How Do You Choose Your AI Component? An Interview Study of Secure AI Integration in Practice

📅 2026-07-18
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the widespread yet often insecure integration of AI components into software systems, which frequently overlooks critical security risks and can lead to malicious behaviors or data breaches. Through semi-structured interviews with 22 industry practitioners, the work systematically uncovers a pervasive neglect of security considerations during AI component selection and integration, revealing that functional performance overwhelmingly dominates decision-making while security is rarely evaluated. Drawing on established practices from traditional software supply chain security, the paper adapts and extends these principles to the AI context, proposing a set of lifecycle-spanning security-by-design guidelines. It further offers actionable recommendations tailored for developers, model providers, and researchers to foster more secure AI integration practices.
📝 Abstract
The increasing adoption of Large Language Models (LLMs) as AI components in modern software systems introduces distinct security risks to the software supply chain. While many considerations and safety mechanisms are in place for components of the traditional software supply chain, the recent rapid adoption of AI components and platforms has overlooked these hard learned lessons. Selecting and integrating AI models without clear guidance on how these choices affect system security may leave applications vulnerable to threats, such as malicious components, data leakage, and unintended behavior. The goal of this study is to understand practitioners' decision making process and security considerations in selecting and integrating AI components through an exploratory semi-structured interview study. Toward this goal, we conducted semistructured interviews with 22 software developers, architects, and AI practitioners across diverse organizations about how they integrate AI components into their software. Our analysis finds that practitioners' model selection is predominantly driven by functional criteria, including performance, accuracy, cost, and specific features, e.g., tool calling or multimodal support, while security is rarely considered as an evaluation criterion. We observe a consistent lack of security concern throughout the AI component integration process, with established software supply chain lessons overlooked or ignored. The industry is repeating the historically costly mistakes of early software dependency management, prioritizing rapid reuse and availability over security and provenance. We distill our findings into actionable recommendations for AI adopters, model providers, and researchers, advocating for a proactive, security-by-design approach that integrates security evaluation into component selection and sustains it throughout the software development lifecycle.
Problem

Research questions and friction points this paper is trying to address.

AI component integration
software supply chain security
Large Language Models
security risks
model selection
Innovation

Methods, ideas, or system contributions that make the work stand out.

AI component integration
software supply chain security
security-by-design
Large Language Models (LLMs)
developer practices
🔎 Similar Papers
No similar papers found.