Taming the Wild West of ML: Practical Model Signing with Sigstore
… Most of these could be prevented by signing the model during training and verifying integrity before any usage, in every step: the signature would have to be verified when the model gets uploaded to a model hub, when the model gets selected to be deployed into an application embedded or via remote … …