Building, Owning, and Securing Private AI Infrastructure

OWASP 25th Anniversary Virtual Conference (September)

22 September 2026

Date: September 22, 2026 | 1:15pm - 2:00pm PDT Event: OWASP 25th Anniversary Virtual Conference (September) Track: Implementation Audience: Intermediate Format: 45-minute Talk

Overview

AI is rapidly becoming part of how we write code, analyze data, investigate security issues, and interact with our own information — raising a basic question: if intelligence is becoming part of our infrastructure, how much of that infrastructure do we actually control?

This talk looks at what it takes to build and secure private AI infrastructure, whether the model is running on hardware sitting next to you or on a GPU rented in the cloud. It starts by defining what “private AI” actually means, takes a practical 10,000-foot tour through the terminology that makes this space unnecessarily confusing, follows the software path from client tools down to the model itself, and finally treats the working stack like any other infrastructure — threat modeling the environment and defining practical security guidelines and guardrails.

The goal is not to convince everyone to buy a GPU. It is to understand the stack well enough to decide what should run locally, what can safely run in the cloud, what can be delegated to an external provider, and what you actually give up with each of those choices.

Key Topics

AI Generated Summary

AI Generated Content Disclaimer

Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.

Anant Shrivastava — information security professional, founder of Cyfinoid Research, and a 15+ year veteran spanning application security, mobile security, cloud, DevSecOps, Linux and supply chain (the force behind Android Tamer and Code Vigilant, and a familiar voice at Black Hat, DEF CON, nullcon and c0c0n) — delivered “Building, Owning, and Securing Private AI Infrastructure” at the OWASP 25th Anniversary Virtual Conference on September 22, 2026. Coming at the topic as “an ops person, being a server admin in my past life, and now being a security professional,” he set out to show what private AI infrastructure actually looks like, which decisions you must make while building one, and where security constraints enter the picture. The talk moves from the economics and politics of SaaS AI, through a ground-level tour of hardware, models and the software stack, and closes by threat modeling a self-hosted LLM environment. His goal was explicitly not to convince everyone to buy a GPU, but to help each listener decide what should run locally, what can safely run in the cloud, and what you give up with each of those choices.

Defining Private AI: Control, Not Cost

The certainty cuts both ways: you know exactly what works in your environment — and you also know, painfully, when nothing works. That is a certainty SaaS APIs can never give you.

Why Renting Cognition Hurts

Deployment Models and Cost Profiles

Hardware: Dedicated GPU vs Unified Memory

Models, Quantization and the VRAM Budget

The Software Stack

Choosing and Vetting Models

OS and Maintenance: Make It Boring

Threat Modeling Your Own Stack

So… Should You Self-Host?

Anant closed with a decision flow rather than a blanket recommendation:

Q&A

The session ended with no audience questions; the host joked that this meant “either you explained everything brilliantly or everyone is quietly reviewing their security architecture.” Anant wrapped up by sharing his contact details — cyfinoid.com and anant@cyfinoid.com — thanking the audience for listening.