Uploaded May 2026 | Updated September 2026, 33 minutes ago
Daniel Bardenstein (Manifest, US)
Vulnerability management has spent the last decade arguing about identifiers (as we’ve seen from each previous VulnCon) – mostly between CPEs in NVD and for commercial products, and Package URLs (PURLs)for open-source software (leaving aside the technical argument about purls being locators and not identifiers). CPEs promised standardization and delivered ambiguity. PURLs emerged as a practical alternative,imperfect, but grounded in how software is actually built, packaged, and consumed. Along the way, the community learned hard lessons about versioning, namespaces, ecosystems, vulnerability scanning, and the cost of getting identifiers wrong.
Now we’re repeating the same mistakes with AI.
Security teams are being asked to reason about vulnerabilities, licenses, and provenance for models and datasets that have no consistent identifiers, unclear version semantics, and weak ties to their underlying components. Without stable, resolvable IDs, everything from SBOMs to VEX to policy enforcement breaks down.
This talk draws on lessons learned from years of wrestling with CPEs and PURLs in traditional software supply chains and applies them to AI systems. We’ll explore why models and datasets need first-class identifiers, what properties those identifiers must have to be security-relevant, and why the PURL design turns out to be a surprisingly good fit. We’ll walk through concrete examples of model and dataset PURLs, discuss edge cases like fine-tuning and composite models, and highlight where existing tooling can already be reused—or where it needs to evolve.
If we want to save ourselves the headache around identifiers for AI vulnerability management, we need to get identifiers right this time. This talk is about how to do that, before the ecosystem calcifies around another bad abstraction.
---
Daniel Bardenstein is the CEO and co-founder of Manifest, focused on making software and AI supply chains more transparent and secure. He is a co-chair of both the CISA AI Bill of Materials (AIBOM) Working Group and the OWASP AIBOM Working Group, helping shape how AI systems are identified, described, and secured in practice. Previously, Daniel served as Chief of Technology Strategy at CISA, where he led technology modernization efforts, OT/ICS strategy, and the development of the Cybersecurity Performance Goals. At the Defense Digital Service, he ran cybersecurity initiatives across the Department of Defense, including securing COVID-19 vaccine distribution and leading Hack the Pentagon. Before government service, Daniel built cybersecurity and data platforms at Exabeam and Palantir.
Daniel Bardenstein (Manifest, US)
Vulnerability management has spent the last decade arguing about identifiers (as we’ve seen from each previous VulnCon) – mostly between CPEs in NVD and for commercial products, and Package URLs (PURLs)for open-source software (leaving aside the technical argument about purls being locators and not identifiers). CPEs promised standardization and delivered ambiguity. PURLs emerged as a practical alternative,imperfect, but grounded in how software is actually built, packaged, and consumed. Along the way, the community learned hard lessons about versioning, namespaces, ecosystems, vulnerability scanning, and the cost of getting identifiers wrong.
Now we’re repeating the same mistakes with AI.
Security teams are being asked to reason about vulnerabilities, licenses, and provenance for models and datasets that have no consistent identifiers, unclear version semantics, and weak ties to their underlying components. Without stable, resolvable IDs, everything from SBOMs to VEX to policy enforcement breaks down.
This talk draws on lessons learned from years of wrestling with CPEs and PURLs in traditional software supply chains and applies them to AI systems. We’ll explore why models and datasets need first-class identifiers, what properties those identifiers must have to be security-relevant, and why the PURL design turns out to be a surprisingly good fit. We’ll walk through concrete examples of model and dataset PURLs, discuss edge cases like fine-tuning and composite models, and highlight where existing tooling can already be reused—or where it needs to evolve.
If we want to save ourselves the headache around identifiers for AI vulnerability management, we need to get identifiers right this time. This talk is about how to do that, before the ecosystem calcifies around another bad abstraction.
---
Daniel Bardenstein is the CEO and co-founder of Manifest, focused on making software and AI supply chains more transparent and secure. He is a co-chair of both the CISA AI Bill of Materials (AIBOM) Working Group and the OWASP AIBOM Working Group, helping shape how AI systems are identified, described, and secured in practice. Previously, Daniel served as Chief of Technology Strategy at CISA, where he led technology modernization efforts, OT/ICS strategy, and the development of the Cybersecurity Performance Goals. At the Defense Digital Service, he ran cybersecurity initiatives across the Department of Defense, including securing COVID-19 vaccine distribution and leading Hack the Pentagon. Before government service, Daniel built cybersecurity and data platforms at Exabeam and Palantir.










