Uploaded May 2026 | Updated September 2026, 33 minutes ago
Alexandra Selldorff (Manifest Cyber, US), Ugur Koc (Manifest Cyber)
AI systems increasingly rely on open-source models and datasets, yet most vulnerability management (VM) programs still treat these artifacts as opaque. AI model cards help with documentation, but they rarely provide the structured, machine-readable, policy-evaluable metadata needed for risk controls, approval workflows, and governance. This session provides an introduction of AIBOMs (AI Bills of Materials): a standardized approach for describing models and datasets with provenance, licensing, dataset dependencies, research ties, technical specs, and revision history. We will detail the distinct nature of "AI vulnerabilities" compared to traditional software and hardware flaws. This includes an examination of data poisoning, integrity issues, risks related to misalignment and misuse, and license conflicts. A key operational challenge we will emphasize is the current lack of a centralized, NVD-equivalent registry for reporting AI artifacts.
We then show how organizations can use AIBOMs as the substrate for configurable policies (e.g., license allow/ban lists, dataset origin constraints, revision freshness, model-card completeness requirements, and risk markers) and evaluate those policies deterministically during model onboarding and promotion. Attendees will see a practical approval workflow that gates model usage in CI/CD and connects to PSIRT-style processes, plus an approach for offline discovery and caching of popular Hugging Face assets to support air-gapped environments and consistent decisions at scale.
Attendees leave with a blueprint to operationalize AIBOMs, integrate policy evaluators, and extend existing VM programs to AI artifacts using deterministic analysis and scalable caching
---
Lexi Selldorff is a Senior Engineering Manager at Manifest, leading work on SBOM vulnerability scanning. Previously, she was an Engineering Manager at Rula and a Forward Deployed Engineer at Palantir. She has built and operated software in highly regulated environments, including healthcare and government, and is passionate about delivering mission-critical systems quickly and securely. Lexi enjoys getting deep into data, and her work at Manifest focuses on the real-world challenges of vulnerability matching, package identification, and reducing noise in vulnerability management.
Dr. Ugur Koc is a Senior AI R&D Engineer at Manifest Cyber, where he leads the design and development of AI Risk Management solutions like AI-BOM generation and automated policy evaluation. With a PhD in Computer Science from University of Maryland, his research spans AI-augmented program analysis, software security, privacy, and AI governance. His work is published in premier venues including ASE, FSE, TSE, and ICST. Prior to Manifest, Ugur led AI platform development at Privado, building LLM-powered privacy scanning services, and spent three years at Amazon developing automated privacy auditors for ML models leveraging adversarial ML techniques like membership inference and input reconstruction attacks. He holds the AI Governance Professional (AIGP) certification from IAPP and AWS Solutions Architect certification. Ugur bridges cutting-edge research with practical vulnerability management, bringing deep expertise in operationalizing AI security controls, policy automation, and supply chain risk mitigation for AI/ML systems.
Alexandra Selldorff (Manifest Cyber, US), Ugur Koc (Manifest Cyber)
AI systems increasingly rely on open-source models and datasets, yet most vulnerability management (VM) programs still treat these artifacts as opaque. AI model cards help with documentation, but they rarely provide the structured, machine-readable, policy-evaluable metadata needed for risk controls, approval workflows, and governance. This session provides an introduction of AIBOMs (AI Bills of Materials): a standardized approach for describing models and datasets with provenance, licensing, dataset dependencies, research ties, technical specs, and revision history. We will detail the distinct nature of "AI vulnerabilities" compared to traditional software and hardware flaws. This includes an examination of data poisoning, integrity issues, risks related to misalignment and misuse, and license conflicts. A key operational challenge we will emphasize is the current lack of a centralized, NVD-equivalent registry for reporting AI artifacts.
We then show how organizations can use AIBOMs as the substrate for configurable policies (e.g., license allow/ban lists, dataset origin constraints, revision freshness, model-card completeness requirements, and risk markers) and evaluate those policies deterministically during model onboarding and promotion. Attendees will see a practical approval workflow that gates model usage in CI/CD and connects to PSIRT-style processes, plus an approach for offline discovery and caching of popular Hugging Face assets to support air-gapped environments and consistent decisions at scale.
Attendees leave with a blueprint to operationalize AIBOMs, integrate policy evaluators, and extend existing VM programs to AI artifacts using deterministic analysis and scalable caching
---
Lexi Selldorff is a Senior Engineering Manager at Manifest, leading work on SBOM vulnerability scanning. Previously, she was an Engineering Manager at Rula and a Forward Deployed Engineer at Palantir. She has built and operated software in highly regulated environments, including healthcare and government, and is passionate about delivering mission-critical systems quickly and securely. Lexi enjoys getting deep into data, and her work at Manifest focuses on the real-world challenges of vulnerability matching, package identification, and reducing noise in vulnerability management.
Dr. Ugur Koc is a Senior AI R&D Engineer at Manifest Cyber, where he leads the design and development of AI Risk Management solutions like AI-BOM generation and automated policy evaluation. With a PhD in Computer Science from University of Maryland, his research spans AI-augmented program analysis, software security, privacy, and AI governance. His work is published in premier venues including ASE, FSE, TSE, and ICST. Prior to Manifest, Ugur led AI platform development at Privado, building LLM-powered privacy scanning services, and spent three years at Amazon developing automated privacy auditors for ML models leveraging adversarial ML techniques like membership inference and input reconstruction attacks. He holds the AI Governance Professional (AIGP) certification from IAPP and AWS Solutions Architect certification. Ugur bridges cutting-edge research with practical vulnerability management, bringing deep expertise in operationalizing AI security controls, policy automation, and supply chain risk mitigation for AI/ML systems.










