The rapid advancement of artificial intelligence has led to an increased reliance on specialized chips known as accelerators. These chips, distinct from traditional CPUs and GPUs, are designed to handle the specific workloads necessary for AI applications. Key producers in this sector include companies like Tenstorrent, Groq, Cerebras, Graphcore, and Google.
Emergence of Neo-Clouds in AI
Newly emerging ‘neo-clouds’ are transforming the landscape of cloud computing. Unlike conventional hyperscalers such as Azure, Google Cloud, and AWS, neo-clouds are AI-centric and often integrated with these accelerators. They cater specifically to AI tasks such as training, inference, and model development, offering benefits like massive parallel processing capabilities, low latency edge computing, and cost-effective deployment options. Prominent examples of neo-clouds include CoreWeave and Nebius.
Businesses utilize neo-clouds to train large-scale AI models and execute high-throughput AI inference tasks. For instance, an organization might leverage a neo-cloud’s optimized hardware to deliver swift response times for AI-driven chatbots.
Security Challenges in Neo-Clouds
Despite their advantages, both accelerators and neo-clouds present significant security vulnerabilities. Traditional cybersecurity measures, primarily designed for CPU-centric systems, have not evolved to address the unique challenges posed by accelerators. These tools lack the capability to monitor the high-speed memory within accelerator chips, leaving a blind spot in security.
If attackers manage to infiltrate a neo-cloud, the breach may go unnoticed by both the cloud provider and its users. This poses a critical risk, particularly for customers utilizing these clouds for AI development. A recent example of a potential threat was the Januscape malware, which could have exploited these vulnerabilities if it had been more effective.
Stealthium’s Innovative Approach
Stealthium, a startup, is on a mission to address these security gaps. Although it cannot directly monitor accelerators within neo-clouds, it employs an agent within customer infrastructures to detect subtle signs of compromise. Chris Hosking, a GTM Advisor at Stealthium, emphasizes the need for visibility in security, stating that assuming nothing is happening due to the absence of evidence is a dangerous approach.
Stealthium’s strategy involves deploying agents that scrutinize telemetry data from neo-clouds, searching for indicators of compromise. This proactive methodology aims to preemptively identify threats that could lead to cross-tenant data leakage or unauthorized resource utilization.
These supply chain attacks are already a reality and are expected to rise. The potential rewards attract both financially motivated cybercriminals and nation-states seeking to influence or gather information. As Hosking notes, compromising a neo-cloud node could allow attackers to manipulate AI models or conduct illicit activities undetected.
If a powerful entity were to alter AI tools like ChatGPT or Gemini, it could sway public opinion at a national level. The stakes are incredibly high in this emerging threat landscape, and Stealthium represents a pioneering force in securing AI accelerators by analyzing telemetry data to detect and prevent such vulnerabilities.
