Open framework · Handbook
MLSecOps Practical Reference Guide
2024-06-01
My highest-priority research contribution — an open, practical-operational framework for securing machine-learning systems across the full lifecycle. Among everything I have published, this is the work I value most.
External link →MLSecOps Practical Reference Guide
Author’s pick. Of all my published research, this is the piece I stand behind most strongly — the deepest, most complete, and most important body of work I have released so far.
An open technical framework — not a short essay — for securing AI/ML systems in real delivery environments.
It bridges AI security, DevSecOps, and Secure MLOps: from data and training through serving, monitoring, and governance-aligned evidence.
Why it exists
Most AI security material is either abstract policy or one-off exploit write-ups. This guide is built as a working reference: something engineers and security leads can map to pipelines, reviews, and releases.
What it covers
- Threat modeling for ML/AI systems (aligned with catalogs such as MITRE ATLAS)
- Lifecycle controls from build → deploy → operate
- Evidence and review patterns useful for DevSecOps and governance conversations
- Practical notes on LLM, RAG, agentic, and MCP-related attack surfaces
Read it
- On this site: overview and entry point
- Full live handbook: mhaghighian.github.io/MLSecOps