Breaking
February 22, 2025

Protectors of the modern world: defending against Shadow ML and Agentic AI | usagoldmines.com

It may sound like hyperbole to say that machine learning operations (MLOps) have become the backbone of our digital future, but it’s actually true. Similar to how we view energy grids or transportation systems as part of the critical infrastructure that powers society, AI/ML software and capabilities is quickly becoming essential technology for a wide range of companies, industries, and citizen services.

With artificial intelligence (AI) and machine learning (ML) rapidly transform industries, we’ve also seen the rise of a new age of “Shadow IT” now referred to as “Shadow ML.” Employees are increasingly deploying AI agents and ML models without the knowledge or approval of IT departments, often circumventing security protocols, data governance policies, and compliance frameworks.

This unchecked proliferation of unauthorized AI tools introduces significant risks, from data leakage to model bias and vulnerabilities that threat actors could exploit. CISOs and IT leaders are now tasked with shining a light into the shadows– ensuring that AI-driven decisions are explainable, secure, and aligned with enterprise policies. Understanding the evolving role of MLOps in managing and securing the rapidly expanding AI/ML IT landscape is essential to safeguarding the interconnected systems that define our era.

Software is critical infrastructure

Software is an omnipresent component of our day-to-day lives, operating quietly but indispensably behind the scenes. For that reason, failures in these systems are often hard to detect, can happen at any moment, and spread quickly across the globe, disrupting businesses, upsetting economies, undermining governments or even endangering lives.

The stakes are even more significant as AI and ML technologies increasingly take center stage when it comes to software development and management. Traditional software operations are giving way to AI-driven systems capable of decision-making, prediction, and automation at unprecedented scale. However, like any technology that ushers in new but immense potential, AI and ML also introduce new complexities and risks, elevating the importance and need for strong MLOps security. As reliance on AI/ML grows, the robustness of MLOps security becomes foundational to fending off evolving cyber threats.

Understanding the risks of the MLOps lifecycle

The lifecycle of building and deploying ML models is filled with both complexity and opportunity. At its core, these processes include:

  • Selecting an appropriate ML algorithm, such as a support vector machine (SVM) or decision tree.
  • Feeding a dataset into the algorithm to train the model.
  • Producing a pre-trained model that can be queried for predictions.
  • Registering the pre-trained model in a model registry.
  • Deploying the pre-trained model into production by either embedding it in an app or hosting it on an inference server.

It’s a structured approach but one with significant vulnerabilities that threaten stability and security. These vulnerabilities, broadly categorized as inherent and implementation-related, include:

  • Inherent Vulnerabilities: The complexity of ML environments, including cloud services and open-source tools, can create security gaps that may be exploited.
  • Malicious ML models: Pre-trained models can be weaponized or intentionally crafted to produce biased or harmful outputs, causing trickle-down damage across dependent systems.
  • Malicious datasets: Training data can be poisoned to inject subtle yet dangerous behaviors that undermine a model’s integrity and reliability.
  • Jupyter “sandbox escapes”: In another example of “Shadow ML,” many data scientists today rely on Jupyter Notebook, which can serve as a path for malicious code execution and unauthorized access when not adequately secured.

Implementation vulnerabilities

  • Authentication shortcomings: Poor access controls expose MLOps platforms to unauthorized users, enabling data theft or model tampering.
  • Container escape: Containerized environments with improper configuration allow attackers to break isolation and access the host system and other containers.
  • MLOps platform immaturity: The rapid pace of innovation in AI/ML often outpaces the development of secure tooling, creating gaps in resilience and reliability.

While AI and ML can offer enormous benefits for organizations, it’s crucial not to prioritize rapid development over security. Doing so could compromise ML models and put organizations at risk. Furthermore, developers must exercise caution when loading models from public repositories, ensuring they validate the source and potential risks associated with the model files. Robust input validation, restricted access, and continuous vulnerability assessments are critical to mitigating risks and ensuring the secure deployment of machine learning solutions.

MLOps hygiene best practices

There are many other vulnerabilities across the MLOps pipeline, underscoring the importance of vigilance among teams. Many separate elements within a model serve as potential attack vectors, which organizations typically manage and secure. Therefore, implementing standard APIs for artifact access and ensuring seamless integration of security tools across various ML platforms for data scientists, machine learning engineers, and core development teams is essential. Key security considerations for MLOps development should include:

  • Dependencies and packages: Teams often use open-source frameworks and libraries like TensorFlow and PyTorch. Providing access to these dependencies from trusted sources—rather than directly from the internet—and conducting vulnerability scans to block malicious packages ensures the security of each component within the model.
  • Source code: Models are typically developed in languages such as Python, C++, or R. Employing static application security testing (SAST) to scan source code can identify and alleviate errors that may compromise model security.
  • Container images: Containers are used to deploy models for training and facilitate their use by other developers or applications. Performing comprehensive scans of container images before deployment helps prevent introducing risks into the operational environment.
  • Artifact signing: Signing all new service components early in the MLOps lifecycle and treating them as immutable units throughout different stages ensures that the application remains unchanged as it advances toward release.
  • Promotion/release blocking: Automatically rescanning the application or service at each stage of the MLOps pipeline allows for early detection of issues, which in turn helps with swift resolution and maintaining the integrity of the deployment process.

By adhering to these best practices, organizations can effectively safeguard MLOps pipelines and ensure that security measures enhance rather than impede the development and deployment of ML models. As we move further into an AI-driven future, the resilience of the MLOps infrastructure will become an increasingly key component to maintaining the trust, reliability, and security of the digital systems that power the world.

We’ve featured the best online cybersecurity course.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

I used NoteBookLM to help with productivity - here’s 5 top tips to get the most from Google’s AI aud...

Best wireless keyboards 2025: Top Bluetooth and USB models | usagoldmines.com

OpenAI confirms 400 million weekly ChatGPT users - here's 5 great ways to use the world’s most popul...

California Nominates Steve Jobs for $1 American Innovation Coin Juli Clover | usagoldmines.com

German startup to attempt the first orbital launch from Western Europe Stephen Clark | usagoldmines....

Android 16’s Live Update Notifications Look Awesome Tim | usagoldmines.com

Here's a Look at Apple's Secret Modem Testing Lab Where C1 Was Developed Juli Clover | usagoldmines....

DEAL: Galaxy S25 Ultra for $399, Get Galaxy Buds 3 Pro for $10 ($1260 Off) Tim | usagoldmines.com

How Apple Watch, Fitbit, Garmin, Oura, and Whoop Compare on Measuring HRV Beth Skwarecki | usagoldmi...

Here's How Four Major Newsrooms Are Using AI Michelle Ehrhardt | usagoldmines.com

Researchers figure out how to get fresh lithium into batteries John Timmer | usagoldmines.com

Leaked chat logs expose inner workings of secretive ransomware group Dan Goodin | usagoldmines.com

Under new bill, Bigfoot could become California’s “official cryptid” Nate Anderson | usagoldmines.co...

Texas measles outbreak may have spread to New Mexico; total cases near 100 Beth Mole | usagoldmines....

Windows tests long-awaited changes to Start, Share, and Search | usagoldmines.com

I Make This Easy and Elegant 'King Cake' to Impress My Guests Allie Chanthorn Reinmann | usagoldmine...

Everything New in iOS 18.4 Beta 1 Juli Clover | usagoldmines.com

Lenovo is going all out with yet another funky laptop design: this time, it's a business notebook wi...

“Bouncing” winds damaged Houston skyscrapers in 2024 Jennifer Ouellette | usagoldmines.com

Asus’ new “Fragrance Mouse” is a wireless mouse that also smells Andrew Cunningham | usagoldmines.co...

Dangling, twitching human robot with synthetic muscles makes its debut Benj Edwards | usagoldmines.c...

Unblockable ads now litter Microsoft’s Windows Surface app | usagoldmines.com

Best gaming laptops 2025: What to look for and highest-rated models | usagoldmines.com

'Fix Me a Plate' Is the Cookbook You Need for Hearty Meals Allie Chanthorn Reinmann | usagoldmines.c...

Download Your Kindle Books While You Still Can Emily Long | usagoldmines.com

I installed iOS 18.4 dev beta and the big Siri intelligence update is nowhere to be found lance.ulan...

F1 may ditch hybrids for V10s and sustainable fuels Jonathan M. Gitlin | usagoldmines.com

Elon Musk to “fix” Community Notes after they contradict Trump Ashley Belanger | usagoldmines.com

Microsoft’s new Majorana 1 chip is a quantum computing breakthrough | usagoldmines.com

4 things to expect at Amazon’s AI Alexa event | usagoldmines.com

Nine Tricks That Make Painting Any Room a Lot Easier Jeff Somers | usagoldmines.com

The Echo Show 15 Is $100 Off Right Now Daniel Oropeza | usagoldmines.com

Apple News+ Gains Recipes, Restaurant Reviews, and More in iOS 18.4 Juli Clover | usagoldmines.com

iOS 18.4 Adds New Ambient Music Feature Juli Clover | usagoldmines.com

Revamped Mail App With Built-In Categorization Comes to Mac and iPad Juli Clover | usagoldmines.com

iOS 18.4 Adds Apple Intelligence Priority Notifications Feature Juli Clover | usagoldmines.com

This is the weirdest laptop I've ever seen and it reminds me of an often-mocked, thoroughly misunder...

Amazon just overtook Walmart in revenue for the first time | usagoldmines.com

As the Kernel Turns: Rust in Linux saga reaches the “Linus in all-caps” phase Kevin Purdy | usagoldm...

RFK Jr. promptly cancels vaccine advisory meeting, pulls flu shot campaign Beth Mole | usagoldmines....

New Dockcase 7-in-1 Hub is Latest Favorite Accessory, Available on Kickstarter Tim | usagoldmines.co...

I Tested Grok 3, and It's Not Worth the Price Hike Khamosh Pathak | usagoldmines.com

The Six Best Methods for Paying Off Credit Card Debt Meredith Dietz | usagoldmines.com

Best Apple Deals of the Week: Big Apple Watch Series 10 Discounts Hit Alongside AirPods and More Mit...

Apple Seeds First Betas of tvOS 18.4 and watchOS 11.4 Juli Clover | usagoldmines.com

Apple Seeds First Beta of macOS Sequoia 15.4 Juli Clover | usagoldmines.com

Apple Releases First visionOS 2.4 Beta With Apple Intelligence, Spatial Gallery and More Juli Clover...

Apple Releases First Beta of iOS 18.4 With New Vision Pro App Juli Clover | usagoldmines.com

Meze Audio's beautiful new wired headphones have a new kind of planar magnetic driver, hand-finished...

Top US mineral firm hit by cyberattack that saw thieves steal $500,000 | usagoldmines.com

"We will never build a backdoor" – Apple kills its iCloud's end-to-end encryption feature in the UK ...

Google has stopped selling the Chromecast with Google TV – but there's no way I'm replacing mine | ...

Security flaw in popular stalkerware apps is exposing phone data of millions | usagoldmines.com

The Oppo Find N5 has made me even more excited for the Samsung Galaxy S25 Edge – here’s why jamie.ri...

Apple Intelligence finally arrives on Vision Pro, but it's the new iOS app that might turn heads lan...

Google’s cheaper YouTube Premium Lite subscription will drop Music Ryan Whitwam | usagoldmines.com

Notorious crooks broke into a company network in 48 minutes. Here’s how. Dan Goodin | usagoldmines.c...

Samsung’s tiny 128GB flash drive is a steal at this deal price: $14 | usagoldmines.com

This 34-inch Gigabyte ultrawide OLED gaming monitor is 39% off | usagoldmines.com

Here’s the Nothing Phone 3a and 3a Pro Tim | usagoldmines.com

This Blink Video Doorbell Is at Its Lowest Price Ever Pradershika Sharma | usagoldmines.com

My Favorite Amazon Deal of the Day: The Samsung Galaxy Watch Ultra Daniel Oropeza | usagoldmines.com

The MacRumors Show: iPhone 16e Announced! Hartley Charlton | usagoldmines.com

An Apple Store is on the Move in the UK Joe Rossignol | usagoldmines.com

iPhone 16e Continues Apple's Transition to Manufacturing in India Hartley Charlton | usagoldmines.co...

Apple pulls end-to-end encryption in UK, spurning backdoors for gov’t spying Ashley Belanger | usago...

DeepSeek goes beyond “open weights” AI with plans for source code release Kyle Orland | usagoldmines...

LG UltraGear 27GX790A-B review: A monitor for competitive gamers | usagoldmines.com

A cheaper YouTube Premium plan is coming ‘soon’ for users in the US | usagoldmines.com

Lenovo laptops get an F rating for repairability | usagoldmines.com

GTA V for PC will get ray tracing and more with big visual update in March | usagoldmines.com

Make sure you update your AM5 motherboard for the Ryzen 9 9950X3D | usagoldmines.com

Turn Off Uber's Preferred Currency Feature to Avoid a Fee Emily Long | usagoldmines.com

Google's 'Career Dreamer' Claims It Can Help You Find a Job to Match Your Skills David Nield | usago...

Apple Denies Speculation Surrounding iPhone 16e's Lack of MagSafe Joe Rossignol | usagoldmines.com

Is the Apple Watch SE next for the chop? The surprise iPhone 16e reveal could hint at more changes t...

Salt Typhoon hackers used this clever technique to attack US networks | usagoldmines.com

An episode of The Simpsons? Fake speakers found in Chinese Volvos. Jonathan M. Gitlin | usagoldmines...

HP realizes that mandatory 15-minute support call wait times isn’t good support Scharon Harding | us...

SEC’s “scorched-earth” lawsuit against Coinbase to be dropped, company says Ashley Belanger | usagol...

Nissan’s latest desperate gamble—see if Tesla will buy the company Jonathan M. Gitlin | usagoldmines...

The truth about PC gaming on SSDs vs. HDDs, tested with real data | usagoldmines.com

Your gaming monitor specs could be deceiving you | usagoldmines.com

This Ryzen 7 mini PC with 32GB RAM is only $299 right now | usagoldmines.com

ExpressVPN: The first 5 settings you need to change | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Grab this fast-charging 25K power bank for 25% off while you can | usagoldmines.com

Shopping for Google’s cheapest TV streamers? Good luck with that | usagoldmines.com

Windows 11 Remote Desktop issues? You aren’t alone. Here’s what you can do | usagoldmines.com

The First Seven Things to Cut From Your Budget When You Lose Your Job Meredith Dietz | usagoldmines....

13 Body Horror Movies With Substance Ross Johnson | usagoldmines.com

Here Are The Best Carrier Deals You Can Get When Pre-Ordering iPhone 16e Today Mitchel Broussard | u...

Report: Apple's C1 Is Just the Beginning of Modem Changes Hartley Charlton | usagoldmines.com

All Four iPhone 17 Models Said to Feature Apple-Designed Wi-Fi 7 Chip Joe Rossignol | usagoldmines.c...

Apple Pulls Encrypted iCloud Security Feature in UK Amid Government Backdoor Demands Tim Hardwick | ...

US government reveals new cybercrime unit targeting AI fraud, crypto and other scams | usagoldmines...

Leaked Nothing Phone 3a and 3a Pro renders tease a mid-range phone that should have Samsung worried ...

A cheaper YouTube Premium Lite tier could roll out soon – and as a Spotify fan I'm ready to sign up ...

Microsoft fixes Power Pages security flaw, tells users to be on their guard | usagoldmines.com

Building a resilient workforce security strategy | usagoldmines.com

Leave a Reply