AI data centers outpacing security, report finds
Lava Labs warns AI data centers are being built faster than security can keep up, exposing GPU-dense facilities to firmware, network and multi-tenant risks.
A recent report from Lava Labs, titled “The Top 10 Data Center and AI Infrastructure Security Risks,” warns that AI data centers are being built faster than security can keep pace. The firm groups the key dangers under FORGE, an acronym for “harden the metal beneath the model,” and says AI data centers differ from traditional sites because they are GPU-dense, highly interconnected and often serve many unknown customers.
The report ranks ten risks by severity. The top five are firmware and hardware integrity compromise; network and interconnect vulnerabilities; unsafe multi-tenant isolation and resource reuse; insecure out-of-band management plane; and AI infrastructure supply chain compromise. Lava Labs says those five risks operate below the operating system, are hard to detect and can produce cluster-wide failure effects that affect many customers at once.
Technical realities raise the threat level. Dense GPU clusters use complex firmware and have narrow thermal tolerances, which can make hardware or firmware faults more consequential. High-performance fabrics used to link GPUs and servers — including InfiniBand, RoCE, RDMA and NVLink — are often deployed without encryption and with limited monitoring, creating paths an attacker could use to discover systems and move laterally. Heavy use of automated baseboard management controllers and management protocols such as Redfish and IPMI concentrates operational control in a few systems.
Multi-tenant operation and resource reuse further increase exposure. GPUs and nodes are frequently reassigned between customers, and residual data or model artifacts on hardware can expose training data, models or inference results to other tenants. The report also identifies gaps in certification and provider transparency that can leave customers uncertain about the security posture of the infrastructure they rent.
Supply chain and patching issues add to the risk picture. Global GPU scarcity has prompted some operators to deploy alternative processors and configurations that may offer weaker isolation, the report notes. Delays in vendor patches and in applying updates can extend the window during which many tenants remain exposed.
Lava Labs says the report is intended to help defenders prioritize risks and includes example attack scenarios and practical mitigations. Recommended measures listed in the report include stronger firmware and hardware integrity checks, encrypted and monitored interconnect fabrics, stricter tenant isolation and artifact handling, tighter supply chain controls, and faster patching and disclosure by vendors and providers.
The report states: “Systems originally designed for trusted operators are now supporting high-value, multi-tenant workloads from unrelated customers.”








