Part III: Platform and service compromise

A model that passed evaluation can still be exposed through acquired software, shared infrastructure, or the identities and interfaces of the running service.

Downloaded models and packages become inputs to a running service. Their origin and integrity matter before deployment, but checks on those files do not establish that a host isolates tenants or that an interface limits access. Chapter 7 examines acquired components, Chapter 8 examines shared infrastructure, and Chapter 9 follows identities, network access, and resource use during operation. Internal and external model arrangements assign different controls and evidence to the organization and its providers.

A titled technical map connects acquired AI components to Chapter 7 trusted component intake, Chapter 8 platform access, Chapter 9 runtime exposure, and a running AI service. It shows source and integrity checks, safe loading, isolated testing, organization and provider duties, interfaces, identities, secrets, network paths, isolation, resource limits, logs, patching, and recovery. Lower strips list boundaries, records, units, and risks.
Figure 1: The dependency chain runs from acquired datasets, models, packages, containers, and skills through component intake, platform access, and runtime exposure. Separate organization, provider, tenant, workload, and network boundaries show where duties and evidence change. The lower fields record identity, age, capacity, and exposure in explicit units. The pictured assignment of hardware and firmware duties applies to an organization operating those layers. In the rented-platform case in Chapter 8, the provider operates them and the organization needs evidence from that provider.

Chapters in this part

  • Supply chain compromise: A model file from the intended supplier can still execute unwanted code during loading or behave harmfully during use.
  • Isolation on shared infrastructure: Data processed by an AI service can be exposed or altered through the platform on which it runs.
  • Runtime intrusion and resource abuse: Exposed interfaces, stolen credentials, unrestricted network access, and excessive work can compromise an AI service or make it unavailable to legitimate users.