read-only demo

Videos XjI-AR4pt7Y

Your LLM Stack Is a 2008 Database With Better Marketing — Lovina Dmello, NVIDIA

index_state ready data_status ok

AI Engineer· published 2026-07-20· 0:20:36· en-US· indexed 2026-08-10 19:47

Open on YouTube

Scene timeline

  1. Shot 0, 0:00 to 0:03, 1 of 1 keyframes kept
  2. Shot 1, 0:03 to 0:05, 1 of 1 keyframes kept
  3. Shot 2, 0:05 to 0:12, 1 of 1 keyframes kept
  4. Shot 3, 0:12 to 0:28, 1 of 1 keyframes kept
  5. Shot 4, 0:28 to 1:03, 1 of 1 keyframes kept
  6. Shot 5, 1:03 to 1:33, 1 of 1 keyframes kept
  7. Shot 6, 1:33 to 2:04, 0 of 1 keyframes kept
  8. Shot 7, 2:04 to 2:35, 0 of 1 keyframes kept
  9. Shot 8, 2:35 to 3:05, 0 of 1 keyframes kept
  10. Shot 9, 3:05 to 3:31, 1 of 1 keyframes kept
  11. Shot 10, 3:31 to 3:57, 0 of 1 keyframes kept
  12. Shot 11, 3:57 to 4:23, 0 of 1 keyframes kept
  13. Shot 12, 4:23 to 4:48, 0 of 1 keyframes kept
  14. Shot 13, 4:48 to 5:36, 0 of 1 keyframes kept
  15. Shot 14, 5:36 to 6:02, 1 of 1 keyframes kept
  16. Shot 15, 6:02 to 6:27, 0 of 1 keyframes kept
  17. Shot 16, 6:27 to 6:53, 0 of 1 keyframes kept
  18. Shot 17, 6:53 to 7:20, 1 of 1 keyframes kept
  19. Shot 18, 7:20 to 7:46, 0 of 1 keyframes kept
  20. Shot 19, 7:46 to 8:13, 0 of 1 keyframes kept
  21. Shot 20, 8:13 to 8:22, 1 of 1 keyframes kept
  22. Shot 21, 8:22 to 8:53, 1 of 1 keyframes kept
  23. Shot 22, 8:53 to 9:23, 0 of 1 keyframes kept
  24. Shot 23, 9:23 to 9:54, 0 of 1 keyframes kept
  25. Shot 24, 9:54 to 10:25, 0 of 1 keyframes kept
  26. Shot 25, 10:25 to 10:32, 0 of 1 keyframes kept
  27. Shot 26, 10:32 to 11:01, 0 of 1 keyframes kept
  28. Shot 27, 11:01 to 11:31, 0 of 1 keyframes kept
  29. Shot 28, 11:31 to 12:00, 0 of 1 keyframes kept
  30. Shot 29, 12:00 to 12:29, 0 of 1 keyframes kept
  31. Shot 30, 12:29 to 13:02, 1 of 1 keyframes kept
  32. Shot 31, 13:02 to 13:35, 0 of 1 keyframes kept
  33. Shot 32, 13:35 to 14:07, 0 of 1 keyframes kept
  34. Shot 33, 14:07 to 14:29, 0 of 1 keyframes kept
  35. Shot 34, 14:29 to 15:01, 1 of 1 keyframes kept
  36. Shot 35, 15:01 to 15:33, 0 of 1 keyframes kept
  37. Shot 36, 15:33 to 15:59, 0 of 1 keyframes kept
  38. Shot 37, 15:59 to 16:25, 0 of 1 keyframes kept
  39. Shot 38, 16:25 to 16:52, 1 of 1 keyframes kept
  40. Shot 39, 16:52 to 17:18, 0 of 1 keyframes kept
  41. Shot 40, 17:18 to 17:51, 0 of 1 keyframes kept
  42. Shot 41, 17:51 to 18:23, 0 of 1 keyframes kept
  43. Shot 42, 18:23 to 18:56, 0 of 1 keyframes kept
  44. Shot 43, 18:56 to 19:31, 1 of 1 keyframes kept
  45. Shot 44, 19:31 to 20:05, 0 of 1 keyframes kept
  46. Shot 45, 20:05 to 20:19, 1 of 1 keyframes kept
  47. Shot 46, 20:19 to 20:35, 0 of 1 keyframes kept

47 shot(s).

keyframes kept every frame deduplicated

What was stored

cues
235
whisperx 235
chunks
37
from 235 cues
keyframes
16
kept of 47 captured
frames with text
16
250 lines read
chapters
0
from the source metadata
keyframe bytes
5.8 MB
word timings on 235 cues

Provenance

Each pipeline stage, its state and the model that produced it
stage state model started took
fetch done 2026-08-10 04:07 1m 52s
stt done 2026-08-10 04:09 20s
chunk done 2026-08-10 04:10 0s
text_embed done 2026-08-10 19:47 0s
keyframe done 2026-08-10 04:10 1m 56s
ocr done 2026-08-10 04:11 7s
frame_embed done 2026-08-10 19:47 3s

Frames, and what the machine read

  • 0:02 #0 done2 line(s)

    shot 0·sharpness 453.4

    1. AlEngineer0.96
    2. World's Fair0.97
  • 0:03 #1 done2 line(s)

    shot 1·sharpness 665.7

    1. AlEngineer0.95
    2. World's Fair0.99
  • 0:10 #2 done24 line(s)

    shot 2·sharpness 2743.2

    1. LAB & PLATINUM SPONSORS0.98
    2. Amazon AGI Lab0.98
    3. ANTHROP\C1.00
    4. Google DeepMind1.00
    5. MINIMAX0.94
    6. OpenAI0.92
    7. Akamai1.00
    8. arize1.00
    9. aws1.00
    10. Braintrust bright data0.99
    11. B1.00
    12. Browserbase1.00
    13. docker1.00
    14. :neo4j0.93
    15. ORACLE1.00
    16. PayPal1.00
    17. qodo1.00
    18. reducto1.00
    19. Sonar1.00
    20. Makers of0.99
    21. togetherai1.00
    22. Unblocked1.00
    23. WorkOS1.00
    24. SonarQube1.00
  • 0:17 #3 done2 line(s)

    shot 3·sharpness 127.1

    1. AlEngineer1.00
    2. World's Fair0.96
  • 0:39 #4 done13 line(s)

    shot 4·sharpness 2281.4

    1. AlEngineer0.97
    2. World'sFair1.00
    3. AIENGINEER·SECURITYTRACK·ROOM 20050.99
    4. Your LLM Stack Is a0.99
    5. 2008 Database1.00
    6. PRESENTED BY1.00
    7. Microsoft1.00
    8. With Better Marketing1.00
    9. Why ML security is dominated by misconfiguration, not missing features1.00
    10. Lovina Dmello1.00
    11. Senior Infrastructure Software Engineer· Deep Learning Libraries, NVIDIA0.99
    12. World'sFair0.98
    13. Engineering the future of Al1.00
  • 1:12 #5 done19 line(s)

    shot 5·sharpness 3110.8

    1. AlEngineer0.97
    2. Astory1.00
    3. World'sFair1.00
    4. $1B+ exposed. No zero-day. Just a default left on.1.00
    5. "ShadowRay,"2023: Ray clusters exposed to the open internet with authentication turned0.99
    6. PRESENTED BY1.00
    7. off.1.00
    8. Microsoft1.00
    9. Ray didn't lack a security feature. Operators deployed it with the feature disabled.1.00
    10. It wasn't a clever new attack. The headline ML breaches almost never exploit novel attacks on1.00
    11. models.1.00
    12. • It was the boring stuff. Exposed API keys, overprivileged accounts, model weights in public0.99
    13. buckets.1.00
    14. The whole breach was a checkbox nobody flipped.0.98
    15. Your LLM Stack Is a 2008 Database With Better Marketing1.00
    16. 02/ 170.91
    17. World'sFair0.97
    18. TRACK 5· JUNE 30,20260.96
    19. Security1.00
  • 1:49 #6 skipped

    shot 6·duplicate of #5

  • 2:22 #7 skipped

    shot 7·duplicate of #5

  • 2:59 #8 skipped

    shot 8·duplicate of #5

  • 3:18 #9 done27 line(s)

    shot 9·sharpness 2652.7

    1. AlEngineer0.98
    2. How we got here1.00
    3. World's Fair0.99
    4. We changed everything about the stack except our1.00
    5. assumptions1.00
    6. 20081.00
    7. Today1.00
    8. Now1.00
    9. Classic app1.00
    10. ML in prod0.98
    11. LLM stack1.00
    12. Deterministic code. A perimeter.0.99
    13. Probabilistic behavior, copyable0.99
    14. Prompts as control flow, RAG0.97
    15. One tenant. Security had a clean1.00
    16. weights, shared multi-tenant0.99
    17. corpora, agents the surface0.99
    18. mental model.0.99
    19. GPUs.1.00
    20. explodes again.1.00
    21. The systems got probabilistic, copyable, and multi-tenant. Our security playbook is still deterministic,1.00
    22. perimeter-based,single-tenant.1.00
    23. Your LLM Stack Is a 2008 Database With Better Marketing0.98
    24. 03 / 170.86
    25. World's Fair0.97
    26. TRACK 5· JUNE 30,20260.96
    27. Security1.00
  • 3:34 #10 skipped

    shot 10·duplicate of #9

  • 4:10 #11 skipped

    shot 11·duplicate of #9

  • 4:45 #12 skipped

    shot 12·duplicate of #9

  • 5:30 #13 skipped

    shot 13·duplicate of #5

  • 5:51 #14 done19 line(s)

    shot 14·sharpness 2494.1

    1. AlEngineer0.99
    2. The mental model0.97
    3. World'sFair1.00
    4. Four-pillar defense-in-depth1.00
    5. OPERATIONAL PRACTICES MLSecOps·compliance·incident response·culture1.00
    6. PRESENTED BY1.00
    7. Microsoft1.00
    8. ACCESS CONTROL0.98
    9. RUNTIME SECURITY1.00
    10. auth·authz·multi-tenant1.00
    11. validation·anomaly·logging1.00
    12. INFRASTRUCTURE SECURITY1.00
    13. containers·network segmentation·GPU virtualization·encryption1.00
    14. Infrastructure is the foundation. Get the bottom layer wrong and every layer above it is decoration.0.99
    15. Your LLM Stack Is a 2008 Database With Better Marketing0.98
    16. 05 /170.94
    17. World'sFair0.95
    18. TRACK 5· JUNE 30, 20260.95
    19. Security1.00
  • 6:10 #15 skipped

    shot 15·duplicate of #14

  • 6:45 #16 skipped

    shot 16·duplicate of #14

  • 7:04 #17 done24 line(s)

    shot 17·sharpness 2909.2

    1. AlEngineer0.99
    2. What you're defending against0.99
    3. World'sFair1.00
    4. Six threat categories each needs a stack of defenses0.99
    5. THREAT1.00
    6. PRIMARY DEFENSES1.00
    7. Adversarial inputs1.00
    8. Input validation + adversarial detection1.00
    9. Model extraction1.00
    10. Rate limiting, API auth, query analysis0.98
    11. Data poisoning / supply chain0.99
    12. Secure Cl/CD, model signing, provenance1.00
    13. Privacy breaches1.00
    14. Access control, encryption, audit logs0.99
    15. Infra compromise & DoS0.98
    16. Container isolation, network segmentation1.00
    17. Insider threats1.00
    18. RBAC/ABAC, MFA, behavior analytics1.00
    19. No threat maps to one control. Defense is always a stack: primary + secondary + detection.1.00
    20. Your LLM Stack Is a 2008 Database With Better Marketing0.99
    21. 06 / 170.89
    22. World'sFair0.96
    23. TRACK 5• JUNE 30, 20260.94
    24. Security1.00
  • 7:41 #18 skipped

    shot 18·duplicate of #17

  • 8:10 #19 skipped

    shot 19·duplicate of #17

  • 8:19 #20 done8 line(s)

    shot 20·sharpness 1542.3

    1. AlEngineer0.98
    2. World'sFair0.96
    3. 011.00
    4. Misconfiguration, not missing0.99
    5. features, is the #1 failure mode.0.99
    6. World's Fair0.94
    7. TRACK 5· JUNE 30, 20260.95
    8. Security1.00
  • 8:49 #21 done20 line(s)

    shot 21·sharpness 3037.8

    1. AlEngineer0.97
    2. Core idea 1 ·the evidence0.96
    3. World'sFair1.00
    4. Configuration beats features more reliably than any1.00
    5. attacker1.00
    6. RBAC left at cluster-admin defaults.1.00
    7. 78%0.93
    8. — Network policies absent in > half of clusters.0.97
    9. of reviewed K8s ML deployments had1.00
    10. — Secrets and model artifacts in public buckets.0.99
    11. ≥1 critical misconfiguration0.99
    12. One well-configured cluster Pod Security Standards, network policies, secret management0.99
    13. would prevent more real breaches than every adversarial-defense0.99
    14. technique from the last five years.1.00
    15. Your LLM Stack Is a 2008 Database With Better Marketing0.99
    16. 08 /170.91
    17. GQ0.64
    18. World'sFair0.98
    19. TRACK 5· JUNE 30,20260.95
    20. Security1.00
  • 9:17 #22 skipped

    shot 22·duplicate of #21

  • 9:27 #23 skipped

    shot 23·duplicate of #21

Transcript

235 cues· 2,679 words· 14,701 chars

  1. 0:13 Hi, everyone.
  2. 0:14 So my name is Lavina Demelo.
  3. 0:16 And I'm a senior software developer at NVIDIA.
  4. 0:19 And I work on the deep learning infrastructure team.
  5. 0:22 So the title here is a bit of provocation.
  6. 0:27 What I really mean and what I want you to leave with
  7. 0:31 is for the next 15 minutes, I am going to make one uncomfortable argument, which is almost everything that is breaking in the production ML security isn't some exotic AI attack.
  8. 0:45 It's the same boring infrastructure mistakes that we supposedly fixed years ago.
  9. 0:52 Now, once you look across the research from the whole field, the pattern is very easy.
  10. 1:00 It's very difficult to unsee.
  11. 1:02 Let me start with a story.
  12. 1:04 So in 2023, security researchers went looking at Ray clusters.
  13. 1:12 And Ray is one of the most popular framework for distributed ML.
  14. 1:17 So what they found out over there was there were thousands of clusters that were sitting open on the internet.
  15. 1:26 What that means is the dashboards were open,
  16. 1:30 And there were job APIs that were open.
  17. 1:34 And why that happened?
  18. 1:36 Because authentication was off by default.
  19. 1:39 And somebody just forgot to turn it on while putting the ML in production.
  20. 1:53 So I'm a little bit short, you know.
  21. 1:57 So I need this.
  22. 1:59 Thank you.
  23. 2:00 Okay.
  24. 2:01 So the exposure at that time was a lot.
  25. 2:05 Like, it was over a billion dollars.
  26. 2:08 So now let's sit with this part.
  27. 2:10 This was not a zero-day attack, and it was not a clever new attack.
  28. 2:16 on a neural network.
  29. 2:18 So what happened was somebody just forgot to turn the default setting on while putting them into the production environment.
  30. 2:26 So it just depends upon what the configurations are on different deployment environments in the infrastructure.
  31. 2:34 And when we look at the breaches that actually make the news,
  32. 2:38 What we see, this is not a rule, it's not an exception, but it's almost never the fancy adversarial attack.
  33. 2:45 What is happening is it's maybe like somebody exposed an API key.
  34. 2:51 What happened is maybe some account was just overprivileged.
  35. 2:55 Maybe some model weight was in a public bucket.
  36. 3:00 And the whole bridge, it was just like somebody forgot to flip.
  37. 3:07 So how did we get here?
  38. 3:08 Let's rewind a little bit.
  39. 3:10 So what used to happen is a classic 2008 application was deterministic.
  40. 3:16 So we could reason what the code would exactly do.
  41. 3:21 It had a fixed parameter, and it served one tenant.
  42. 3:25 Security researchers or security team had a clear mental model.
  43. 3:32 like what they need to secure.
  44. 3:34 And great tools were built around that time.
  45. 3:38 So later, what happened is we put these machine learning models into production.
  46. 3:43 And we quietly broke all of the three assumptions because behaviors became probabilistic.
  47. 3:51 Correct is a distribution now.
  48. 3:52 It is not one branch, like we say yes or no.
  49. 3:56 And then we are protecting the weights, which the weights itself are copyable.
  50. 4:03 And the leaks are straight through the API that we are trying to serve.

Open at this second