AIBoMGen: Generating an AI Bill of Materials for Secure, Transparent, and Compliant Model Training
cs.SE, cs.AI, cs.CR
Submitted: 2026-01-09
Updated: 2026-01-09
Comments: Accepted at ACM/IEEE CAIN 2026
Journal ref: Proc. IEEE/ACM 5th International Conference on AI Engineering - Software Engineering for AI (CAIN 2026), pp. 45-53
Code: https://github.com/idlab-discover/AIBoMGen
Project page: https://spdx.github.io/spdx-spec/v3.0.1/model/AI/AI
License: http://creativecommons.org/licenses/by/4.0/
The gist: The rapid adoption of complex AI systems has outpaced the development of tools to ensure their transparency, security, and regulatory compliance.
Terminology
Abstract
The rapid adoption of complex AI systems has outpaced the development of tools to ensure their transparency, security, and regulatory compliance. In this paper, the AI Bill of Materials (AIBOM), an extension of the Software Bill of Materials (SBOM), is introduced as a standardized, verifiable record of trained AI models and their environments. Our proof-of-concept platform, AIBoMGen, automates the generation of signed AIBOMs by capturing datasets, model metadata, and environment details during training. The training platform acts as a neutral, third-party observer and root of trust. It enforces verifiable AIBOM creation for every job. The system uses cryptographic hashing, digital signatures, and in-toto attestations to ensure integrity and protect against threats such as artifact tampering by dishonest model creators. Our evaluation demonstrates that AIBoMGen reliably detects unauthorized modifications to all artifacts and can generate AIBOMs with negligible performance overhead. These results highlight the potential of AIBoMGen as a foundational step toward building secure and transparent AI ecosystems, enabling compliance with regulatory frameworks like the EUs AI Act.
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties