惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
雷峰网
雷峰网
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Spread Privacy
Spread Privacy
H
Hacker News: Front Page
PCI Perspectives
PCI Perspectives
Webroot Blog
Webroot Blog
罗磊的独立博客
H
Heimdal Security Blog
TaoSecurity Blog
TaoSecurity Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Google Online Security Blog
Google Online Security Blog
Last Week in AI
Last Week in AI
美团技术团队
Help Net Security
Help Net Security
The Hacker News
The Hacker News
C
Cisco Blogs
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
The Register - Security
The Register - Security
IT之家
IT之家
WordPress大学
WordPress大学
Jina AI
Jina AI
Recent Commits to openclaw:main
Recent Commits to openclaw:main
H
Help Net Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Threat Research - Cisco Blogs
P
Proofpoint News Feed
NISL@THU
NISL@THU
爱范儿
爱范儿
The GitHub Blog
The GitHub Blog
Scott Helme
Scott Helme
V
Vulnerabilities – Threatpost
B
Blog
T
Tenable Blog
博客园 - 三生石上(FineUI控件)
T
The Exploit Database - CXSecurity.com
S
Security Affairs
小众软件
小众软件
Hacker News: Ask HN
Hacker News: Ask HN
Security Latest
Security Latest
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
W
WeLiveSecurity
A
Arctic Wolf
L
LINUX DO - 热门话题
Google DeepMind News
Google DeepMind News
M
MIT News - Artificial intelligence

IBM Research

All of AI benchmarking at your fingertips What are spin qubits? | IBM Quantum Computing Blog IBM to acquire HRL Laboratories IBM commits $50M in quantum access for US Genesis Mission It’s time for cryptography to get its own abstraction layer It’s time for cryptography to get its own abstraction layer This could be the largest synthetic code dataset yet How to measure the performance of a quantum computer | IBM Quantum Computing Blog Release News: Qiskit v2.5 is here! | IBM Quantum Computing Blog CoFrGeNets replace the ‘bones’ of transformer-based models How training environments can teach AI models to misbehave What’s new at IBM Quantum - Q2 2026 | IBM Quantum Computing Blog Modeling the chemistry of fusion reactor material | IBM Quantum Computing Blog Ponder This Challenge - July 2026 - Return of the Superheroes Apply to IBM Quantum Developer Conference 2026 | IBM Quantum Computing Blog Qiskit Paulice: postselected quantum error correction | IBM Quantum Computing Blog What is IBM’s nanostack chip architecture? IBM introduces the smallest computer chip in the world A new playbook for quantum optimization benchmarking Running AI on mixed hardware for speed and affordability Explore next-gen quantum algorithms with IBM Quantum Credits | IBM Quantum Computing Blog Allstate explores quantum computing for insurance portfolios | IBM Quantum Computing Blog Can LLMs discover quantum error correction codes? Prototype and validate fermionic circuits faster with ffsim | IBM Quantum Computing Blog Bringing the power of semantic AI to IBM Db2 The fast Fourier transform, how and why it works Building AI more like software The future of quantum takes center stage at NY Tech Week Qiskit Fall Fest 2026: Applications open | IBM Quantum Computing Blog IBM to invest $10 billion in quantum computing | IBM Quantum Computing Blog Renowned mathematician Subhash Khot joins IBM Research Ponder This Challenge - June 2026 - The Superhero Team Movies New Classroom Accounts expand quantum access for educators | IBM Quantum Computing Blog Qiskit Global Summer School 2026: Registration now open | IBM Quantum Computing Blog How researchers built a record-setting quantum circuit | IBM Quantum Computing Blog IBM charts a new research path with MIT How IBM is using quantum computing to understand the operating system of the universe How to use sample-based quantum diagonalization on IBM hardware Quantum-centric supercomputing simulates 12,635-atom protein | IBM Quantum Computing Blog A decade of quantum on the cloud | IBM Quantum Computing Blog Ponder This Challenge - May 2026 - The Powers of a Binary Matrix Where the frontiers of high-speed racing and computing meet Introducing the IBM Granite 4.1 family of models Building the future of computing, together Next-generation algorithms could move fusion from the lab to the grid Bringing quantum-centric supercomputing to Illinois What’s new at IBM Quantum - Q1 2026 | IBM Quantum Computing Blog Release News: Qiskit v2.4 is here! | IBM Quantum Computing Blog How IBM Quantum is enabling healthcare and biology research | IBM Quantum Computing Blog How an extra training step can unlock AI’s reasoning power IBM demonstrates extreme scale for content-aware storage with a 100-billion vector database Ponder This Challenge - April 2026 - The Unlabeled Clock IBM Research and ETH Zurich open a new era of innovation IBM’s newest time-series models cover a full range of enterprise prediction tasks Quantum computers take a step into real materials science Donating llm-d to the Cloud Native Computing Foundation Cleveland Clinic & IBM debut new quantum simulation workflow | IBM Quantum Computing Blog Turning turbulence into transcripts Like the information in a dream: IBM’s Charles H. Bennett receives ACM Turing award Doubling down on open-access quantum computing | IBM Quantum Computing Blog Unveiling the first reference architecture for quantum-centric supercomputing Realizing Feynman’s vision for the future of simulation | IBM Quantum Computing Blog IBM is working today to secure communication from tomorrow’s quantum risks Building PyTorch-native support for the IBM Spyre Accelerator Quantum simulates properties of the first-ever half-Möbius molecule, designed by IBM and researchers A look back at the International Year of Quantum | IBM Quantum Computing Blog TerraStackAI: Bringing Earth and space AI to Red Hat and the world Ponder This Challenge - March 2026 - Path game on a hole-riddled chessboard IBM demonstrates High NA EUV process capability on track for insertion below 2 nm nodes at SPIE 2026 Quantum Advantage Tracker: the race to advantage | IBM Quantum Computing Blog
Toward a transparent supply chain for AI
2026-03-26 · via IBM Research

Behind the smartphone in your pocket, and nearly every other manufactured good, is something called a BOM — a bill of materials that breaks down the product’s parts and explains how it was made. A BOM serves as a manufacturing blueprint that can help businesses manage inventory, reduce waste, and improve supply chain efficiency.

Software products got their own bill of materials in the 2010s, with an initial focus on making open-source licensing requirements easier to follow. As malicious attacks grew more common, the scope of software BOMs (or SBOMs) expanded to include provenance and security vulnerabilities. Now, as AI takes over some traditional software roles, the SBOM is evolving again to bring more consistency and accountability to the fragmented way that foundation models and their off-shoot applications are currently documented.

Standards are still evolving, but an AIBOM at a high level provides a standardized, auditable record of the datasets, weights, and methodologies underpinning a modern AI model. It’s like a machine-readable model card with enough fine print for users to inspect dataset licenses, earlier versions of the model, and evaluation results. In theory, the AIBOM is the record you check to make sure your model complies with ethical standards and major safety and security regulations.

To the extent that today’s models are documented at all, the metadata is often buried in PDFs, long blog posts, or in semi-structured model cards. Downstream users often have little idea of what data went into the models they’re adapting or how design choices during pre-training could play out in real life.

As a first step toward a full AIBOM, IBM just released model and dataset metadata for its Granite 4.0 models in machine-readable JSON. The structured format means that model cards and other AI documentation that model builders had to create manually can now be generated instantly. Enterprises can also use this format to compare models and check that those put into production meet internal safety and security policies, adding extra risk controls at runtime.

An audit trail for AI models

Like an SBOM, an AIBOM tracks individual software components. Its scope, however, extends to features unique to foundation models — things like model weights, downstream applications, and the provenance of training data, whether it was gathered from the web or generated automatically, in increasingly complex pipelines.

Other AI-specific components include the hardware the model trained on and what will be required for it to run, as well as details related to LLMs and LLM agents whose outputs can vary widely based on how a prompt is worded.

“Software is currently treated as a first-class citizen, while the data is an afterthought,” said Arthit Suriyawongkul, a researcher at Trinity College in Dublin focused on AI governance. “Modern AI flips that around. Data is just one of many primary artifacts that need to be thoroughly documented.”

Then, as now, security concerns and emerging regulations drove the tech industry to adopt SBOMs with their more rigorous reporting. The Linux Foundation in 2010 introduced its software package data exchange (SPDX) standard to make open-source licensing easier to communicate.

Later, a series of high-profile supply chain attacks led Linux to expand the focus of SPDX to exposing security risks. In 2017, the Open Worldwide Application Security Project (OWASP) introduced its own standard for generating software documentation, CycloneDX. The emphasis on security continued with President Biden’s executive order in 2021 to improve the nation’s cybersecurity by making software supply chain risks more visible.

Both Linux and OWASP are now extending their SBOM standards to AI, and IBM Research drew on this work in building out Granite’s new structured disclosures. As the industry works toward a common standard, IBM researchers have shared their best practices back with the community.

Broadly, an AIBOM covers six main areas — models, datasets, code, hardware, data processing, and governance. Once this information is machine-readable, it can be updated as models and processes evolve. Information can be instantly extracted for reporting, and security policies can be integrated into downstream applications to ensure the model behaves as its creators intended.

“If you look at any model card on Hugging Face, it's a README.md file which you can look at, but you can’t actually use programmatically without developing some parsing mechanism,” said Rakesh Jain, manager and chief architect of the data management platform behind IBM Granite. “Every model provider writes it differently.”

There’s more work to do before IBM Granite has a full bill of materials, but the team’s investments in governance and automated workflows should streamline the process, since most of the metadata needed for a full AIBOM already exists, said Jain.

“Once we have it all in a machine-readable format, retrieving information at a large scale from all our models will become very easy,” he said.

The untapped value of open

Open-source LLMs have improved dramatically in recent years, with Granite and other top open models now outperforming much larger frontier models in specific domains at a fraction of the cost. Despite the narrowing gap, closed models dominate the inferencing market, capturing about 96% of revenue, according to a new study by MIT and Georgia Tech researchers Frank Nagle and Daniel Yue.

This imbalance is economically significant, they found, estimating that if demand were to shift to open models, inferencing costs would drop by more than 70%, on average. In 2025, open models could have delivered $24.8 billion in savings to users.

“It’s more than the annual GDP of entire nations,” Nagle wrote in a blog post for the Linux Foundation, where he is also chief economist. “It represents a substantial consumer savings that could be captured by organizations, developers, and downstream users.”

It’s unclear whether brand recognition, performance benchmarks, or other factors are driving user preference for closed models, but standardized disclosures on their own are probably not enough to convince users to switch, said Nagle in an interview.

“Open models aren’t underutilized because of transparency — closed model users have no idea what’s in the models they’re using and which they’re paying more for,” he said. “But trust is a big thing, and maybe an AIBOM could help some people get over the hurdle.”

Open models covered by an AIBOM could be especially appealing to enterprises doing business in Europe, where AI-specific regulations are now in effect. Machine readable documentation leaves a clear audit trail for both enterprises and regulators, which could be helpful for both parties.

It makes data provenance and model lineage easier to track and prove. And if an AI system is attacked, the structured metadata can help enterprises isolate compromised datasets, dependencies, and model versions, which could lead to faster remediation.

The business case for transparency

The latest Stanford transparency rankings showed many tech companies moving away from transparency, for what could be a variety reasons.

Companies may be focused on performance above all else, while others may want to keep their data and techniques private to protect their market advantage. Companies that took shortcuts may not want to draw attention to themselves. If they gathered training data haphazardly and their models ingested copyrighted material, even unintentionally, it could open the door to lawsuits.

There’s no question that transparency brings extra scrutiny and can slow down the development process. But there’s ample evidence to suggest that transparency, and the ethical practices that go with it, can create value.

Responsible AI systems can build trust among customers and employees, lower risks by reducing customer complaints and compliance problems, and lead to higher-quality products. In a recent survey of 915 global executives, researchers at IBM and the University of Notre Dame’s Institute for Ethics and the Common Good found that organizations that invested the most in AI ethics reported 30% higher operating profit attributable to AI, on average, than those that spent the least.

“The ROI can be short-term and quantitative, like higher profits or reduced expenses, but it can also be a qualitative return like increasing the skills and capabilities within a firm,” said study co-author Francesca Rossi, an IBM Fellow who focuses on AI governance.

Check out IBM Granite’s new structured disclosures for the Granite language models here, including our Nano collection here.