Exploding GPUs

Abstract

AI workloads on Kubernetes inherit every cloud native vulnerability. And from GPU mega-clusters training hundred-million-dollar models, to MCP servers acting as universal adapters for autonomous agents, non-deterministic systems create a threat landscape that traditional cloud native security wasn't designed for.

In this talk, we examine the real-world attack surface of AI on Kubernetes: from NVIDIA container escapes and GPU memory side-channels, through tool poisoning and agent trust boundary failures, finishing with the governance gap that leaves critical services exposed.

Using the FINOS AI Readiness Governance Framework, we map controls to infrastructure, demonstrate potential gaps and highlight risk, and demonstrate that securing AI is still fundamentally Kubernetes security, with new crown jewels to protect.


Speaker

Andrew Martin

Founder and CEO @ControlPlane, CISO OpenUK, CNCF Security Advisory Group

Andrew is founder CEO at controlplane.io — securing regulated AI and cloud native systems. Hacking and hardening containers in production since 2014, he is co-author of Hacking Kubernetes (O’Reilly Media, 2022), an international conference and meetup speaker, and delivers training and whitepapers (SANS, Linux Foundation, O’Reilly, eBPF Foundation, Docker, Hashicorp). He is pro bono CISO for non-profit OpenUK.

His clients include Citibank, JPMC, Morgan Stanley, Google, Visa, S&P, PWC, BP, and various governmental departments.

Read more

Date

Tuesday Mar 17 / 10:35AM GMT ( 50 minutes )

Location

Mountbatten (6th Fl.)

Topics

security

Share

From the same track

Session security

Why Governance Matters: The Key to Reducing Risk Without Slowing Down

Tuesday Mar 17 / 03:55PM GMT

When you hear “governance,” you might think of red tape, bureaucracy, or someone telling you what you can’t do. But real governance is about alignment and reducing technical risk. And that matters more than ever.

Speaker image - Sarah Wells

Sarah Wells

Independent Consultant and Author

Session Kernel

Building on Bedrock: A Security Philosophy from Bootloader to Runtime

Tuesday Mar 17 / 11:45AM GMT

In Minecraft, every world is built from blocks. At the very bottom lies bedrock: an unbreakable foundation that everything else rests on. Above it sit layers of stone, dirt, sand, and other materials.

Speaker image - Alex Zenla

Alex Zenla

Founder & CTO @Edera

Session SBOMs

From Chaos to Clarity: Modern SBOM Practices That Actually Work

Tuesday Mar 17 / 01:35PM GMT

In this talk, Viktor will walk you through everything you need to know to build a practical and future ready SBOM strategy.

Speaker image - Viktor Petersson

Viktor Petersson

Founder of sbomify, Co-founder & CEO of Screenly, Host of Nerding Out with Viktor

Session security

Adopting Memory-Safety and Fine-Grained Compartmentalisation With CHERI

Tuesday Mar 17 / 05:05PM GMT

This talk will describe how CHERI achieves memory safety for existing code with just a recompile and how that non-bypassable memory safety can be used as a building block for higher-level security abstractions.

Speaker image - David Chisnall

David Chisnall

Director of System Architecture @SCI Semiconductor, OS, Compiler, and Computer-Architecture Expert, Maintainer of the CHERIoT Platform

Session

Unconference: Software Security & Risk Management

Tuesday Mar 17 / 02:45PM GMT