Chuyển đến nội dung chính

Bài 11: AI Security, Data Privacy & Compliance on AWS

IAM cho AI/ML workloads. Encryption at rest & in transit. VPC endpoints cho Bedrock/SageMaker. PII detection. AWS compliance programs. Data governance cho AI.

AI Security Layers on AWS

AI Security Layers: Network, Identity, Data Protection và AI-specific Controls trên AWS

1. AI Security on AWS — Overview

AI workloads cần bảo mật ở nhiều layers: data, model, infrastructure, và application.

AI Security Layers:
┌─────────────────────────────────────────┐
│  APPLICATION SECURITY                   │
│  Guardrails, input validation,          │
│  prompt injection prevention            │
├─────────────────────────────────────────┤
│  MODEL SECURITY                         │
│  Model access control, versioning,      │
│  model integrity, adversarial defense   │
├─────────────────────────────────────────┤
│  DATA SECURITY                          │
│  Encryption, PII handling, data access  │
│  control, audit logging                 │
├─────────────────────────────────────────┤
│  INFRASTRUCTURE SECURITY                │
│  VPC, security groups, endpoints,       │
│  network isolation, IAM                 │
└─────────────────────────────────────────┘

2. IAM for AI/ML Workloads

2.1. IAM for Amazon Bedrock

PermissionWhat it controls
bedrock:InvokeModelCall a specific FM
bedrock:InvokeModelWithResponseStreamStreaming model invocation
bedrock:CreateKnowledgeBaseCreate RAG knowledge bases
bedrock:CreateGuardrailCreate safety guardrails
bedrock:CreateModelCustomizationJobStart fine-tuning jobs

2.2. IAM Best Practices for AI

  • Least privilege: Grant only required permissions per role
  • Separate roles: Different roles for data scientists, ML engineers, admins
  • Resource-based policies: Restrict access to specific models
  • Service-linked roles: Let AWS services assume roles as needed
  • Condition keys: Restrict by IP, VPC, time, MFA

Exam tip: "How to restrict which foundation models a team can use in Bedrock?" → IAM policy with bedrock:InvokeModel and resource ARN for specific models.

3. Data Encryption

3.1. Encryption at Rest

ServiceDefault EncryptionCustom Key (KMS)
Amazon BedrockAWS-managed keyCustomer-managed KMS key
SageMaker trainingAWS-managed keyCustomer-managed KMS key
SageMaker notebooksAWS-managed keyCustomer-managed KMS key
S3 (training data)SSE-S3SSE-KMS, SSE-C
Knowledge Bases vectorsDepends on vector DBKMS encryption supported

3.2. Encryption in Transit

  • All AWS API calls use TLS 1.2+ by default
  • Bedrock API calls are encrypted in transit
  • SageMaker endpoints use HTTPS
  • Inter-node training communication: encrypted

3.3. AWS KMS for AI

Use AWS KMS when you need:
✓ Control over encryption keys
✓ Key rotation policies
✓ CloudTrail audit of key usage
✓ Cross-account key sharing
✓ Compliance requirements (HIPAA, PCI-DSS)

4. Network Security

4.1. VPC Endpoints for AI Services

VPC endpoints cho phép truy cập AWS AI services privately — traffic không qua internet.

Without VPC Endpoint:
App in VPC → Internet Gateway → Public Internet → Bedrock API

With VPC Endpoint (PrivateLink):
App in VPC → VPC Endpoint → AWS Private Network → Bedrock API
             (no internet!)
ServiceVPC Endpoint Type
Amazon BedrockInterface (PrivateLink)
SageMaker RuntimeInterface (PrivateLink)
SageMaker APIInterface (PrivateLink)
Amazon S3Gateway or Interface

4.2. SageMaker Network Isolation

  • VPC mode: Run training/inference inside your VPC
  • Network isolation: No internet access for containers (EnableNetworkIsolation=true)
  • Security groups: Control inbound/outbound traffic
  • Private subnets: No direct internet access

Exam tip: "How to ensure Bedrock API calls don't traverse the public internet?" → VPC endpoint (AWS PrivateLink) for Amazon Bedrock.

5. PII Detection & Data Privacy

5.1. PII Detection Services

ServicePII CapabilityData Type
Amazon ComprehendDetect and redact PII entitiesText
Amazon MacieDiscover PII in S3 bucketsFiles in S3
Bedrock GuardrailsBlock/anonymize PII in FM I/OFM prompts/responses
AWS Glue DataBrewPII detection in data pipelinesStructured data

5.2. Common PII Types for Exam

PII TypeExamples
Direct identifiersName, SSN, email, phone, passport number
FinancialCredit card number, bank account, tax ID
HealthMedical record number, health conditions (PHI)
LocationHome address, GPS coordinates
DigitalIP address, device ID, login credentials

6. Amazon Bedrock Security

6.1. Data Privacy in Bedrock

  • Data isolation: Your data is NOT used to train base FMs
  • Data stays in region: Processed in the AWS region you choose
  • Custom models: Fine-tuned models are private to your account
  • No data sharing: Your prompts/responses are not shared with model providers
  • Encryption: All data encrypted at rest and in transit

6.2. Monitoring & Logging

ServiceWhat it logs
AWS CloudTrailAPI calls (who invoked which model, when)
Amazon CloudWatchModel invocation metrics (latency, errors, tokens)
Bedrock Model Invocation LoggingFull prompts and responses (to S3 or CloudWatch)

Exam tip: "How to audit which users are calling Bedrock models?" → CloudTrail. "How to log the actual prompts and responses?" → Bedrock Model Invocation Logging.

7. Compliance & Governance

7.1. AWS Compliance Programs

ProgramWhatRelevant AI Services
SOC 1/2/3Security controls auditBedrock, SageMaker
HIPAAHealthcare data protectionSageMaker, Comprehend Medical
GDPREU data privacyAll AWS services (data residency)
PCI-DSSPayment card data securitySageMaker (with controls)
FedRAMPUS government cloud securityGovCloud regions
ISO 27001Information security managementBedrock, SageMaker

7.2. Shared Responsibility Model for AI

CUSTOMER responsibility ("Security IN the cloud"):
├── Training data quality and bias
├── Model selection and evaluation
├── Prompt design and guardrails configuration
├── IAM permissions and access control
├── PII handling and data classification
├── Application-level security
└── Compliance with industry regulations

AWS responsibility ("Security OF the cloud"):
├── Physical infrastructure security
├── Network and hardware security
├── Base FM provider management
├── Service availability and reliability
├── Encryption implementation
└── Compliance certifications

8. Data Governance for AI

PracticeAWS Service
Data catalogingAWS Glue Data Catalog
Data classificationAmazon Macie
Access controlAWS Lake Formation
Data lineageSageMaker ML Lineage Tracking
Data qualitySageMaker Data Wrangler, Glue DataBrew

9. Practice Questions

Q1: A financial services company wants to use Amazon Bedrock but requires that API calls do NOT traverse the public internet. What should they configure?

  • A) AWS Direct Connect
  • B) VPC endpoint (AWS PrivateLink) for Bedrock ✓
  • C) VPN connection
  • D) CloudFront distribution

Explanation: A VPC interface endpoint (PrivateLink) for Amazon Bedrock allows private connectivity from within a VPC without traffic going through the internet.

Q2: According to the AWS Shared Responsibility Model, who is responsible for ensuring training data does not contain bias?

  • A) AWS
  • B) The foundation model provider
  • C) The customer ✓
  • D) Both AWS and the customer equally

Explanation: Under the shared responsibility model, customers are responsible for "security IN the cloud" — this includes training data quality, bias detection, and ethical AI practices. AWS is responsible for infrastructure security.

Q3: A company needs to discover which S3 buckets contain personally identifiable information (PII) before using the data for ML training. Which service should they use?

  • A) Amazon Comprehend
  • B) Amazon Macie ✓
  • C) Amazon Inspector
  • D) AWS Config

Explanation: Amazon Macie uses machine learning to automatically discover and classify sensitive data (including PII) stored in Amazon S3 buckets. Comprehend detects PII in text, but Macie is designed for S3-level discovery.