Videos XjI-AR4pt7Y
Your LLM Stack Is a 2008 Database With Better Marketing — Lovina Dmello, NVIDIA
Scene timeline
47 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 235
- whisperx 235
- chunks
- 37
- from 235 cues
- keyframes
- 16
- kept of 47 captured
- frames with text
- 16
- 250 lines read
- chapters
- 0
- from the source metadata
- keyframe bytes
- 5.8 MB
- word timings on 235 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 04:07 | 1m 52s |
stt |
done | — | 2026-08-10 04:09 | 20s |
chunk |
done | — | 2026-08-10 04:10 | 0s |
text_embed |
done | — | 2026-08-10 19:47 | 0s |
keyframe |
done | — | 2026-08-10 04:10 | 1m 56s |
ocr |
done | — | 2026-08-10 04:11 | 7s |
frame_embed |
done | — | 2026-08-10 19:47 | 3s |
Frames, and what the machine read
-
- AlEngineer0.96
- World's Fair0.97
-
- AlEngineer0.95
- World's Fair0.99
-
- LAB & PLATINUM SPONSORS0.98
- Amazon AGI Lab0.98
- ANTHROP\C1.00
- Google DeepMind1.00
- MINIMAX0.94
- OpenAI0.92
- Akamai1.00
- arize1.00
- aws1.00
- Braintrust bright data0.99
- B1.00
- Browserbase1.00
- docker1.00
- :neo4j0.93
- ORACLE1.00
- PayPal1.00
- qodo1.00
- reducto1.00
- Sonar1.00
- Makers of0.99
- togetherai1.00
- Unblocked1.00
- WorkOS1.00
- SonarQube1.00
-
- AlEngineer1.00
- World's Fair0.96
-
- AlEngineer0.97
- World'sFair1.00
- AIENGINEER·SECURITYTRACK·ROOM 20050.99
- Your LLM Stack Is a0.99
- 2008 Database1.00
- PRESENTED BY1.00
- Microsoft1.00
- With Better Marketing1.00
- Why ML security is dominated by misconfiguration, not missing features1.00
- Lovina Dmello1.00
- Senior Infrastructure Software Engineer· Deep Learning Libraries, NVIDIA0.99
- World'sFair0.98
- Engineering the future of Al1.00
-
- AlEngineer0.97
- Astory1.00
- World'sFair1.00
- $1B+ exposed. No zero-day. Just a default left on.1.00
- "ShadowRay,"2023: Ray clusters exposed to the open internet with authentication turned0.99
- PRESENTED BY1.00
- off.1.00
- Microsoft1.00
- Ray didn't lack a security feature. Operators deployed it with the feature disabled.1.00
- It wasn't a clever new attack. The headline ML breaches almost never exploit novel attacks on1.00
- models.1.00
- • It was the boring stuff. Exposed API keys, overprivileged accounts, model weights in public0.99
- buckets.1.00
- The whole breach was a checkbox nobody flipped.0.98
- Your LLM Stack Is a 2008 Database With Better Marketing1.00
- 02/ 170.91
- World'sFair0.97
- TRACK 5· JUNE 30,20260.96
- Security1.00
-
- AlEngineer0.98
- How we got here1.00
- World's Fair0.99
- We changed everything about the stack except our1.00
- assumptions1.00
- 20081.00
- Today1.00
- Now1.00
- Classic app1.00
- ML in prod0.98
- LLM stack1.00
- Deterministic code. A perimeter.0.99
- Probabilistic behavior, copyable0.99
- Prompts as control flow, RAG0.97
- One tenant. Security had a clean1.00
- weights, shared multi-tenant0.99
- corpora, agents the surface0.99
- mental model.0.99
- GPUs.1.00
- explodes again.1.00
- The systems got probabilistic, copyable, and multi-tenant. Our security playbook is still deterministic,1.00
- perimeter-based,single-tenant.1.00
- Your LLM Stack Is a 2008 Database With Better Marketing0.98
- 03 / 170.86
- World's Fair0.97
- TRACK 5· JUNE 30,20260.96
- Security1.00
-
- AlEngineer0.99
- The mental model0.97
- World'sFair1.00
- Four-pillar defense-in-depth1.00
- OPERATIONAL PRACTICES MLSecOps·compliance·incident response·culture1.00
- PRESENTED BY1.00
- Microsoft1.00
- ACCESS CONTROL0.98
- RUNTIME SECURITY1.00
- auth·authz·multi-tenant1.00
- validation·anomaly·logging1.00
- INFRASTRUCTURE SECURITY1.00
- containers·network segmentation·GPU virtualization·encryption1.00
- Infrastructure is the foundation. Get the bottom layer wrong and every layer above it is decoration.0.99
- Your LLM Stack Is a 2008 Database With Better Marketing0.98
- 05 /170.94
- World'sFair0.95
- TRACK 5· JUNE 30, 20260.95
- Security1.00
-
- AlEngineer0.99
- What you're defending against0.99
- World'sFair1.00
- Six threat categories each needs a stack of defenses0.99
- THREAT1.00
- PRIMARY DEFENSES1.00
- Adversarial inputs1.00
- Input validation + adversarial detection1.00
- Model extraction1.00
- Rate limiting, API auth, query analysis0.98
- Data poisoning / supply chain0.99
- Secure Cl/CD, model signing, provenance1.00
- Privacy breaches1.00
- Access control, encryption, audit logs0.99
- Infra compromise & DoS0.98
- Container isolation, network segmentation1.00
- Insider threats1.00
- RBAC/ABAC, MFA, behavior analytics1.00
- No threat maps to one control. Defense is always a stack: primary + secondary + detection.1.00
- Your LLM Stack Is a 2008 Database With Better Marketing0.99
- 06 / 170.89
- World'sFair0.96
- TRACK 5• JUNE 30, 20260.94
- Security1.00
-
- AlEngineer0.98
- World'sFair0.96
- 011.00
- Misconfiguration, not missing0.99
- features, is the #1 failure mode.0.99
- World's Fair0.94
- TRACK 5· JUNE 30, 20260.95
- Security1.00
-
- AlEngineer0.97
- Core idea 1 ·the evidence0.96
- World'sFair1.00
- Configuration beats features more reliably than any1.00
- attacker1.00
- RBAC left at cluster-admin defaults.1.00
- 78%0.93
- — Network policies absent in > half of clusters.0.97
- of reviewed K8s ML deployments had1.00
- — Secrets and model artifacts in public buckets.0.99
- ≥1 critical misconfiguration0.99
- One well-configured cluster Pod Security Standards, network policies, secret management0.99
- would prevent more real breaches than every adversarial-defense0.99
- technique from the last five years.1.00
- Your LLM Stack Is a 2008 Database With Better Marketing0.99
- 08 /170.91
- GQ0.64
- World'sFair0.98
- TRACK 5· JUNE 30,20260.95
- Security1.00
Transcript
235 cues· 2,679 words· 14,701 chars
- 0:13 Hi, everyone.
- 0:14 So my name is Lavina Demelo.
- 0:16 And I'm a senior software developer at NVIDIA.
- 0:19 And I work on the deep learning infrastructure team.
- 0:22 So the title here is a bit of provocation.
- 0:27 What I really mean and what I want you to leave with
- 0:31 is for the next 15 minutes, I am going to make one uncomfortable argument, which is almost everything that is breaking in the production ML security isn't some exotic AI attack.
- 0:45 It's the same boring infrastructure mistakes that we supposedly fixed years ago.
- 0:52 Now, once you look across the research from the whole field, the pattern is very easy.
- 1:00 It's very difficult to unsee.
- 1:02 Let me start with a story.
- 1:04 So in 2023, security researchers went looking at Ray clusters.
- 1:12 And Ray is one of the most popular framework for distributed ML.
- 1:17 So what they found out over there was there were thousands of clusters that were sitting open on the internet.
- 1:26 What that means is the dashboards were open,
- 1:30 And there were job APIs that were open.
- 1:34 And why that happened?
- 1:36 Because authentication was off by default.
- 1:39 And somebody just forgot to turn it on while putting the ML in production.
- 1:53 So I'm a little bit short, you know.
- 1:57 So I need this.
- 1:59 Thank you.
- 2:00 Okay.
- 2:01 So the exposure at that time was a lot.
- 2:05 Like, it was over a billion dollars.
- 2:08 So now let's sit with this part.
- 2:10 This was not a zero-day attack, and it was not a clever new attack.
- 2:16 on a neural network.
- 2:18 So what happened was somebody just forgot to turn the default setting on while putting them into the production environment.
- 2:26 So it just depends upon what the configurations are on different deployment environments in the infrastructure.
- 2:34 And when we look at the breaches that actually make the news,
- 2:38 What we see, this is not a rule, it's not an exception, but it's almost never the fancy adversarial attack.
- 2:45 What is happening is it's maybe like somebody exposed an API key.
- 2:51 What happened is maybe some account was just overprivileged.
- 2:55 Maybe some model weight was in a public bucket.
- 3:00 And the whole bridge, it was just like somebody forgot to flip.
- 3:07 So how did we get here?
- 3:08 Let's rewind a little bit.
- 3:10 So what used to happen is a classic 2008 application was deterministic.
- 3:16 So we could reason what the code would exactly do.
- 3:21 It had a fixed parameter, and it served one tenant.
- 3:25 Security researchers or security team had a clear mental model.
- 3:32 like what they need to secure.
- 3:34 And great tools were built around that time.
- 3:38 So later, what happened is we put these machine learning models into production.
- 3:43 And we quietly broke all of the three assumptions because behaviors became probabilistic.
- 3:51 Correct is a distribution now.
- 3:52 It is not one branch, like we say yes or no.
- 3:56 And then we are protecting the weights, which the weights itself are copyable.
- 4:03 And the leaks are straight through the API that we are trying to serve.
loading