1 of 13

Secure OSS AI Infrastructure with Tsunami Network Scanner

​

Andrey Kovalev

avkov@google.com

1

2 of 13

Agenda

  1. Tsunami 101
  2. AI Infrastructure & security risks
  3. New approach for plugin development

​

2

2

3 of 13

Tsunami 101

3

4 of 13

Tsunami

Find vulns in minutes

Be false positive free

Focus on critical vulns

Deploy new detectors fast

Keep it open source

4

4

5 of 13

Tsunami architecture

Tsunami scan consists of 2 parts:

Reconnaissance: identifies open ports, protocols, services and other software running on the target

​

Vulnerability verification: selects relevant detectors to run for each service which verifies if a vulnerability exists

5

5

6 of 13

AI Infrastructure

& security risks

6

7 of 13

AI risks in Tsunami scope

Generation

Serving

Data preprocessing

Training and evaluation

Data sources

Serving

Applications

Model storage

  • RCE
  • Model temering
  • Model exfiltration
  • Data leakage
  • Model exfiltration
  • Model temering
  • Data poisoning
  • Data exfiltration
  • RCE
  • Data poisoning
  • Model tempering
  • Data exfiltration
  • Denial of ML

Generation

Data storage

Data preprocessing

Training and evaluation

7

7

8 of 13

Popular AI Frameworks and serving platforms

8

8

9 of 13

Example of the RCE vulnerability in Ray.IO

curl -H 'Content-Type: application/json' -d '{"entrypoint":"echo hello"}' -X POST "http://127.0.0.1:8265/api/jobs/" creates a new job to execute the command:

{"job_id": "raysubmit_C4TMa9eH8vfHcDri", "submission_id": "raysubmit_C4TMa9eH8vfHcDri"}

​

9

9

10 of 13

New approach for

plugin development

10

11 of 13

New plugin development workflow

11

11

12 of 13

Internet CTF Preview

12

12

13 of 13

Thank you!

Subscribe for more updates

13