"Uncovering Multitenancy Issues in AI-as-a-Service Providers"

No ratings

Presented at POC 2024 by

The demand for AI services has increased dramatically in recent years, as companies and organizations rush to enhance their offerings with AI capabilities. AI-as-a-Service providers help facilitate this demand by offering scalable cloud-based infrastructure. As a result of their business model, AI-as-a-Service providers face a significant security challenge: They must handle potentially untrusted inputs, in the form of AI models, within a multi-tenant environment. Over the past year, our team has been researching popular AI-as-a-Service platforms with key questions in mind: Could a determined attacker hack their way into the private AI models of industry leading companies? What unique attack surface do these services expose? In this session, we will discuss the security concerns faced by multi-tenant AI-as-a-Service providers. To illustrate our findings, we'll examine a case study based on our recent research into Hugging Face, a leading platform in the AI industry. Together, we'll craft a malicious AI model to achieve Remote Code Execution on the platform's underlying infrastructure, exploit a Kubernetes misconfiguration to escape our container, and eventually reach the stage where we could potentially compromise all models hosted on the platform. Additionally, we'll discuss our collaboration with Hugging Face to address the issues we uncovered.