AI 안전애플리케이션 🇨🇳 24.07.2026 14:02

Google Cloud introduces new approach to protecting AI workloads on GKE

Google/DeepMindGoogle/DeepMind Amazon Web ServicesAmazon Web Services MicrosoftMicrosoft Cloud Native Computing FoundationCloud Native Computing Foundation
Google Cloud has published a whitepaper describing a three-tier security system for AI workloads on Google Kubernetes Engine (GKE). The document, aimed at CISOs and platform engineers, covers infrastructure security, model integrity, and application security, including Confidential Nodes, Model Armor, and GKE Sandbox.
Google Cloud가 Google Kubernetes Engine(GKE)에서 실행되는 AI 워크로드를 보호하기 위한 접근 방식을 담은 새 문서를 발표했습니다. Glen Messenger와 Shannon Kularathna가 작성한 이 문서에서는 인프라 보호, 모델 무결성, 애플리케이션 보안의 세 가지 보안 계층 모델을 제시합니다. 주요 대상은 최고정보보안책임자(CISO)와 플랫폼 엔지니어링 팀입니다. 인프라 수준에서는 NVIDIA H100 GPU 및 TPU 가속기를 포함한 하드웨어 메모리 암호화를 제공하는 기밀 GKE 노드(Confidential GKE Nodes) 사용을 권장합니다. 액세스 관리를 위해 Workload Identity Federation과 VPC Service Controls가 제안됩니다. AI 종속성 관리를 위해 오픈소스 Kubernetes 컨트롤러인 k8s-aibom이 도입되어 AI 자재 명세서(AI Bill of Materials)를 자동 생성합니다. 애플리케이션 수준에서는 Model Armor가 프롬프트 인젝션(Prompt Injection)과 데이터 유출을 방지하고, gVisor 기반 GKE Sandbox가 AI 에이전트를 격리합니다. Google은 단계적 구현(Deploy-기본 제어, Operate-보안 강화, Govern-조직 정책)을 설명합니다. 다른 클라우드 제공업체들도 유사한 이니셔티브를 개발 중입니다: AWS는 AI 보안 프레임워크(AI Security Framework)를 제공하고, Microsoft는 Entra Agent ID와 에이전트 테스트 도구 PyRIT를 사용합니다. CNCF는 Kubernetes 자체가 요청의 의미를 이해하지 못하므로 전통적인 역할 기반 액세스 제어(RBAC)와 네트워크 정책만으로는 부족하다고 지적합니다.
출처: InfoQ 中国 — 원문
관련 게시물 ↓
새로운 뉴스