Stop “securing the model”—Secure the runtime instead
“Securing the AI model” sounds like a clean, fundable story. In practice, it’s often the wrong security target. In this episode of Pop Goes the Stack, F5's Lori MacVittie and Joel Moses are joined by Mark Menger to cut through the myth and focus on where the real risk lives: the inferencing server, the data sources it can reach, and the runtime environment that’s actually exposed to traffic.
They make the point plainly: a model file is usually just static weights, a heavy spreadsheet sitting at rest. If you trained a proprietary model, protecting that artifact matters. But most enterprises aren’t training producers; they’re training consumers using open-weight models, and obsessing over encrypting and isolating a freely downloadable file won’t stop the failures showing up in headlines.
The real battleground is everything around the model: what data the inference system can access, how RAG sources are protected, what APIs agents can invoke, what credentials get embedded in “skills” files, and how the system behaves under production-scale load. Mark frames it as an iceberg problem: the shiny GPU layer is above the waterline, but reliability, security, performance, and resilience are won or lost in the unglamorous infrastructure underneath.
A key architectural theme is loose coupling. Adding control points between clients, RAG, object stores, and inference services limits blast radius and prevents “pilot success” from turning into production Thanksgiving. The practical advice is to stop treating the model file as the center of gravity, build strong boundaries around the runtime, and stress test for real scale and real failure modes before rollout.
Creators and Guests
Host
Joel Moses
Distinguished Engineer and VP, Strategic Engineer at F5, Joel has over 30 years of industry experience in cybersecurity and networking fields. He holds several US patents related to encryption technique.
Host
Lori MacVittie
Distinguished Engineer and Chief Evangelist at F5, Lori has more than 25 years of industry experience spanning application development, IT architecture, and network and systems' operation. She co-authored the CADD profile for ANSI NCITS 320-1998 and is a prolific author with books spanning security, cloud, and enterprise architecture.
Producer
Tabitha R.R. Powell
Technical Thought Leadership Evangelist producing content that makes complex ideas clear and engaging.
