Microsoft Details New Security Safeguards for Generative AI Models on Azure AI Foundry
## Microsoft Security Enhancements for Generative AI on Azure AI Foundry
Microsoft Security Enhancements for Generative AI on Azure AI Foundry
Microsoft has introduced a comprehensive framework to enhance the security of generative AI models hosted on its Azure AI Foundry platform. This initiative addresses potential vulnerabilities in AI models, which are increasingly targeted as potential vectors for malware delivery.
AI models on Azure function as software applications within Azure Virtual Machines, accessed via APIs. These models adhere to Azure's standard security protocols, including a zero-trust architecture, which ensures no software is inherently trusted. Additionally, customer data is not utilized to train shared AI models, maintaining data privacy and integrity.
Both Azure AI Foundry and Azure OpenAI Service operate on Microsoft's infrastructure, ensuring no external connections during runtime. Fine-tuned models using customer data remain within the customer's own security boundaries.
Models with high visibility undergo a detailed multi-stage scanning process before public release. This includes:
Microsoft has introduced a comprehensive framework to enhance the security of generative AI models hosted on its Azure AI Foundry platform.
Malware Analysis: Scanning for embedded malicious code. Vulnerability Assessment: Identifying known vulnerabilities and zero-day threats. Backdoor Detection: Checking for signs of supply chain tampering and unauthorized code execution. Integrity Checks: Analyzing model components for unauthorized modifications.
Specialized models, such as DeepSeek R1, receive additional scrutiny through source code examination and red team exercises to test against adversarial tactics.
Organizations using AI models through Azure AI Foundry should verify that models carry a scan-complete indicator prior to deployment. It is crucial to apply governance controls according to each model's risk profile and extend zero-trust principles across all AI-integrated pipelines. Conducting internal risk assessments remains essential for evaluating third-party AI models.
Based on reporting by Cyber Security News.
