AIBoMGen: Generating an AI Bill of Materials for Secure, Transparent, and Compliant Model Training

arXiv:2601.05703 · cs.SE, cs.AI, cs.CR · Submitted 2026-01-09 · Read on arXiv

cs.SE, cs.AI, cs.CR

Submitted: 2026-01-09

Updated: 2026-01-09

Comments: Accepted at ACM/IEEE CAIN 2026

Journal ref: Proc. IEEE/ACM 5th International Conference on AI Engineering - Software Engineering for AI (CAIN 2026), pp. 45-53

DOI: 10.1145/3793653.3793763

Code: https://github.com/idlab-discover/AIBoMGen

Project page: https://spdx.github.io/spdx-spec/v3.0.1/model/AI/AI

License: http://creativecommons.org/licenses/by/4.0/

The gist: The rapid adoption of complex AI systems has outpaced the development of tools to ensure their transparency, security, and regulatory compliance.

Terminology

Abstract

The rapid adoption of complex AI systems has outpaced the development of tools to ensure their transparency, security, and regulatory compliance. In this paper, the AI Bill of Materials (AIBOM), an extension of the Software Bill of Materials (SBOM), is introduced as a standardized, verifiable record of trained AI models and their environments. Our proof-of-concept platform, AIBoMGen, automates the generation of signed AIBOMs by capturing datasets, model metadata, and environment details during training. The training platform acts as a neutral, third-party observer and root of trust. It enforces verifiable AIBOM creation for every job. The system uses cryptographic hashing, digital signatures, and in-toto attestations to ensure integrity and protect against threats such as artifact tampering by dishonest model creators. Our evaluation demonstrates that AIBoMGen reliably detects unauthorized modifications to all artifacts and can generate AIBOMs with negligible performance overhead. These results highlight the potential of AIBoMGen as a foundational step toward building secure and transparent AI ecosystems, enabling compliance with regulatory frameworks like the EUs AI Act.

Related papers