September 29, 2026
Report

Evaluation of Artificial Intelligence (AI) and Machine Learning (ML) Approaches for Bill-of-Material (BOM) Analysis

Abstract

Advanced reactors rely on complex programmable digital devices whose hardware and software supply chains can hide cybersecurity issues. This paper examines three areas of cybersecurity concern; common cause failure (CCF), diversity, and defense-in-depth (D3). Ensuring D3 requires deep visibility into hardware bills-of-materials (HBOMs) and software bills-of- materials (SBOMs). However, BOMs are often in a proprietary format, have inconsistent features, and can contain inexact matches. Furthermore, vendors do not consistently make BOMs available to customers. This paper compares artificial intelligence (AI) and machine learning (ML) approaches to detect CCF and D3 risks by analyz- ing HBOM and SBOM data at scale. AI/ML models help quantify risks that traditional cybersecurity review cannot easily detect by comparing component lineages, identifying shared dependencies, and uncovering hidden homogeneity. These methods support vendors, regulators, advanced reactor designers, and operators by facilitating cybersecurity analysis, improving component and supply chain transparency, and strengthening D3 across diverse programmable digital devices across multiple systems throughout advanced reactors.

Published: September 29, 2026

Citation

Roth C.G., W.J. Hutton, F.A. de Peralta, and A. Baji. 2026. Evaluation of Artificial Intelligence (AI) and Machine Learning (ML) Approaches for Bill-of-Material (BOM) Analysis. Richland, WA: Pacific Northwest National Laboratory. PNNL-39767.

Research topics