cncf / cncf/toc

[Initiative]:Cloud Native AI Security Whitepaper

Open
#1,718 16 comments 0 reactions 0 assignees View on GitHub
kind/initiative kind/publication needs-triage pub/tech-paper tag/security-and-compliance toc toc/initiative/AI
Dominant language
HTML
Stars
1.9k
Forks
724
Avg merge
6d 12h
Merged PRs (30d)
4

Description

### Name

Cloud Native AI Security Whitepaper

### Short description

This whitepaper discusses securing AI workloads, AI Systems in Cloud Native environments

### Responsible group

TOC

### Does the initiative belong to a subproject?

Yes

### Subproject name

Cloud Native AI Working Group

### Primary contact

@dehatideep

### Additional contacts

@zanetworker
@ronaldpetty
@raravena80

### Initiative description

[Cloud Native AI Security Whitepaper](https://docs.google.com/document/d/1uhleMu_HBfkdhLKzxtAephDrvALt5NYaWhZNBPqtt_E/edit?tab=t.0)

The increasing adoption of AI in cloud-native environments presents a compelling case for prioritizing AI security. As AI systems become integral to decision-making and automation, the potential impact from security breaches becomes a critical concern. Compromised AI models can lead to incorrect predictions, manipulated outcomes, and even the theft of sensitive intellectual property. Moreover, regulatory compliance and customers trust are at stake when AI systems are not adequately secured. This paper should aim to address some of these concerns by providing a guide to securing AI in cloud-native environments, offering practical solutions and strategies to mitigate risks and ensure the integrity of AI-powered applications. Along these lines, here are some rough goals/ideas:

Analyze specific security risks unique to cloud-native AI deployments and the potential impact of breaches.
Explore how cloud native security tooling/landscape would make AI workloads more secure. If not, explore how to.
Draft esign considerations for securing AI workloads, data, and infrastructure in cloud-native environments, including Kubernetes security best practices.
Provide actionable guidance on securing AI models, data pipelines, and infrastructure, along with recommendations for secure CI/CD pipelines and vulnerability management.
Exploration emerging trends such as confidential computing, homomorphic encryption, and AI-powered threat detection for cloud-native AI.

AI WG issue link: https://github.com/cncf/tag-runtime/issues/177

### Deliverable(s) or exit criteria

Fully reviewed document by the stakeholders (AI WG and STAG) and finished document after all comments are incorporated.
This is completed on May 21, 2025. Document link provided in the description and it is fully ready.
All meeting minutes and Research and Resources docs are listed on first page in the 'Metadata' section.
This project actively started in Oct 2024 and finished whitepaper document is delivered today (May 21, 2025).

Contributor guide

Open the contributing guide

Research direction

Start with the linked Google Docs whitepaper and AI WG issue #177. Check the document’s Metadata section for meeting minutes and research/resources, then compare it against the listed goals and confirm stakeholder comments are incorporated. Done means the fully reviewed document is ready and all referenced materials are present.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes
Domain
ai, cloud, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.