The Discipline at the Intersection of Machine Learning and Security Operations.
The Discipline
What is SecMLOps?
SecMLOps — Security for Machine Learning Operations — is the convergence of three disciplines that have historically operated in isolation: MLOps, Application Security, and Adversarial Machine Learning. As organizations deploy ML models at scale, the attack surface expands in ways that traditional security tooling was never designed to address.
A model is not just code. It is a statistical artifact trained on data, served through an API, updated continuously, and embedded in decisions that carry real-world consequences. Securing it requires a fundamentally different mental model — one that accounts for the probabilistic nature of ML behavior, the opacity of model internals, and the novel threat vectors that emerge when adversaries can query, probe, and manipulate inference endpoints.
Traditional AppSec covers the infrastructure around a model. SecMLOps covers the model itself — its training pipeline, its data supply chain, its inference surface, and its governance lifecycle.
Adversarial Robustness
Defending models against adversarial inputs — crafted perturbations designed to cause misclassification, evasion, or targeted misbehavior. Covers attack taxonomy, evaluation frameworks, and certified defenses.
ML Pipeline Security
Securing the end-to-end training pipeline: data ingestion, feature engineering, model training, and artifact storage. Addresses supply chain attacks, dependency poisoning, and CI/CD integrity for ML workflows.
Model Governance & Compliance
Establishing controls for model versioning, access management, audit trails, and regulatory compliance. Covers model cards, risk assessments, and the operational policies that govern model promotion to production.
Threat Modeling for AI Systems
Applying structured threat modeling methodologies — STRIDE, PASTA, LINDDUN — to ML architectures. Identifying trust boundaries, data flows, and adversarial objectives specific to AI-enabled systems.
Incident Response for ML
Detecting, containing, and recovering from ML-specific security incidents: model poisoning events, inference attacks, data exfiltration via model outputs, and silent model degradation caused by adversarial drift.
The Stakes
Why It Matters Now
of organizations have deployed ML models in production
— Gartner, 2025
increase in adversarial ML attacks on production systems year-over-year
— IBM X-Force, 2025
of security teams report confidence in securing ML-specific attack surfaces
— SANS Institute, 2025
Certification Program
A Certification Program Is Coming.
The SecMLOps School certification is in development.
We are building the first practitioner-grade certification program for ML security operations. Designed for ML engineers and data scientists who need to operate securely in adversarial environments — not a survey course, but a rigorous, hands-on curriculum grounded in real threat models and production systems.
// curriculum subject to revision
Early Access
Reserve Your Spot.
The program opens to a limited first cohort. Leave your email and we will notify you when enrollment opens — along with early access to curriculum previews and field resources.
No spam. Unsubscribe at any time.