Are you equipped to handle the AI sprawl that’s coming your way? Our new hands-on lab, Securing AI/ML Workloads, can help you get there! Kubernetes adoption in AI continues to grow because of its ability to orchestrate complex workloads and optimize resource usage, making it a natural choice for AI and machine learning environments. As teams deploy more GPU-intensive and data-driven workloads, Kubernetes provides the flexibility to schedule, isolate, and monitor these jobs across shared infrastructure. This shift introduces new challenges for security teams. AI and ML workloads often involve sensitive data, large-scale data movement and high-performance compute nodes that require secure communication between components. Network security in Kubernetes is no longer limited to isolating services. It now includes protecting model training pipelines, securing inter-node traffic and enforcing policies that ensure data confidentiality and compliance. Administrators now need to think about data poisoning, Prompt injection, and various other threats. Building a security-first Kubernetes environment for AI and ML workloads requires balancing performance with protection. Teams must safeguard workloads while preserving the agility and scalability that make Kubernetes effective in the first place. At Isovalent we understand that AI and ML workloads intersect with every part of the platform, from data pipelines to networking to access controls. Securing the network remains central to enabling these workloads, and Isovalent helps organizations strengthen their Kubernetes environments to support secure high-performance AI strategies. This is why we’ve created a new hands-on lab, Securing AI/ML Workloads with Isovalent! This self paced lab is now available, featuring ways to navigate common threats to AI systems. In this lab, you will learn how to build a comprehensive, security-first Kubernetes environment with Isovalent Networking for Kubernetes and Isovalent Runtime Security that will demonstrate best practices for AI workload protection. This lab is use-case centric; and will walk you through how to use encrypted networking, controlled data access, runtime monitoring, and API security to help you identify and isolate threats like data poisoning. At the end of the lab, you’ll be able to test your skills and earn a Credly badge; certified by Isovalent. How Can We Secure AI Systems Against Evolving Threats? The MITRE Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS) Framework is a knowledge base that documents tactics, techniques, and procedures used in attacks against machine learning systems. It helps security teams understand how ML models can be targeted, assess vulnerabilities, and develop defenses. ATLAS is modeled after the original MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK). In our new hands-on lab; these are the techniques you’ll walk through mitigating: AML.T0018: Backdoor ML Model - File integrity monitoring detects training data tampering AML.T0010: ML Supply Chain Compromise - FQDN policies prevent malicious data ingestion AML.T0015: Data and Model Poisoning - File monitoring prevents dataset tampering At the same time, OWASP (Open Worldwide Application Security Project) maintains a list of the most critical security risks in LLM applications. Part of this list is an LLM Top 10, which documents the top 10 risks and mitigation measures for LLMs. Working with LLMs is becoming more and more popular, and it’s important to keep up to date with how to provide a robust system to allow your organization to do their best work. In the lab, you’ll use Cilium and Tetragon to help mitigate against: LLM01: Prompt Injection - Network policies restrict dangerous AI API endpoints LLM03: Supply Chain - Tracing policies control model and data sources LLM04: Data and Model Poisoning - File monitoring prevents dataset tampering Paired with the MITRE ATLAS knowledge base, this provides a great framework to help organizations secure their platforms for AI/ML workloads. This lab will go through how to use Cilium and Tetragon by Isovalent to use the framework to gaurd against actual vulnerabilities that have compromised AI systems in production like PoisonGPT Attack (2023), PyTorch Supply Chain Attack (2022), and Probllama CVE-2024-370032 (2024). Modern AI/ML Usecases In this lab, we explore running AI and machine learning workloads on Kubernetes using Cilium. You start by setting up a cluster with Cilium networking and configuring L2 announcements for LoadBalancer services. Then, as part of the lab you deploy a neural network trained on the MNIST dataset to recognize handwritten digits and expose it through a Flask API for real-time predictions. Cilium provides advanced networking, load balancing, and observability through Hubble (which provides real-time observability into network, security, and application behavior), letting you see every network interaction and monitor performance. This approach shows how eBPF-powered networking can support AI workloads efficiently while maintaining security, both at low overhead. By following practices inspired by MITRE ATLAS and considering risks from the OWASP Top LLM 10, you learn how to protect models from adversarial inputs and data exfiltration. Data poisoning attacks manipulate training datasets and compromise ML model behavior. Common techniques include label flipping, backdoor insertion, and malicious sample injection. In this new lab, you’ll get a look on how training data manipulation attacks work and use Tetragon's File Integrity Monitoring (FIM), which monitors and detects unauthorized changes to files and directories, to detect suspicious file operations that could indicate data tampering and actively work against data poisoning as part of this lab! This hands-on experience demonstrates how to take AI workloads from development to production with visibility and safety built in. Even if you’re not familiar or not running AI/ML, this lab provides a good introduction into AI and AI infrastructure. Getting Started Kubernetes enables powerful AI and ML workloads, but securing these environments requires careful attention to data, networking, and compute resources. The Securing AI/ML Workloads with Isovalent lab offers a hands-on way to learn practical strategies for protecting AI pipelines using Isovalent Networking for Kubernetes and Isovalent Runtime Security, utilizing Cilium, Tetagon, MITRE ATLAS, and OWASP guidance. Ready for more? Explore self-guided hands-on labs on security, networking and observability for deep dive into Isovalent and Cilium products by visiting isovalent.com/labs/. You can also visit our interactive map or our learning paths if you prefer a more guided learning experience with our labs. We’d love feedback! Try out our new AI Lab and let us know what you think, and earn a Credly badge certified by Isovalent.