Last week I gave my first major external conference talk at BSides Seattle, and somehow didn’t mass kubectl delete my career in the process.
The talk was called “Zero Trust in the Matrix: Hardening Kubernetes for the AI Frontier”—25 minutes of me explaining why your ML infrastructure is likely more exposed than you think, and what to actually do about it. Yes, the Matrix references were intentional. No, I did not show up in a trench coat (though I considered it).
📥 Download the slides (GitHub)
First Talk Jitters (and Why BSides is Great)
I’ll be honest—I was nervous. The kind of nervous where you triple-check your slides at 2 AM and then again at 6 AM “just in case the bits decayed overnight.”
But the BSides community made it easy. People were genuinely helpful and motivating, asked thoughtful questions, and nobody heckled me when I fumbled a slide transition. (The bar for success was low, and I cleared it.)
A few folks came up afterward to chat about their own K8s security struggles, which reminded me why I wanted to do this in the first place—sharing hard-won lessons so others don’t have to learn them the painful way.
Verdict: 10/10, would public-speak again. Already eyeing CFPs for later this year.
The Core Problem
When you run AI on Kubernetes, you’re dealing with assets worth millions—trained models, proprietary data, fine-tuning that took weeks of GPU time. But here’s what breaks traditional security thinking:
In normal software, code and data are separate. You write code, it processes data. Clear boundary.
With AI? That model file is code. That prompt is code. The data you feed into RAG becomes instructions.
Or as I put it in the talk: “What happens when you plug an LLM into the Matrix? It doesn’t just query your data—it can be reprogrammed by it.”
This isn’t theoretical. I covered real attacks happening in the wild.
Key Topics Covered
1. Infrastructure Exposure (or: “Why Is This Port Open?”)
Remember ShadowRay? Thousands of Ray clusters compromised in 2024—not through sophisticated exploits, but because the Ray Dashboard (port 8265) has no authentication by default. One curl command = job submission to your entire GPU cluster.
The attacker doesn’t even need to do lateral movement. Ray does it for them. Your distributed computing framework becomes their botnet. Efficiency!
The fix isn’t complicated: NetworkPolicies with default-deny. Thirty minutes of work that blocks 80% of lateral movement. But most deployments I see? Wide open, like a Kubernetes cluster that took “open source” too literally.
2. The Pickle Problem (Not the Cucumber Kind)
That .pt model file you downloaded from Hugging Face? It’s not data—it’s executable code.
Python’s pickle format is basically a stack-based virtual machine. When you call torch.load(), it doesn’t just deserialize—it executes whatever’s in that file. Before you can inspect it. Before you can say “wait, what?”
So that “Llama-3-Finance-Optimized” model some helpful stranger uploaded? You’re running arbitrary code from the internet. Your security team is crying somewhere, and they don’t even know why yet.
The solution: SafeTensors format (no executable capability), model signing with Sigstore, and scanning with PickleScan before loading anything. Treat models like container images—you wouldn’t run an unsigned image in prod. Same rules apply.
3. RAG Poisoning & Indirect Prompt Injection
In RAG architectures, data becomes instructions. Here’s the attack:
- Attacker plants a document with malicious instructions
- It gets indexed into your vector DB
- User asks an innocent question
- RAG retrieves the poisoned chunk as “context”
- LLM executes those instructions
The LLM can’t distinguish between “context” and “commands.” It’s all just tokens in the context window. And if your agent has tools—email, code execution, API access—those instructions can do things.
My favorite example: white text on white background in a PDF resume. Hidden from humans, visible to the parser. Your HR bot processes it, retrieves the chunk, and suddenly it’s exfiltrating conversation history. The user never typed anything malicious. The attack came through the data.
(Someone in the audience audibly sighed at this point. I felt that.)
4. Identity & Exfiltration
Workload Identity is table stakes in 2026. No more static credentials in K8s secrets. But here’s the thing: workload identity doesn’t fix overprivilege—it just makes the overprivilege short-lived.
I walked through the “Shadow Admin” attack: container compromise → federated token → az login → if the identity has Contributor on the subscription, game over. Container escape becomes full cloud takeover.
The fix? Least privilege. Your ML workload needs to read from blob storage? Give it Storage Blob Data Reader. Not Contributor. Not Owner. Exactly what it needs, nothing more.
The Monday Checklist
If you missed the talk, here’s what to do this week:
| Layer | Action |
|---|---|
| Infrastructure | Network policies (default-deny), mTLS, no exposed dashboards |
| Supply Chain | SafeTensors format, PickleScan, sign models with Sigstore |
| Identity | Workload Identity, least privilege, audit everything |
| Data Flow | Sanitize RAG inputs, prompt guardrails, lock down egress |
If you can only do one thing: Implement default-deny network policies for your ML workloads. Thirty minutes of effort, 80% risk reduction.
Or as I closed the talk: “Don’t just deploy AI. Secure the Matrix.”
(Yes, I said it with a straight face. Yes, it worked.)
What’s Next
I’m continuing to research AI infrastructure security—specifically looking at inference frameworks, sandbox isolation in code interpreters, and the authentication boundaries (or lack thereof) in model serving platforms.
More findings to share soon. I practice responsible disclosure, so technical details come after vendor coordination. (Translation: I have spicy findings that I can’t talk about yet. Stay tuned.)
BSides Seattle was a blast, and it definitely won’t be my last conference talk. If you’re thinking about submitting to a CFP but feel like an imposter—do it anyway. The community is welcoming, the feedback is valuable, and the worst case is you learn something.
If you’re working on similar problems or want to chat about K8s security, find me on LinkedIn
Thanks to the BSides Seattle organizers for putting on a great event, and to everyone who attended, asked questions, and didn’t judge my slide transitions. See you at the next one. 🖖