) and mentions a research paper on AI supply chain. The content is technical and practical, but it is primarily an expert opinion without detailed citations or verifiable data.

Key Moments

Cited Sources

Concurring Sources

  • SLSA Framework — The presentation discusses SLSA, and this is the official framework website.
  • CISA SBOM — The presentation emphasizes SBOMs, and CISA provides authoritative guidance.

Contribution & Novelties

The presentation offers a unique insider perspective on Google’s approach to securing the software and AI supply chain, emphasizing practical implementation at scale. It highlights the importance of hardware root of trust, SLSA, and binary authorization, and extends these concepts to AI models. The talk also mentions a research paper on AI supply chain, which is a novel contribution.

Pour aller plus loin :

  • SLSA Framework — Official website for the Supply-chain Levels for Software Artifacts framework.
  • SBOM (Software Bill of Materials) — CISA’s page on SBOMs, explaining their importance and implementation.
  • Sigstore — Project for signing and verifying software artifacts.
  • GUAC — Tool for understanding software dependencies and security posture.
  • OSV-Scanner — Vulnerability scanner for open source dependencies.

119 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level. This indicates a well-balanced presentation that is both informative and credible, though it may not delve into the most advanced technical details.

Reliability 8/10

💬 No comments were provided for analysis.