BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.devconf.info//devconf-us-2026//talk//MMPEZG
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-devconf-us-2026-MMPEZG@pretalx.devconf.info
DTSTART;TZID=EST:20260925T092000
DTEND;TZID=EST:20260925T093500
DESCRIPTION:As organizations adopt Large Language Models in production syst
 ems\, a critical gap is emerging: model trust and supply chain security.\n
 \nUnlike container ecosystems\, where image signing\, scanning\, and prove
 nance are well-established practices\, LLM artifacts are often downloaded\
 , shared\, and deployed with minimal verification. This creates a blind sp
 ot in modern AI infrastructure where untrusted or tampered models can be i
 ntroduced into production environments.\n\nIn this talk\, we explore how c
 loud-native security practices can be extended to AI workloads using tools
  like Sigstore and Clair.\n\nWe will cover:\n\n- Signing and verifying LLM
  artifacts to ensure provenance and integrity\n- Scanning model containers
  for vulnerabilities and unsafe dependencies\n- Building a trusted supply 
 chain for AI artifacts\n- Integrating model verification into CI/CD and de
 ployment pipelines\n\nThrough practical examples and workflows\, this sess
 ion demonstrates how teams can apply existing container security principle
 s to AI systems without introducing entirely new infrastructure.\n\nThe go
 al is to make LLM deployment as trustworthy as container deployment alread
 y is today.
DTSTAMP:20260727T174714Z
LOCATION:Ladd Room (Capacity 170)
SUMMARY:Unsigned Models Are the New “curl | bash”: Securing the LLM Sup
 ply Chain - Shubhra Jayant Deshpande\, Harish
URL:https://pretalx.devconf.info/devconf-us-2026/talk/MMPEZG/
END:VEVENT
END:VCALENDAR
