《人工智能时代的云应用安全:来自 Adobe 和 Fortinet 的经验教训(由 Fortinet 赞助).pdf》由会员分享,可在线阅读,更多相关《人工智能时代的云应用安全:来自 Adobe 和 Fortinet 的经验教训(由 Fortinet 赞助).pdf(40页珍藏版)》请在三个皮匠报告上搜索。
1、 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.H M C 2 0 8-SCloud Application Security in the AI ERA:Lessons from Adobe&FortinetAidan WaldenGlobal Dir.Cloud and AI Engineering,FortinetAmmar AlimHead of DevSecOps,
2、Adobe 2023,Amazon Web Services,Inc.or its affiliates.All rights reserved.Amazon Confidential and Trademark.2023,Amazon Web Services,Inc.or its affiliates.All rights reserved.Amazon Confidential and Trademark.3 2023,Amazon Web Services,Inc.or its affiliates.All rights reserved.Amazon Confidential and
3、 Trademark.4Cloud Application Security in the AI EraAI is transforming how we build,attack,and defendAgentCloud InfraPipelineModelApplicationInfrastructureAPIDataThenNow 2023,Amazon Web Services,Inc.or its affiliates.All rights reserved.Amazon Confidential and Trademark.An adversary obtaining direct
4、 or indirect access or entitlements to AI modelsUnauthorized AccessLogic manipulations,malicious scripts,or command injectionsMalicious PromptsModels that reveal sensitive data when interacting with a threat actorData LeakageManipulating the learning model to degrade performance or introduce vulnera
5、bilitiesModel PoisoningRisks and Concerns with Securing GenAI and LLMs Models 2023,Amazon Web Services,Inc.or its affiliates.All rights reserved.Amazon Confidential and Trademark.6AI introduces new components:models|data pipelines|agents|promptsTraditional“app perimeter”no longer appliesReliability,
6、scale,and security must be re-architectedCamp 1:Fragile SystemsCamp 2:Hardened ArchitecturesThe Shift:AI Is Redefining the Cloud StackAI is transforming how we build,attack,and defendUnvalidated reasoning loopsNo telemetry or observability Data&prompts intermixedNo failure recovery Over-trusted mode