• bitcoinBitcoin(BTC)$79,916.000.19%
  • ethereumEthereum(ETH)$2,495.600.65%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$750.64-2.69%
  • rippleXRP(XRP)$1.420.00%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$105.622.15%
  • tronTRON(TRX)$0.3358720.43%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.065.00%
  • zcashZcash(ZEC)$1,218.7220.50%
  • HyperliquidHyperliquid(HYPE)$87.762.56%
  • dogecoinDogecoin(DOGE)$0.090065-0.96%
  • RainRain(RAIN)$0.016746-1.59%
  • moneroMonero(XMR)$529.38-3.01%
  • USDSUSDS(USDS)$1.000.03%
  • chainlinkChainlink(LINK)$12.695.17%
  • whitebitWhiteBIT Coin(WBT)$73.600.25%
  • leo-tokenLEO Token(LEO)$9.290.49%
  • cardanoCardano(ADA)$0.2206580.30%
  • stellarStellar(XLM)$0.1847970.25%
  • bitcoin-cashBitcoin Cash(BCH)$257.630.51%
  • daiDai(DAI)$1.000.00%
  • uniswapUniswap(UNI)$7.130.10%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • CantonCanton(CC)$0.1102101.06%
  • USD1USD1(USD1)$1.000.02%
  • litecoinLitecoin(LTC)$54.220.67%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.43-0.20%
  • hedera-hashgraphHedera(HBAR)$0.0810610.23%
  • avalanche-2Avalanche(AVAX)$7.721.57%
  • suiSui(SUI)$0.80-0.06%
  • Global DollarGlobal Dollar(USDG)$1.00-0.01%
  • shiba-inuShiba Inu(SHIB)$0.000005-0.59%
  • nearNEAR Protocol(NEAR)$2.4110.54%
  • paypal-usdPayPal USD(PYUSD)$1.000.01%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • crypto-com-chainCronos(CRO)$0.0574611.93%
  • tether-goldTether Gold(XAUT)$4,415.97-0.22%
  • Circle USYCCircle USYC(USYC)$1.140.00%
  • BittensorBittensor(TAO)$269.7915.64%
  • MemeCoreMemeCore(M)$1.12-0.09%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • okbOKB(OKB)$113.130.28%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.40%
  • AsterAster(ASTER)$0.78-0.81%
  • aaveAave(AAVE)$133.22-1.12%
  • mantleMantle(MNT)$0.602.76%
  • pax-goldPAX Gold(PAXG)$4,420.54-0.27%
  • OndoOndo(ONDO)$0.3789542.47%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.056423-1.27%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Protecting ML models will secure supply chain, JFrog releases ML security features 

September 13, 2023
in AI & Technology
Reading Time: 6 mins read
A A
Protecting ML models will secure supply chain, JFrog releases ML security features 
ShareShareShareShareShare

Head over to our on-demand library to view sessions from VB Transform 2023. Register Here


The potential for supply chain attacks has grown as cybercriminals become increasingly adept at exploiting the dependencies within software services containing open-source libraries. But companies haven’t moved fast enough to take adequate counter measures.

YOU MAY ALSO LIKE

What Is Vibe Coding And Why Does It Get So Much Hate?

My Content Tracker Idea Became a Real App – Unite.AI

This was highlighted by Chris Krebs, the inaugural director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), in his keynote address at the BlackHat conference.”Companies shipping software products are shipping targets,” Krebs warned the audience, a sentiment echoed by the White House’s recent announcement of a national cybersecurity strategy that emphasizes cyber-resilience and holds software companies accountable for the security of their products.

Security gets traded for speed – even with new ML model development

DevOps teams are under pressure to deliver more apps that contain ML models in less time to support new sources of digital-first revenue and customer experiences. DevOps leaders say that security gate reviews get sacrificed to meet increasingly tight code delivery dates. VentureBeat has learned that a typical DevOps team in a $600 million enterprise has over 250 concurrent projects in progress, with over 70% dedicated to safeguarding and improving digital customer experiences.  

Security gets traded for speed because nearly every DevOps team has a backlog of new digital transformation apps supported by ML models that are behind schedule. Security testing apps are also disconnected from DevOps, and engineers aren’t trained to embed security into their code during development. Using open-source code saves time and keeps development within budget but introduces new risks. 97% of commercial code contains open-source code, and 81% contains at least one vulnerability. Additionally, 53% of the codebases analyzed had licensing conflicts, and 85% were at least four years out of date. 

Event

VB Transform 2023 On-Demand

Did you miss a session from VB Transform 2023? Register to access the on-demand library for all of our featured sessions.

 

Register Now

JFrog’s latest release goes all-in on protecting ML models during the development

JFrog, a leader in providing software supply chain security for DevOps, knows these and other challenges well. Today, the company launched a series of new products and enhancements at its 2023 swampUP Conference. The most noteworthy announcements are in ML Model Management, including scanning models for compliance, detecting malicious models, and managing model delivery alongside software releases. 

“Today, Data Scientists, ML Engineers, and DevOps teams do not have a common process for delivering software. This can often introduce friction between teams, difficulty in scale, and a lack of standards in management and compliance across a portfolio,” said Yoav Landman, Co-founder and CTO, JFrog. “Machine learning model artifacts are incomplete without Python and other packages they depend on and are often served using Docker containers. Our customers already trust JFrog as the gold standard for artifact management and DevSecOps processes. Data scientists and software engineers are the creators of modern AI capabilities, and already JFrog-native users. Therefore, we look at this release as the next logical step for us as we bring machine learning model management, as well as model security and compliance, into a unified software supply chain platform to help them deliver trusted software at scale in the era of AI.”  

The company also introduced a new security platform that provides end-to-end protection across the software development lifecycle (SDLC), from code to runtime. New features include SAST scanning, an OSS catalog as part of JFrog Curation, and ML model security. Additional new capabilities include release lifecycle management to track software bundles and enhanced DevOps features like immutable release bundles.

JFrog’s strategy is focused on unifying and streamlining the entire software development lifecycle within a single platform. As evidenced by their results at Hitachi Vantara, JFrog Artifactory acts as a “single source of truth” to manage software binaries and artifacts across the organization while providing consistent security scanning with JFrog Xray. By replicating key repositories across multiple sites, JFrog enabled Hitachi Vantara to accelerate multi-site pipelines and shift security left.

JFrog’s unified software supply chain platform manages and secures the software development lifecycle from code to runtime across repositories, dev tools, pipelines, and security controls. Source: JFrog, The Software Supply Chain Platform For DevOps & Security

Getting scaling right is core to securing every phase of ML model development 

What’s noteworthy about JFrog’s series of announcements today is how they’re building out security and code integrity from the initial commit of source code through building, testing, deployment, and runtime operations of ML models. 

“It can take significant time and effort to deploy ML models into production from start to finish. However, even once in production, users face challenges with model performance, model drift, and bias,” said Jim Mercer, Research Vice President, DevOps & DevSecOps, IDC. So, having a single system of record that can help automate the development, ongoing management, and security of ML Models alongside all other components that get packaged into applications offers a compelling alternative for optimizing the process.”

JFrog’s DevOps, engineering, and product management teams deserve credit for integrating AI/ML techniques to improve compliance, coding, developer productivity, and threat detection in their platform, strengthening those elements in the latest release. The following table compares JFrog’s progress in delivering solutions that scale across core software supply chain security attributes CISOs, CIOS, and boards look for in protecting their CI/CD pipelines and processes.  

JFrog’s platform spans the core supply chain security areas. Source: VentureBeat analysis of JFrog announcements at 2023 swampUP Conference

ML model security is a moving target that demands scalable platforms

ML model threats will continue to accelerate as attackers seek to weaponize AI at every chance. The many vulnerabilities in software supply chains directly impact teams’ productivity, building ML models for release into production and broad use today. 

JFrog’s approach of developing a platform that combines DevSecOps fundamentals to provide end-to-end vision and control of the ML models defines the future of secure software supply chains. Every CISO, Devops leader, and CEO is betting that ML model security must continue to evolve to stay current against threats, and platform architectures like JFrog’s re-defining how they secure ML models at scale is core to the future of secure software supply chains.

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.

Credit: Source link

ShareTweetSendSharePin

Related Posts

What Is Vibe Coding And Why Does It Get So Much Hate?
AI & Technology

What Is Vibe Coding And Why Does It Get So Much Hate?

September 6, 2026
My Content Tracker Idea Became a Real App – Unite.AI
AI & Technology

My Content Tracker Idea Became a Real App – Unite.AI

September 6, 2026
Is 256GB Enough For An iPhone? Here’s When You Should Go Bigger
AI & Technology

Is 256GB Enough For An iPhone? Here’s When You Should Go Bigger

September 6, 2026
How To Check Your PC’s Hard-Drive Health
AI & Technology

How To Check Your PC’s Hard-Drive Health

September 6, 2026
Next Post
MSFT and GOOG Miss, Shares Tank

MSFT and GOOG Miss, Shares Tank

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Fauci pleads fifth during Covid hearing

Fauci pleads fifth during Covid hearing

September 2, 2026
KFC founder Colonel Sanders’ planner auctioned for k

KFC founder Colonel Sanders’ planner auctioned for $30k

September 2, 2026
NBC Nightly News Full Episode – August 1

NBC Nightly News Full Episode – August 1

August 31, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!