Back to Feed
Threat IntelligenceAug 28, 2026

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

AI model lineage can obscure origin and inherited risks, Cisco research finds.

Summary

Cisco research reveals that country-of-origin labels for AI models are insufficient for assessing security risks. AI models can inherit behaviors and biases from upstream models, regardless of their stated origin, creating a 'provenance entanglement' that mirrors software supply chain vulnerabilities. This necessitates deeper due diligence beyond publisher identity, including lineage, training dependencies, and behavioral analysis.

Full text

If you think you’ve excluded all Chinese AI from your tech stack, you may need to think again. The US government’s attitude toward Chinese AI is that it is a national security threat. This alone could persuade patriotic Americans to eschew any AI labelled ‘Chinese’ in favor of an AI without that label. Cisco has published details on new research from itself and VAIL demonstrating that national labels do not give an accurate picture of model lineage and characteristics. In a blog post titled “The ‘U.S. vs. China’ AI Trap: An Incomplete Proxy for AI Security,” Cisco argues that country labels do not provide a complete picture of an AI model’s components because of a phenomenon it calls provenance entanglement. Researchers used two AI model fingerprinting methods to analyze model weights and behavioral patterns, and found that they do not accurately or necessarily reflect the model’s publisher name and country of origin. They suggest that AI models require their own form of SBOM but note there are difficulties: “the dependencies aren’t listed in a manifest file, they’re embedded in the learned weights themselves.” This is because a model producer is likely to fine-tune its AI with existing checkpoints rather than training it from a blank page. In short, it can inherit weights, biases and behavioral patterns from a different model originating in a different country to the one indicated on the label. A US model could contain behaviors inherited from a Chinese model while a Chinese model could inherit US characteristics. The developer and country of origin on the AI label retains value, says Cisco, providing insight into the accountable developer, the applicable jurisdiction, and ‘authorized’ procurement process – but it does not provide an accurate assessment of what may exist inside the model.Advertisement. Scroll to continue reading. Nemotron and Qwen models were chosen for study since it is known that some Nemotron models use Qwen base weights. The researchers looked for surviving relationships between the two families, using Cisco’s Model Provenance Kit and VAIL’s Behavioral Fingerprinting. The former examines the artifact from the inside, while the later examines inference behavior from the outside. “Both methods found Nemotron models built from Qwen base weights to be substantially more similar to Qwen models than chance would predict.” Their ultimate conclusion is that post-training and a new publisher name do not necessarily erase detectable relationships to an upstream model family. This is important, since model lineage can create issues similar to the software supply chain threat for which SBOMs were created. For example, say the researchers, “If an upstream model is later found to contain a backdoor, systematic bias, or exploitable behavior, organizations would need to know which downstream models may warrant review.” It suggests three areas that need improvement for the efficient use of AI: Enterprises considering the use of a particular model should, “treat the publisher identity as one piece of the puzzle.” Due diligence should include lineage, training dependencies, behavior analysis, and operational control: the name on the label is not a proxy for potential risk. Regulators need a better understanding of a model’s upstream dependencies to build a true picture regarding vulnerabilities, biases and restrictions stemming from model lineage. AI developers should treat lineage disclosure as routine, not optional. As in all things, transparency is the best disinfectant, and it would allow users to understand upstream dependencies before integrating a model into their tech stack. In a geopolitical context, a complete model is often known simply by the labeled country of origin. But this can produce blind spots and false equivalences. “A model bill of materials could extend responsible AI adoption by recording base checkpoints, derivation methods, major datasets, synthetic-data generators, teacher and reward models, licenses, and entities with post-deployment access. Technical fingerprints can corroborate those disclosures or identify relationships that may warrant further review. The industry doesn’t need to wait for regulation to make that routine.” So, conclude the researchers, while country of origin labels have relevance, they do not define a model’s technical lineage. “Models do not have passports. They have supply chains.” Related: Cisco Releases Open Source Tool for AI Model Provenance Related: AI Weights: Securing the Heart and Soft Underbelly of Artificial Intelligence Related: Bias in Artificial Intelligence: Can AI be Trusted? Related: AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Iran-Linked Hackers Shut Down UK Power Plant for Four DaysEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsSurveillance – Everything You Wanted to Know, But Were Afraid to AskCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOWAI-Driven Vulnerability Surge Breaks the Traditional Patching ModelStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption Latest News Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense PledgePaperCut Releases Emergency Patch for Exploited Zero-DayTrump Order Aims to Block Foreign Backdoors in US Power Grid GearAustralia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteCyberattack Causes Global Disruption at Boston Scientific Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patche

Entities

Cisco (vendor)AI (technology)Nemotron (product)Qwen (product)