Schedule icon
Webhook icon
Queries icon
Query icon
ChatCompletion icon
OpenAI icon
OutputValues icon
If icon
Write icon
SlackIncomingWebhook icon
Fail icon
Log icon

ML Training Dataset Security Guard and Poisoning Prevention Gate

Audit ML training datasets for leaked credentials and adversarial poisoning, quarantine contaminated batches, and alert Slack in Kestra.

Categories
AIDataInfrastructureinfrastructure

Diagram unavailable

We could not build the topology for this blueprint. The flow itself is valid, use the YAML on the left to run it.

Protect production machine learning models and fine-tuning pipelines from data poisoning, covert backdoor triggers, and credential leakage. When fine-tuning models on customer support tickets, scraped web text, or partner data dumps, unvetted training files pose immediate operational risks: leaked AWS keys, private certificates, or prompt-injection payloads can be permanently memorized into model weights. This blueprint establishes an automated pre-training quarantine gate using in-memory DuckDB pattern scanning and Kestra's AI plugin before data ever reaches a GPU training cluster.

How it works

  1. stage_training_dataset (io.kestra.plugin.jdbc.duckdb.Queries) loads candidate training samples into an in-memory DuckDB table with zero external database dependencies.
  2. scan_credential_patterns (io.kestra.plugin.jdbc.duckdb.Query) executes high-speed regular expression pattern matching to detect AWS access keys, private certificates, and high-entropy authentication tokens.
  3. evaluate_adversarial_poisoning (io.kestra.plugin.ai.completion.ChatCompletion) evaluates samples against an adversarial taxonomy with strict JSON Schema output, detecting covert backdoor triggers and system prompt overrides that static regexes miss.
  4. consolidate_security_audit (io.kestra.plugin.core.output.OutputValues) computes total security violations and extracts tainted sample IDs.
  5. evaluate_quarantine_gate (io.kestra.plugin.core.flow.If) branches deterministically:
    • Quarantine: Generates a downloadable dataset-quarantine-report.md artifact in Kestra storage, delivers a Slack alert with the breach breakdown, and terminates the execution before model training runs.
    • Certified: Persists a certified-dataset.json artifact and logs an all-clear verification.
  6. alert_audit_failure (errors block) notifies Slack if the audit workflow fails.

What you get

  • Zero secret leakage into model weights, preventing irreversible memorization attacks.
  • Automated detection of adversarial backdoor injections before GPU hours are spent.
  • Publication-ready quarantine Markdown report artifacts stored in Kestra internal storage.
  • Slack alerting with immediate visibility into contaminated sample IDs.

Who it's for

  • MLSecOps engineers, AI Platform teams, and Data Scientists fine-tuning foundation models.
  • Regulated enterprises (finance, healthcare, defense) subject to EU AI Act and SOC2 audits.

Why orchestrate this with Kestra

Securing training data requires coordinating fast SQL pattern scanning with AI-based semantic threat analysis. Kestra coordinates DuckDB, frontier LLMs, storage persistence, and Slack alerting into a single auditable, declarative pipeline with complete execution lineage.

Prerequisites

  • OpenAI API key or any OpenAI-compatible LLM endpoint (Groq, Ollama, vLLM).
  • Slack incoming webhook URL for alert delivery.

Secrets

  • OPENAI_API_KEY: API key for the AI threat evaluation task.
  • SLACK_WEBHOOK_URL: Slack incoming webhook endpoint for quarantine alerts.
  • MLSECOPS_WEBHOOK_KEY: Authentication key for event-driven CI/CD triggers.

Quick start

  1. Configure OPENAI_API_KEY and SLACK_WEBHOOK_URL in your Kestra namespace.
  2. Import this blueprint into your Kestra instance.
  3. Click Execute with default sample data to verify the quarantine gate in action.
  4. Enable the schedule or point your ML dataset CI/CD webhook at the endpoint.

How to extend

  • Add Microsoft Presidio or specialized PII detectors in downstream tasks.
  • Route certified datasets directly to S3 or Hugging Face Hub for training jobs.
  • Chain automated Jira ticket creation for quarantined security incidents.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.