This 2D companion strips the 3D lab down to a flat weight-array view, but runs the exact same defense. Every deployed model is just an array of numbers. A supply-chain tampering attack silently substitutes a few of those numbers โ a poisoned checkpoint, a compromised model registry, a trojaned artifact in the CI/CD pipeline โ hoping nobody notices before it reaches production.
The defense is a block-level rolling checksum, the same idea behind model signing (Sigstore/cosign for ML) and Merkle-tree integrity proofs. At deployment the network's weights are split into fixed-size blocks and each block is hashed:
h_0 = 0
h_i = (h_i-1 * 31 + q(w_i)) mod (2^31 - 1)
q(w) = round(w * 1000) + 100000 // quantize + shift, keeps the hash input non-negative
digest(block) = h_n // stored as the block's signature
On every verification sweep the digest is recomputed from the current weights and compared to the signed value. A single altered weight โ even a small one โ cascades through the polynomial hash and flips the digest, so any tamper anywhere in a block is caught. On a match the block's diamond marker turns green; on a mismatch it turns red, the block is quarantined and rolled back to its signed values, and the event is logged with its detection latency. (We numerically fuzz-tested this rolling hash โ 20,000 random single-weight tampers across block sizes 2โ24 โ and it caught every one; the "shift by 100,000" term also stays safely positive for the weight ranges this lab produces, so no changes to the hash itself were needed here.)
- Tamper attack rate โ how often the "attacker" mutates a random weight (simulating a compromised artifact).
- Checksum block size โ the granularity trade-off: small blocks localize tampering precisely but need more digests to store and verify; large blocks are cheap but a single corrupted weight taints the whole block until the next sweep.
- Verification interval โ how often digests are re-checked. Shorter intervals catch tampering faster (lower mean detect latency) at the cost of more compute โ the same trade-off real MLOps pipelines make between continuous attestation and periodic audits.
- Signing OFF โ turns off verification entirely. Tampered weights are never re-checked, so corruption accumulates invisibly and is counted as silent corruption instead of a detected event โ this is the blind spot an unsigned model supply chain leaves open.
Drag the diagram to pan and scroll to zoom โ useful once the block size shrinks and the shield markers get dense. Real-world relevance: this is the same principle behind SBOM-for-AI, model cards with cryptographic hashes, and MLOps pipelines that reject any artifact whose signature doesn't match before it's ever loaded into a serving container.