Breaking
SecurityDeveloping Story

Stealthium Shines Light on AI Accelerator Blind Spots

Startup Stealthium targets security gaps in AI accelerators and neo-clouds, offering visibility into a new threat surface.

··7 hours ago·4 min read
the letter a is placed on top of a circuit board
Photo by Numan Ali on Unsplash

The rapid adoption of AI accelerators and the rise of specialized “neo-clouds” are creating a new security blind spot that traditional tools are ill-equipped to address. These accelerator chips, distinct from CPUs and GPUs, are tailored for AI workloads, yet cybersecurity solutions have largely been built around CPU-centric operating systems, leaving a gap in visibility and protection. A startup called Stealthium is emerging to tackle this challenge, aiming to provide security and observability for AI-accelerated runtime environments.

What Are Accelerators and Neo-Clouds?

Accelerators are specialized chips designed to offload and speed up the specific workloads required for artificial intelligence. Unlike general-purpose CPUs or even GPUs, these chips are optimized for tasks like matrix multiplication and neural network inference, making them critical for modern AI development. Primary producers of these accelerators include Tenstorrent, Groq, Cerebras, Graphcore, and Google.

Neo-clouds are a new class of cloud services that differ from traditional hyperscalers such as Azure, Google Cloud, and AWS. These AI-first clouds are often built with accelerators and are designed for customers requiring AI training, inference, and model-building services. They offer massive parallelism, low-latency edge compute, flexible deployment, and more predictable economics. Notable examples include CoreWeave and Nebius.

Typical use cases for neo-clouds involve training large-scale AI models and running high-throughput AI inference. For instance, a customer might leverage the accelerator-optimized low-latency hardware to ensure rapid response times for in-house developed chatbots.

The Security Blind Spot

However, accelerators and neo-clouds suffer from several security blind spots. Traditional cybersecurity tools, developed over decades around CPU-centric operating systems, haven’t kept pace with the emergence of accelerators. They lack visibility into the accelerators’ high-speed video memory, and current cybersecurity solutions cannot readily detect what is happening within neo-cloud hardware.

Consequently, if a neo-cloud is stealthily compromised by an attacker, neither the cloud provider nor its customers are guaranteed to see the compromise. The result could be a severe but invisible supply chain threat to all customers, but especially those using the neo-cloud for AI development purposes. If it had been more successful, the recent Januscape malware could have been used in such a manner.

Stealthium's Approach

Startup firm Stealthium aims to tackle this threat. It cannot see directly into the accelerators themselves, but instead uses an agent housed within the customers’ infrastructure. This agent is specially trained to detect the subtle hints coming from a compromised neo-cloud, analyzing telemetry for signs of intrusion.

“Unfortunately, our understanding of the shared model of responsibility for security doesn’t apply here, and certainly security controls and observability aren’t applicable in this space.”

— Chris Hosking, GTM Advisor at Stealthium

Hosking further explained, “Our go-to thinking has always been that if you cannot see something happening, then nothing is happening.” This is seriously dangerous, especially with accelerators – in cybersecurity, absence of proof is never proof of absence.

The Threat Landscape

“Organizations are increasingly uncomfortable because they lack meaningful security and observability controls, in real time, for that silicon accelerator layer,” Hosking continued. “That’s the challenge that Stealthium exists to solve. We believe that AI needs to be trustworthy. Sovereign AI can only be sovereign if it’s secure and trustworthy. That’s the purpose of Stealthium. We’re a security and observability company for AI accelerated runtime.”

The technology used is not new; it’s just highly specialized. “We deploy an agent that searches the telemetry coming from the neo cloud, looking for hints of compromise.” It’s the hints rather than the technology that are dramatically different.

As an example, Januscape exploited a vulnerability in nested virtualization, enabling the attacker to offer or sell an environment to a third party. Such an exploit in a neo-cloud could lead to cross-tenant leakage, with the third party gaining insights and potential access into legitimate in-house chatbots. Stealthium will detect this by detecting subtle hints in neo-cloud telemetry indicating this, or a different, type of attack.

Potential Impact

Such supply chain attacks already occur, but incidence is likely to increase in the future. The prize is attractive to both financially motivated cybercriminals and information gathering or influence seeking nation states. “As an attacker who has compromised a neo-cloud node, I can get access to a customer’s AI weights,” explains Hosking. “I can poison and corrupt and change the way that the model operates without anyone noticing. So, for example, I could make it more sympathetic to the cause that I’m trying to promote. I could extort the customer or just use the shared environment to run crypto mining or be my new base of operations.”

Hypothetically, if a nation state were able to influence or change ChatGPT or Gemini, it would be able to influence entire nations. The stakes are very high in a threat vector that is very new with little established security.

Why It Matters

Stealthium represents an early example of a new type of security company, one that seeks visibility into the operation of accelerators. In this instance, it does not look into the hardware concerned but gathers and analyzes the telemetry coming from the hardware, with a specialized and continuously updated agent trained to detect subtle hints of accelerator compromise.

For businesses relying on neo-clouds for AI development, this highlights a critical gap in their security posture. The lack of visibility into accelerator-level activity means that a compromise could go unnoticed, potentially leading to model poisoning, data exfiltration, or even use of resources for crypto mining. As AI adoption accelerates, so does the need for security solutions that extend visibility into this new hardware layer. The emergence of Stealthium suggests a growing recognition that securing AI infrastructure requires more than traditional tools – it requires a new approach tailored to the unique characteristics of accelerators and the clouds that host them.

#ai#accelerators#neo-cloud#security#startup

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories