Breaking
February 21, 2025

Protectors of the modern world: defending against Shadow ML and Agentic AI | usagoldmines.com

It may sound like hyperbole to say that machine learning operations (MLOps) have become the backbone of our digital future, but it’s actually true. Similar to how we view energy grids or transportation systems as part of the critical infrastructure that powers society, AI/ML software and capabilities is quickly becoming essential technology for a wide range of companies, industries, and citizen services.

With artificial intelligence (AI) and machine learning (ML) rapidly transform industries, we’ve also seen the rise of a new age of “Shadow IT” now referred to as “Shadow ML.” Employees are increasingly deploying AI agents and ML models without the knowledge or approval of IT departments, often circumventing security protocols, data governance policies, and compliance frameworks.

This unchecked proliferation of unauthorized AI tools introduces significant risks, from data leakage to model bias and vulnerabilities that threat actors could exploit. CISOs and IT leaders are now tasked with shining a light into the shadows– ensuring that AI-driven decisions are explainable, secure, and aligned with enterprise policies. Understanding the evolving role of MLOps in managing and securing the rapidly expanding AI/ML IT landscape is essential to safeguarding the interconnected systems that define our era.

Software is critical infrastructure

Software is an omnipresent component of our day-to-day lives, operating quietly but indispensably behind the scenes. For that reason, failures in these systems are often hard to detect, can happen at any moment, and spread quickly across the globe, disrupting businesses, upsetting economies, undermining governments or even endangering lives.

The stakes are even more significant as AI and ML technologies increasingly take center stage when it comes to software development and management. Traditional software operations are giving way to AI-driven systems capable of decision-making, prediction, and automation at unprecedented scale. However, like any technology that ushers in new but immense potential, AI and ML also introduce new complexities and risks, elevating the importance and need for strong MLOps security. As reliance on AI/ML grows, the robustness of MLOps security becomes foundational to fending off evolving cyber threats.

Understanding the risks of the MLOps lifecycle

The lifecycle of building and deploying ML models is filled with both complexity and opportunity. At its core, these processes include:

  • Selecting an appropriate ML algorithm, such as a support vector machine (SVM) or decision tree.
  • Feeding a dataset into the algorithm to train the model.
  • Producing a pre-trained model that can be queried for predictions.
  • Registering the pre-trained model in a model registry.
  • Deploying the pre-trained model into production by either embedding it in an app or hosting it on an inference server.

It’s a structured approach but one with significant vulnerabilities that threaten stability and security. These vulnerabilities, broadly categorized as inherent and implementation-related, include:

  • Inherent Vulnerabilities: The complexity of ML environments, including cloud services and open-source tools, can create security gaps that may be exploited.
  • Malicious ML models: Pre-trained models can be weaponized or intentionally crafted to produce biased or harmful outputs, causing trickle-down damage across dependent systems.
  • Malicious datasets: Training data can be poisoned to inject subtle yet dangerous behaviors that undermine a model’s integrity and reliability.
  • Jupyter “sandbox escapes”: In another example of “Shadow ML,” many data scientists today rely on Jupyter Notebook, which can serve as a path for malicious code execution and unauthorized access when not adequately secured.

Implementation vulnerabilities

  • Authentication shortcomings: Poor access controls expose MLOps platforms to unauthorized users, enabling data theft or model tampering.
  • Container escape: Containerized environments with improper configuration allow attackers to break isolation and access the host system and other containers.
  • MLOps platform immaturity: The rapid pace of innovation in AI/ML often outpaces the development of secure tooling, creating gaps in resilience and reliability.

While AI and ML can offer enormous benefits for organizations, it’s crucial not to prioritize rapid development over security. Doing so could compromise ML models and put organizations at risk. Furthermore, developers must exercise caution when loading models from public repositories, ensuring they validate the source and potential risks associated with the model files. Robust input validation, restricted access, and continuous vulnerability assessments are critical to mitigating risks and ensuring the secure deployment of machine learning solutions.

MLOps hygiene best practices

There are many other vulnerabilities across the MLOps pipeline, underscoring the importance of vigilance among teams. Many separate elements within a model serve as potential attack vectors, which organizations typically manage and secure. Therefore, implementing standard APIs for artifact access and ensuring seamless integration of security tools across various ML platforms for data scientists, machine learning engineers, and core development teams is essential. Key security considerations for MLOps development should include:

  • Dependencies and packages: Teams often use open-source frameworks and libraries like TensorFlow and PyTorch. Providing access to these dependencies from trusted sources—rather than directly from the internet—and conducting vulnerability scans to block malicious packages ensures the security of each component within the model.
  • Source code: Models are typically developed in languages such as Python, C++, or R. Employing static application security testing (SAST) to scan source code can identify and alleviate errors that may compromise model security.
  • Container images: Containers are used to deploy models for training and facilitate their use by other developers or applications. Performing comprehensive scans of container images before deployment helps prevent introducing risks into the operational environment.
  • Artifact signing: Signing all new service components early in the MLOps lifecycle and treating them as immutable units throughout different stages ensures that the application remains unchanged as it advances toward release.
  • Promotion/release blocking: Automatically rescanning the application or service at each stage of the MLOps pipeline allows for early detection of issues, which in turn helps with swift resolution and maintaining the integrity of the deployment process.

By adhering to these best practices, organizations can effectively safeguard MLOps pipelines and ensure that security measures enhance rather than impede the development and deployment of ML models. As we move further into an AI-driven future, the resilience of the MLOps infrastructure will become an increasingly key component to maintaining the trust, reliability, and security of the digital systems that power the world.

We’ve featured the best online cybersecurity course.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

The Huawei Band 10 is here, and it's packing a secret mood-tracking weapon | usagoldmines.com

Best external drives 2025: Backup, storage, and portability | usagoldmines.com

I tried this new online AI agent, and I can’t believe how good Convergence AI's Proxy 1.0 is at comp...

Over a million clinical records exposed in data breach | usagoldmines.com

Rabbit AI's new tool can control your Android phones, but I’m not sure how I feel about letting it c...

Everything missing from the iPhone 16e, including MagSafe and Photographic Styles jacob.krol@futuren...

Apple Already Testing a C2 Modem for iPhones, According to Leaker Joe Rossignol | usagoldmines.com

What's New on Max in March in 2025 Emily Long | usagoldmines.com

Apple Says iPhone 16e's New C1 Modem is Just the 'Start' in Interview Joe Rossignol | usagoldmines.c...

Someone wants to sell you a digital version of the antiquated typewriter but without a glued-on keyb...

Microsoft’s new AI agent can control software and robots Benj Edwards | usagoldmines.com

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

T-Mobile’s Free MLB TV Offer Returns March 25 Tim | usagoldmines.com

Why the iPhone 16e Uses a 'Binned' A18 Chip (and What That Means) Jake Peterson | usagoldmines.com

What's New on Paramount+ With Showtime in March 2025 Emily Long | usagoldmines.com

This is probably the best looking docking station I've ever seen in my entire life - and I can't wai...

See a garbage truck’s CNG cylinders explode after lithium-ion battery fire Nate Anderson | usagoldmi...

OnePlus Watch 3 Case Typo Says It is “Meda in China” Kellen | usagoldmines.com

Finally, My iPhone 15 Pro Is Getting the Visual Intelligence Upgrade It Deserves Michelle Ehrhardt |...

The Latest M4 Apple iMac Is Already $150 Off Daniel Oropeza | usagoldmines.com

iPhone 17 Air Now Rumored to Feature 6.7-Inch Display Joe Rossignol | usagoldmines.com

Is that Asus's first portable heater? No, it's the new ROG XG eGPU with a 600w RTX 5090 card and (we...

Study: Cuttlefish adapt camouflage displays when hunting prey Jennifer Ouellette | usagoldmines.com

Nvidia GeForce RTX 5070 Ti review: An RTX 4080 for $749, at least in theory Andrew Cunningham | usag...

FTC investigates “tech censorship,” says it’s un-American and may be illegal Jon Brodkin | usagoldmi...

How to Sideload Android Apps (and What to Watch Out For) Justin Pot | usagoldmines.com

My Favorite Irish Soda Bread Only Has Four Ingredients Allie Chanthorn Reinmann | usagoldmines.com

Elon Musk recommends that the International Space Station be deorbited ASAP Eric Berger | usagoldmin...

Small study suggests dark mode doesn’t save much power for very human reasons Kevin Purdy | usagoldm...

Meta claims torrenting pirated books isn’t illegal without proof of seeding Ashley Belanger | usagol...

SpaceX engineers brought on at FAA after probationary employees were fired Vittoria Elliott and Aari...

ISP sued by record labels agrees to identify 100 users accused of piracy Jon Brodkin | usagoldmines....

Best laptops 2025: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com

Lexar Go SSD with Hub review: Tiny, rugged storage for your phone | usagoldmines.com

Nvidia’s RTX 5070 Ti sells out instantly, surprising no one | usagoldmines.com

Wow! This Core Ultra 9 laptop with RTX 4070 is $600 off right now | usagoldmines.com

Nvidia, Newegg try to keep RTX 50-series cards away from scalpers | usagoldmines.com

This super-fast 1TB Samsung SSD is on sale at its best price: $80 | usagoldmines.com

Why is my HDMI connection buzzing? | usagoldmines.com

This outdoor security camera brings Matter connectivity outside | usagoldmines.com

Microsoft is paywalling these features in Notepad and Paint | usagoldmines.com

New Ring Outdoor Cam Plus promises to deliver 2K resolution | usagoldmines.com

This 34-inch ultrawide OLED gaming monitor is $300 off now | usagoldmines.com

Why you need CUDIMM, the new memory standard for overclockers, PC gamers and DIY PC builders | usag...

Buying an SSD? This is how NVMe 2.0 will supercharge your performance | usagoldmines.com

How faster DDR5 memory can unlock new performance in your desktop PC | usagoldmines.com

Your memory card may be holding you back | usagoldmines.com

Best VPN services 2025: Top picks for speed, price, privacy, and more | usagoldmines.com

This smart indoor security camera is really just $15 right now | usagoldmines.com

Firefox 135 update fixes security flaws and some crash issues | usagoldmines.com

Baseball streaming in 2025: More options, but more mayhem, too | usagoldmines.com

Stop being tricked by AI fakery. Here are the red flags to look for | usagoldmines.com

RIP, Amazon Appstore on Android Kellen | usagoldmines.com

Gemini Advanced Now Gets ‘Deep Research’ on Mobile Tim | usagoldmines.com

Samsung Shipping February Patch to More Galaxy Devices Tim | usagoldmines.com

Six Easy and Cheap Ways to Upgrade Your Staircase Jeff Somers | usagoldmines.com

My Favorite Amazon Deal of the Day: The Ultimate Ears Megaboom 4 Daniel Oropeza | usagoldmines.com

iPhone Feature for Tracking Lost Baggage Expands to American Airlines Joe Rossignol | usagoldmines.c...

Nvidia rival claims DeepSeek world record as it delivers industry-first performance with 95% fewer c...

The cheapest Sonos sales and deals for February 2025 | usagoldmines.com

These new cheap ANC headphones from a reliable brand look like wildly good value – 90 hours of batte...

OnePlus seeks FDA approval for Sleep Apnea Detection on its watch and takes on Apple in the process ...

Hackers are targeting Signal with new QR code-linked cyberattack | usagoldmines.com

Elon Musk recommends that the International Space Station be deorbited ASAP Eric Berger | usagoldmin...

MacBooks lagging behind PC rivals when it comes to repairability: Report Scharon Harding | usagoldmi...

An Ode to the Home Button Jake Peterson | usagoldmines.com

Siri's Apple Intelligence Upgrades Are Still a Couple of Months Away (at Least) Jake Peterson | usag...

How to Do Fartlek Runs (and Seven Different Kinds to Try) Beth Skwarecki | usagoldmines.com

World's Thinnest Foldable Phone Launches in Europe and Asia Tim Hardwick | usagoldmines.com

iPhone 17 Air's Battery Life Looks Promising Based on iPhone 16e Joe Rossignol | usagoldmines.com

Former PlayStation boss says Microsoft's decision to bring Xbox games to PS5 is 'a win for PlayStati...

The iPhone 15 Pro could get one of my favorite Apple Intelligence features soon – and it’s about tim...

The incoming Volvo ES90 is going to be a supercomputer-on-wheels, thanks to Nvidia –and that could g...

Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack | usagoldmi...

Rumor suggests Nvidia’s had difficulties to iron out with chips for RTX 5070 and 5060 GPUs, seemingl...

Sad about Dead Boy Detectives being canceled? You’ll be able to see one of the Netflix show’s stars ...

In the lead-up to GTA 6 releasing later this year, Rockstar announces a new GTA 5 update for PC play...

GoPro unveils a much cheaper 360-degree camera, but it’s not the all-new Max 2 that we’ve been waiti...

Amazon remembers it has an Android app store, kills it Ryan Whitwam | usagoldmines.com

Twitch’s new storage limits will purge huge swaths of Internet gaming history Kyle Orland | usagoldm...

Lamborghini catapults into the electrified supercar age with the Revuelto Bradley Iger | usagoldmine...

Mere weeks after Starship’s breakup, the vehicle may soon fly again Eric Berger | usagoldmines.com

Lexar Go SSD with Hub review: Tiny, rugged storage for your phone | usagoldmines.com

I Used This Free Tool to Maximize My Annual PTO Emily Long | usagoldmines.com

This Is the Best Day of the Week to Browse New Home Listings Meredith Dietz | usagoldmines.com

'Beeftext' Is the Best Free Text Replacement Tool for Windows Justin Pot | usagoldmines.com

Eggless Breakfasts to Fuel Your Day (and Spare Your Wallet) Allie Chanthorn Reinmann | usagoldmines....

These Premium Sony Earbuds Are Almost Half Off Right Now Pradershika Sharma | usagoldmines.com

This Is the Ultimate Tool for Setting Up a New Windows Computer Justin Pot | usagoldmines.com

Android's Circle to Search Is Now on iPhone (Kind Of) Pranay Parab | usagoldmines.com

Here Are the New Apple Products We're Still Expecting This Spring Tim Hardwick | usagoldmines.com

Apple Says 'Severance' Is Now More Popular Than 'Ted Lasso' Tim Hardwick | usagoldmines.com

iPhone 15 Pro to Get Visual Intelligence in Future Update, Likely iOS 18.4 Tim Hardwick | usagoldmin...

Amazon Takes $30 Off Apple Pencil Pro and $299 Off Apple Studio Display Mitchel Broussard | usagoldm...

iPhone 15 vs. iPhone 16e Buyer's Guide: 25+ Differences Compared Hartley Charlton | usagoldmines.com

Kuo: All iPhone 17 Models Will Feature Apple-Designed Wi-Fi Chip to 'Enhance Connectivity' Tim Hardw...

UK private health services firm told to pay up $2m for ransomware hit | usagoldmines.com

Apple's careful approach is killing my interest in Apple Intelligence – here's what I want Apple to ...

Microsoft's new 'breakthrough' generative AI model is designed to 'create consistent and diverse gam...

Palo Alto warns another major firewall hack has been detected | usagoldmines.com

Leave a Reply