<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Supply-Chain on Tom Ganz</title>
    <link>https://thecout.com/tags/supply-chain/</link>
    <description>Recent content in Supply-Chain on Tom Ganz</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 13 Sep 2026 12:49:48 +0000</lastBuildDate>
    <atom:link href="https://thecout.com/tags/supply-chain/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>What you actually download when you download a model</title>
      <link>https://thecout.com/blog/modelsafety/</link>
      <pubDate>Sun, 13 Sep 2026 10:00:00 +0100</pubDate>
      <guid>https://thecout.com/blog/modelsafety/</guid>
      <description>Everyone has run this line:&#xA;1 model = AutoModelForCausalLM.from_pretrained(&amp;#34;some-user/some-model&amp;#34;) It looks like a download. It is closer to running someone else&amp;rsquo;s installer. Some model formats execute code the moment you load them, some configs pull Python straight out of the repository, and the weights themselves can carry behaviour nobody mentioned in the model card.&#xA;It has also been shown that its EXTREMELY easy to poison a big-ass LLM. With a near constant number of samples regardless of the size of the model 1.</description>
    </item>
  </channel>
</rss>
