AI infrastructure — training clusters, model registries, inference servers — is an attractive target.
Assets to Protect
- Model weights and checkpoints.
- Training data and pipelines.
- Inference endpoints.
- Credentials for cloud and model APIs.
- GPU capacity, which attackers may hijack for their own use.
Controls
- Access management: role-based access, multi-factor authentication and approval for sensitive operations.
- Network segmentation: isolate training and serving environments.
- Encryption: weights and data at rest and in transit.
- Integrity: sign and verify models before deployment; track provenance.
- Monitoring: log access to weights and unusual resource use.
- Patching: keep ML frameworks, drivers and serving software up to date.
Inference Endpoints
- Authenticate and rate-limit requests.
- Validate input sizes to prevent resource exhaustion.
- Don't expose internal management interfaces.
Notebooks and Experiments
Data science environments often have broad access and weak controls. Apply the same standards as production when they touch sensitive data.