Skip to content

Cybersecurity & Secure AI

Controls for isolating and observing AI workloads on NVIDIA platforms: BlueField DPUs with DOCA and DOCA Argus, GPU confidential computing with attestation, and the OpenShell runtime for containing AI agents.

Technology profiles for this category are in research.

Overview

AI systems widen the attack surface: shared GPU clusters host several tenants, model weights are valuable, and agents can run code and reach networks. This category covers NVIDIA technologies for isolating and watching those workloads. None of them guarantees security alone; each is one control inside a wider security program.

BlueField DPUs run networking, storage and security functions apart from the host, which supports tenant isolation, and DOCA is their software platform. DOCA Argus, announced in April 2025, uses memory forensics from BlueField to detect threats without a host agent and can feed SIEM, SOAR and XDR tools. Confidential computing on Hopper, Blackwell and Rubin GPUs protects model weights, data and prompts while in use, with hardware-rooted attestation. OpenShell, at version 0.1.x, sandboxes AI agents and checks their file, network and inference access against policy.

The audience is security architects, cloud operators and teams deploying agents.

For a single-tenant cluster without sensitive data, host hardening, network segmentation and access control may cover most risks before adding DPUs or confidential computing.12345

Problems it addresses

  • Keeping tenants apart1

    Shared AI clouds must stop one tenant reaching another. BlueField keeps workloads and tenants separated with in-silicon enforcement.

  • Runtime detection without host agents2

    Host agents can be disabled by an attacker. DOCA Argus runs on BlueField outside the host and needs no host agent.

  • Protecting models and prompts in use3

    Confidential computing runs GPU work inside a trusted execution environment with attestation.

  • Agents with too much access4

    OpenShell runs each agent in a sandbox without direct network access and grants permissions only through policy.

  • Auditing agent actions4

    OpenShell records each allow and deny decision so it can be audited.

A typical workflow

  1. Write a threat model

    List tenants, assets such as weights and data, and what each agent may touch.

  2. Isolate at the infrastructure layer1

    Use BlueField and DOCA for tenant isolation and hardware-level enforcement.

  3. Monitor at runtime2

    Deploy DOCA Argus and connect it to your SIEM or XDR platform.

  4. Protect data in use3

    Enable GPU confidential computing and verify attestation before releasing secrets.

  5. Contain agents4

    Run agents in OpenShell with policy-as-code and review the audit trail.

NVIDIA Solution Architect

Describe your project and get an explainable architecture.

Open the lab

Next steps

  1. Write a threat model covering tenants, model weights, training data and agent permissions.

  2. Check whether your GPUs, drivers and cloud provider support confidential computing and attestation.

  3. Pilot OpenShell with one internal agent and review its record of allowed and denied actions.

  4. Keep existing controls in place while OpenShell is at an early version.

Sources

  1. NVIDIA BlueField Platform (opens in a new tab)NVIDIA · Vendor-reported
  2. NVIDIA Brings Cybersecurity to Every AI Factory (NVIDIA blog) (opens in a new tab)NVIDIA · Vendor-reported
  3. NVIDIA Confidential Computing (opens in a new tab)NVIDIA · Vendor-reported
  4. NVIDIA OpenShell (opens in a new tab)NVIDIA · Vendor-reported
  5. NVIDIA OpenShell documentation (opens in a new tab)NVIDIA · Vendor-reported

Fill out the form below to request your copy.

Name(Required)