DevConf.IN 2026

Securing Your ML Model Supply Chain with OpenSSF Model Signing and Sigstore
2026-02-14 , (Workshop) VYAS - G - Room#VY004

Machine learning models are shared and deployed at massive scale, yet most organizations have no way to verify whether a model is safe, authentic, or tampered with. This creates a growing risk surface. Model backdoors, malicious deserialization, and compromised model files are already appearing in the wild.
This hands-on workshop introduces participants to model supply chain security using the new OpenSSF Model Signing Standard together with Sigstore’s cryptographic signing and verification tools. We will show how to sign an ML model, verify its integrity before loading, and integrate these steps into a simple ML workflow.
The session is designed for beginners and intermediate-level practitioners. No deep cryptography background is required, just basic ML familiarity is sufficient. By the end, attendees will be able to apply signing and verification to their own models and understand how these techniques protect against real world supply chain attacks.


What level of experience should the audience have to best understand your session?: Intermediate - attendees should be familiar with the subject
See also: To participate in the hands-on workshop, please take a look at the github URL provided and install all the prerequisites mentioned in the README. Setup instructions and verification commands are available in the repository.

Cloud-Native Developer passionate about building scalable, secure, and developer-friendly platforms.

Software Engineer at Red Hat, an open-source contributor, and a DevOps believer.