Successful supply chain optimization must mitigate imbalances between supply and demand over time. While accurate demand prediction is essential for supply planning, it alone does not suffice. The key to successful supply planning for optimal and viable execution lies in maximizing predictability for both demand and supply throughout an execution horizon. Therefore, enhancing the accuracy of supply predictions is imperative to create an attainable supply plan that matches demand without overstocking or understocking. However, in complex supply chain networks with numerous nodes and edges, accurate supply predictions are challenging due to dynamic node interactions, cascading supply delays, resource availability, production and logistic capabilities. Consequently, supply executions often deviate from their initial plans. To address this, we present the Graph-based Supply Prediction (GSP) probabilistic model. Our attention-based graph neural network (GNN) model predicts supplies, inventory, and imbalances using graph-structured historical data, demand forecasting, and original supply plan inputs. The experiments, conducted using historical data from a global consumer goods company's
Many real-world resource allocation systems, such as humanitarian logistics and vaccine distribution, must preposition limited supply across multiple locations before demand is realized while stockouts incur irreversible service losses. To study this, we introduce the Online Shared Supply Allocation (OSSA) problem, a stateful online model in which a central hub allocates a finite, unknown supply to multiple sites facing sequential demand under fixed-charge transportation costs and lost-sales penalties. Unlike classical make-to-stock or make-to-order inventory models, OSSA precludes backlogging and replenishment only hedges against future demand. To tackle OSSA, we propose a deterministic threshold-proportional policy GPA and prove that it achieves a $4/3$-approximation to the offline optimum up to an additive term independent of the total supply. We complement this with matching lower bounds showing that the $4/3$ ratio is tight and that the additive-error dependence is unavoidable, even for randomized algorithms that know the total supply upfront. Finally, we develop a learning-augmented extension to GPA that principally incorporates imperfect forecasts (e.g., from human experts o
In this work, we propose a theory for the kinetics of emulsions in which a continuous supply of matter feeds droplet growth. We consider cases where growth is either limited by bulk diffusion or the transport through the droplets' interfaces. Our theory extends the Lifshitz-Slyozov-Wagner (LSW) theory by two types of matter supply, where either the supersaturation is maintained or the supply rate is constant. In emulsions with maintained supersaturation, we find a decoupling of droplets at all times, with the droplet size distribution narrowing in the diffusion-limited regime and a drifting distribution of a fixed shape in the interface-resistance-limited case. In emulsions with a constant matter supply, there is a transition between narrowing and broadening in the diffusion-limited regime, and the distribution is non-universal. For the interface-resistance-limited regime, there is no transition to narrowing, and we find a universal law governing coarsening kinetics that is valid for any constant matter supply. The average radius evolves according to a power law that is independent of the matter supply, and we find a closed-form expression for the droplet size distribution function
We study how product specialization choices affect supply chain resilience. We propose a theory of supply chain formation in which only compatible inputs can be used in final production. Intermediate producers choose how much to specialize their goods, trading off higher value added against a smaller pool of compatible final producers. Final producers operate complex supply chains, requiring multiple complementary inputs. Specialization choices determine how quickly final producers can replace suppliers after disruptions, and thus supply chain resilience. In equilibrium, production inputs are over-specialized due to a novel network externality. Intermediate producers fail to internalize how their specialization choices affect the likelihood that final producers source all required inputs, and therefore the lost value added from complementary inputs if production halts. As a result, supply chains are more productive in normal times but less resilient than socially desirable. We characterize the optimal transfer that restores the efficient allocation and show that non-fiscal interventions, such as compatibility standards, are generally welfare-enhancing.
This paper systematizes knowledge about secure software supply chain patterns. It identifies four stages of a software supply chain attack and proposes three security properties crucial for a secured supply chain: transparency, validity, and separation. The paper describes current security approaches and maps them to the proposed security properties, including research ideas and case studies of supply chains in practice. It discusses the strengths and weaknesses of current approaches relative to known attacks and details the various security frameworks put out to ensure the security of the software supply chain. Finally, the paper highlights potential gaps in actor and operation-centered supply chain security techniques
Supply optimization is a complex and challenging task in the magazine retail industry because of the fixed inventory assumption, irregular sales patterns, and varying product and point-of-sale characteristics. We introduce AthenIA, an industrialized magazine supply optimization solution that plans the supply for over 20,000 points of sale in France. We modularize the supply planning process into a four-step pipeline: demand sensing, optimization, business rules, and operating. The core of the solution is a novel group conformalized quantile regression method that integrates domain expert insights, coupled with a supply optimization technique that balances the costs of out-of-stock against the costs of over-supply. AthenIA has proven to be a valuable tool for magazine publishers, particularly in the context of evolving economic and ecological challenges.
The development of large language models (LLMs) has provided new tools for research in supply chain management (SCM). In this paper, we introduce a retrieval-augmented generation (RAG) framework that dynamically integrates external knowledge into the inference process, and develop a domain-specialized SCM LLM, which demonstrates expert-level competence by passing standardized SCM examinations and beer game tests. We further employ the use of LLMs to conduct horizontal and vertical supply chain games, in order to analyze competition and cooperation within supply chains. Our experiments show that RAG significantly improves performance on SCM tasks. Moreover, game-theoretic analysis reveals that the LLM can reproduce insights from the classical SCM literature, while also uncovering novel behaviors and offering fresh perspectives on phenomena such as the bullwhip effect. This paper opens the door for exploring cooperation and competition for complex supply chain network through the lens of LLMs.
Digital twin technology has been regarded as a beneficial approach in supply chain development. Different from traditional digital twin (temporal dynamic), supply chain digital twin is a spatio-temporal dynamic system. This paper explains what is 'twined' in supply chain digital twin and how to 'twin' them to handle the spatio-temporal dynamic issue. A supply chain digital twin framework is developed based on the theories of system of systems and supply chain operations reference model. This framework is universal and can be applied in various types of supply chain systems. We firstly decompose the supply chain system into unified standard blocks preparing for the adoption of digital twin. Next, the idea of supply chain operations reference model is adopted to digitise basic supply chain activities within each block and explain how to use existing information system. Then, individual sub-digital twin is established for each member in supply chain system. After that, we apply the concept of system of systems to integrate and coordinate sub-digital twin into supply chain digital twin from the views of supply chain business integration and information system integration. At last, one
Over the past thirty years, logistics has undergone tremendous change from a purely operational performance that led to sales or production and focused on securing supply and delivery lines to customers, with the transformation of intelligent technologies into a professional operator. In today's world, the fourth generation of industry has forced companies to rethink how their supply chain is designed. In this case, in addition to the need for adaptation, supply chains also have the opportunity to reach operational horizons, use emerging digital supply chain business models, and transform the company into a digital supply chain. One of the transformational technologies that has had a tremendous impact on the supply chain in this regard is IoT technology. This technology, as one of the largest sources of data production, can facilitate supply chain processes in all its dimensions. However, due to the presence of the Internet and the location of supply chain components in the context of information networks, this digital supply chain always faces major challenges. Therefore, in this paper, an attempt was made to examine and prioritize the most important challenges of implementing a s
With increasing interest in adaptive clinical trial designs, challenges are present to drug supply chain management which may offset the benefit of adaptive designs. Thus, it is necessary to develop an optimization tool to facilitate the decision making and analysis of drug supply chain planning. The challenges include the uncertainty of maximum drug supply needed, the shifting of supply requirement, and rapid availability of new supply at decision points. In this paper, statistical simulations are designed to optimize the pre-study medication supply strategy and monitor ongoing drug supply using real-time data collected with the progress of study. Particle swarm algorithm is applied when performing optimization, where feature extraction is implemented to reduce dimensionality and save computational cost.
Small Office/Home Office (SOHO) devices are widely popular, yet often attacked due to security vulnerabilities in their firmware, affecting thousands of devices. These security vulnerabilities often stem from outdated Linux kernel versions included in SOHO device firmware. Naturally, prior work audited the extent and impact of this issue by simple Linux version extraction and version number based vulnerability mapping. However, it is unclear how many of these anticipated vulnerabilities actually exist in the heavily customized SOHO kernels and if there are any barriers towards updating Linux kernels in SOHO firmwares. To address this gap, we uncover actual kernel-related vulnerabilities found in 306 SOHO devices using a high-precision template-based CVE detection mechanism on GPL source releases of more than 900 firmwares from these devices. Next, as a first, we traced the supply chain of these vulnerable SOHO devices at scale and identify kernel lock-in as a significant security issue -- SOHO vendors are effectively locked to specific (often older) kernel versions due to the system-on-chip (SoC) SDKs they use. This kernel lock-in produces a vulnerability debt that is inherited alo
Electric vertical takeoff and landing (eVTOL) aircraft manufacturers await numerous pre-orders for eVTOLs and expect demand for such advanced air mobility (AAM) aircraft to rise dramatically soon. However, eVTOL manufacturers (EMs) cannot commence mass production of commercial eVTOLs due to a lack of supply chain planning for eVTOL manufacturing. The eVTOL supply chain differs from traditional ones due to stringent quality standards and limited suppliers for eVTOL parts, shortages in skilled labor and machinery, and contract renegotiations with major aerospace suppliers. The emerging AAM aircraft market introduces uncertainties in supplier pricing and capacities, eVTOL manufacturing costs, and eVTOL demand, further compounding the supply chain planning challenges for EMs. Despite this critical need, no study has been conducted to develop a comprehensive supply chain planning model for EMs. To address this research gap, we propose a stochastic optimization model for integrated supply chain planning of EMs while maximizing their operating profits under the abovementioned uncertainties. We conduct various numerical cases to analyze the impact of 1) endogenous eVTOL demand influenced b
Large Language Models (LLMs) are increasingly used as core dependencies in software systems. However, the hosted LLM services evolve continuously through provider-side updates without explicit version changes. These silent updates can introduce behavioral drift, causing regressions in functionality, formatting, safety constraints, or other application-specific requirements. Existing approaches focus primarily on regression testing or versioning but do not provide deployer-side mechanisms for governing compatibility during opaque model evolution. This paper proposes a deployment-side governance framework based on three components: clearly defined rules for how the model is allowed to behave (production contracts), focused testing organized by deployment risk categories (risk-category-based testing suite), and release checkpoints that block updates unless they meet defined safety and performance standards (compatibility gates). Through exploratory validation across multiple LLM versions, we provide evidence that targeted testing in specific risk areas can uncover performance regressions that overall metrics miss. We also identify several open research challenges, including how to sys
We consider a multi-retailer supply chain where each retailer can dynamically choose when to share information (e.g., local inventory levels or demand observations) with other retailers, incurring a communication cost for each sharing event. This flexible information exchange mechanism contrasts with fixed protocols such as always sharing or never sharing. We formulate a joint optimization of inventory control and communication strategies, aiming to balance the trade-off between communication overhead and operational performance (service levels, holding, and stockout costs). We adopt a common information framework and derive a centralized Partially Observable Markov Decision Process (POMDP) model for a supply chain coordinator. Solving this coordinator's POMDP via dynamic programming characterizes the structure of optimal policies, determining when retailers should communicate and how they should adjust orders based on available information. We show that, in this setting, retailers can often act optimally by sharing only limited summaries of their private data, reducing communication frequency without compromising performance. We also incorporate practical constraints on communicat
Motivated by the recently experienced systemic shocks (the COVID-19 pandemic and the full-fledged Russia's war of aggression against Ukraine) - that have created new forms of uncertainties to our supplies - this paper explores the supply chain robustness under risk aversion and ambiguity aversion. We aim to understand the potential consequences of deeply uncertain systemic events on the supply chain resilience and how does the information precision affect individual agents' choices and the chain-level preparedness to aggregate shocks. Augmenting a parsimonious supply chain model with uncertainty, we analyse the relationship between the upstream sourcing decisions and the supply chain survival probability. Both risk-averse and ambiguity-averse individually-optimising agents' upstream sourcing paths are efficient but can become vulnerable to aggregate shocks. In contrast, a chain-level coordination of downstream firm sourcing decisions can qualitatively improve the robustness of the entire supply chain compared to the individual decision-making baseline. Such a robust decision making ensures that in the presence of an aggregate shock - independently of its realisation - part of upstr
In Go, the widespread adoption of open-source software has led to a flourishing ecosystem of third-party dependencies, which are often integrated into critical systems. However, the reuse of dependencies introduces significant supply chain security risks, as a single compromised package can have cascading impacts. Existing supply chain attack taxonomies overlook language-specific features that can be exploited by attackers to hide malicious code. In this paper, we propose a novel taxonomy of 12 distinct attack vectors tailored for the Go language and its package lifecycle. Our taxonomy identifies patterns in which language-specific Go features, intended for benign purposes, can be misused to propagate malicious code stealthily through supply chains. Additionally, we introduce GoSurf, a static analysis tool that analyzes the attack surface of Go packages according to our proposed taxonomy. We evaluate GoSurf on a corpus of widely used, real-world Go packages. Our work provides preliminary insights for securing the open-source software supply chain within the Go ecosystem, allowing developers and security analysts to prioritize code audit efforts and uncover hidden malicious behavior
The food supply chain has a number of challenges, including a lack of transparency and disengagement among stakeholders. By providing a transparent and traceable digital ledger of transactions and movements for all supply chain actors, blockchain technology can provide a resolution to these problems. We propose a blockchain-based system for tracking a product's full path, from its raw components to the finished item in the store. Many advantages of the offered system include improved quality assessment, increased product transparency and traceability, and sophisticated fraud detection capabilities. By reinventing the way transactions are carried out and enabling stakeholders to obtain a complete record of each product's journey, the system has the potential to completely alter the food supply chain. Also, by minimising inefficiencies, waste, and fraudulent activities that have a negative influence on the supply chain, the deployment of this system can remove limits imposed by the current supply chain. Overall, the suggested blockchain-based system has the potential to significantly increase the efficiency, transparency, and traceability of the food supply chain.
The web continues to grow, but dependency-monitoring tools and standards for resource integrity lag behind. Currently, there exists no robust method to verify the integrity of web resources, much less in a generalizable yet performant manner, and supply chains remain one of the most targeted parts of the attack surface of web applications. In this paper, we present the design of LiMS, a transparent system to bootstrap link integrity guarantees in web browsing sessions with minimal overhead. At its core, LiMS uses a set of customizable integrity policies to declare the (un)expected properties of resources, verifies these policies, and enforces them for website visitors. We discuss how basic integrity policies can serve as building blocks for a comprehensive set of integrity policies, while providing guarantees that would be sufficient to defend against recent supply chain attacks detailed by security industry reports. Finally, we evaluate our open-sourced prototype by simulating deployments on a representative sample of 450 domains that are diverse in ranking and category. We find that our proposal offers the ability to bootstrap marked security improvements with an overall overhead
Supply Chain Management requires addressing a variety of complex decision-making challenges, from sourcing strategies to planning and execution. Over the last few decades, advances in computation and information technologies have enabled the transition from manual, intuition and experience-based decision-making, into more automated and data-driven decisions using a variety of tools that apply optimization techniques. These techniques use mathematical methods to improve decision-making. Unfortunately, business planners and executives still need to spend considerable time and effort to (i) understand and explain the recommendations coming out of these technologies; (ii) analyze various scenarios and answer what-if questions; and (iii) update the mathematical models used in these tools to reflect current business environments. Addressing these challenges requires involving data science teams and/or the technology providers to explain results or make the necessary changes in the technology and hence significantly slows down decision making. Motivated by the recent advances in Large Language Models (LLMs), we report how this disruptive technology can democratize supply chain technology
Global crises and regulatory developments require increased supply chain transparency and resilience. Companies do not only need to react to a dynamic environment but have to act proactively and implement measures to prevent production delays and reduce risks in the supply chains. However, information about supply chains, especially at the deeper levels, is often intransparent and incomplete, making it difficult to obtain precise predictions about prospective risks. By connecting different data sources, we model the supply network as a knowledge graph and achieve transparency up to tier-3 suppliers. To predict missing information in the graph, we apply state-of-the-art knowledge graph completion methods and attain a mean reciprocal rank of 0.4377 with the best model. Further, we apply graph analysis algorithms to identify critical entities in the supply network, supporting supply chain managers in automated risk identification.