AI Security Layers: Network, Identity, Data Protection, and AI-specific Controls on AWS
1. AI Security on AWS — Overview
AI workloads require security at multiple layers: data, model, infrastructure, and application.
AI Security Layers:
┌─────────────────────────────────────────┐
│ APPLICATION SECURITY │
│ Guardrails, input validation, │
│ prompt injection prevention │
├─────────────────────────────────────────┤
│ MODEL SECURITY │
│ Model access control, versioning, │
│ model integrity, adversarial defense │
├─────────────────────────────────────────┤
│ DATA SECURITY │
│ Encryption, PII handling, data access │
│ control, audit logging │
├─────────────────────────────────────────┤
│ INFRASTRUCTURE SECURITY │
│ VPC, security groups, endpoints, │
│ network isolation, IAM │
└─────────────────────────────────────────┘
2. IAM for AI/ML Workloads
2.1. IAM for Amazon Bedrock
| Permission | What it controls |
|---|---|
bedrock:InvokeModel | Call a specific FM |
bedrock:InvokeModelWithResponseStream | Streaming model invocation |
bedrock:CreateKnowledgeBase | Create RAG knowledge bases |
bedrock:CreateGuardrail | Create safety guardrails |
bedrock:CreateModelCustomizationJob | Start fine-tuning jobs |
2.2. IAM Best Practices for AI
- Least privilege: Grant only required permissions per role
- Separate roles: Different roles for data scientists, ML engineers, admins
- Resource-based policies: Restrict access to specific models
- Service-linked roles: Let AWS services assume roles as needed
- Condition keys: Restrict by IP, VPC, time, MFA
Exam tip: "How to restrict which foundation models a team can use in Bedrock?" → IAM policy with
bedrock:InvokeModeland resource ARN for specific models.
3. Data Encryption
3.1. Encryption at Rest
| Service | Default Encryption | Custom Key (KMS) |
|---|---|---|
| Amazon Bedrock | AWS-managed key | Customer-managed KMS key |
| SageMaker training | AWS-managed key | Customer-managed KMS key |
| SageMaker notebooks | AWS-managed key | Customer-managed KMS key |
| S3 (training data) | SSE-S3 | SSE-KMS, SSE-C |
| Knowledge Bases vectors | Depends on vector DB | KMS encryption supported |
3.2. Encryption in Transit
- All AWS API calls use TLS 1.2+ by default
- Bedrock API calls are encrypted in transit
- SageMaker endpoints use HTTPS
- Inter-node training communication: encrypted
3.3. AWS KMS for AI
Use AWS KMS when you need:
✓ Control over encryption keys
✓ Key rotation policies
✓ CloudTrail audit of key usage
✓ Cross-account key sharing
✓ Compliance requirements (HIPAA, PCI-DSS)
4. Network Security
4.1. VPC Endpoints for AI Services
VPC endpoints allow private access to AWS AI services — traffic does not traverse the internet.
Without VPC Endpoint:
App in VPC → Internet Gateway → Public Internet → Bedrock API
With VPC Endpoint (PrivateLink):
App in VPC → VPC Endpoint → AWS Private Network → Bedrock API
(no internet!)
| Service | VPC Endpoint Type |
|---|---|
| Amazon Bedrock | Interface (PrivateLink) |
| SageMaker Runtime | Interface (PrivateLink) |
| SageMaker API | Interface (PrivateLink) |
| Amazon S3 | Gateway or Interface |
4.2. SageMaker Network Isolation
- VPC mode: Run training/inference inside your VPC
- Network isolation: No internet access for containers (EnableNetworkIsolation=true)
- Security groups: Control inbound/outbound traffic
- Private subnets: No direct internet access
Exam tip: "How to ensure Bedrock API calls don't traverse the public internet?" → VPC endpoint (AWS PrivateLink) for Amazon Bedrock.
5. PII Detection & Data Privacy
5.1. PII Detection Services
| Service | PII Capability | Data Type |
|---|---|---|
| Amazon Comprehend | Detect and redact PII entities | Text |
| Amazon Macie | Discover PII in S3 buckets | Files in S3 |
| Bedrock Guardrails | Block/anonymize PII in FM I/O | FM prompts/responses |
| AWS Glue DataBrew | PII detection in data pipelines | Structured data |
5.2. Common PII Types for Exam
| PII Type | Examples |
|---|---|
| Direct identifiers | Name, SSN, email, phone, passport number |
| Financial | Credit card number, bank account, tax ID |
| Health | Medical record number, health conditions (PHI) |
| Location | Home address, GPS coordinates |
| Digital | IP address, device ID, login credentials |
6. Amazon Bedrock Security
6.1. Data Privacy in Bedrock
- Data isolation: Your data is NOT used to train base FMs
- Data stays in region: Processed in the AWS region you choose
- Custom models: Fine-tuned models are private to your account
- No data sharing: Your prompts/responses are not shared with model providers
- Encryption: All data encrypted at rest and in transit
6.2. Monitoring & Logging
| Service | What it logs |
|---|---|
| AWS CloudTrail | API calls (who invoked which model, when) |
| Amazon CloudWatch | Model invocation metrics (latency, errors, tokens) |
| Bedrock Model Invocation Logging | Full prompts and responses (to S3 or CloudWatch) |
Exam tip: "How to audit which users are calling Bedrock models?" → CloudTrail. "How to log the actual prompts and responses?" → Bedrock Model Invocation Logging.
7. Compliance & Governance
7.1. AWS Compliance Programs
| Program | What | Relevant AI Services |
|---|---|---|
| SOC 1/2/3 | Security controls audit | Bedrock, SageMaker |
| HIPAA | Healthcare data protection | SageMaker, Comprehend Medical |
| GDPR | EU data privacy | All AWS services (data residency) |
| PCI-DSS | Payment card data security | SageMaker (with controls) |
| FedRAMP | US government cloud security | GovCloud regions |
| ISO 27001 | Information security management | Bedrock, SageMaker |
7.2. Shared Responsibility Model for AI
CUSTOMER responsibility ("Security IN the cloud"):
├── Training data quality and bias
├── Model selection and evaluation
├── Prompt design and guardrails configuration
├── IAM permissions and access control
├── PII handling and data classification
├── Application-level security
└── Compliance with industry regulations
AWS responsibility ("Security OF the cloud"):
├── Physical infrastructure security
├── Network and hardware security
├── Base FM provider management
├── Service availability and reliability
├── Encryption implementation
└── Compliance certifications
8. Data Governance for AI
| Practice | AWS Service |
|---|---|
| Data cataloging | AWS Glue Data Catalog |
| Data classification | Amazon Macie |
| Access control | AWS Lake Formation |
| Data lineage | SageMaker ML Lineage Tracking |
| Data quality | SageMaker Data Wrangler, Glue DataBrew |
9. Practice Questions
Q1: A financial services company wants to use Amazon Bedrock but requires that API calls do NOT traverse the public internet. What should they configure?
- A) AWS Direct Connect
- B) VPC endpoint (AWS PrivateLink) for Bedrock ✓
- C) VPN connection
- D) CloudFront distribution
Explanation: A VPC interface endpoint (PrivateLink) for Amazon Bedrock allows private connectivity from within a VPC without traffic going through the internet.
Q2: According to the AWS Shared Responsibility Model, who is responsible for ensuring training data does not contain bias?
- A) AWS
- B) The foundation model provider
- C) The customer ✓
- D) Both AWS and the customer equally
Explanation: Under the shared responsibility model, customers are responsible for "security IN the cloud" — this includes training data quality, bias detection, and ethical AI practices. AWS is responsible for infrastructure security.
Q3: A company needs to discover which S3 buckets contain personally identifiable information (PII) before using the data for ML training. Which service should they use?
- A) Amazon Comprehend
- B) Amazon Macie ✓
- C) Amazon Inspector
- D) AWS Config
Explanation: Amazon Macie uses machine learning to automatically discover and classify sensitive data (including PII) stored in Amazon S3 buckets. Comprehend detects PII in text, but Macie is designed for S3-level discovery.