20
AI Security Engineering
The penetration tester found the vulnerability in under an hour. The machine learning platform looked well segmented on paper: separate Kubernetes namespaces, separate storage buckets, RBAC policies, and team-level quotas. Then the test job landed on a shared GPU immediately after another team's training run and recovered fragments of data that should no longer have existed.
That is the uncomfortable lesson of AI infrastructure. Traditional controls can be correct and still miss the place where the real exposure lives. Kubernetes namespace isolation does not extend to GPU memory. A service account boundary does not automatically protect a model cache. A network policy does not stop a model from loading an unsafe artifact. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access