Security and Privacy Issues for Data Analytics Using Machine Learning in Cloud Computing
Avita Katal · 2025
While more and more organizations turn to the cloud to handle their data, those in charge of ensuring data confidentiality, integrity and availability face a formidable task. This chapter discusses the challenges of security and privacy issues that arise when using cloud-based data analytics pipelines. The chapter introduces the major security concerns, highlighting the shared responsibility model as the starting point regarding how the security responsibilities are partitioned between the cloud vendors and the consumers of the services. It goes into issues of infrastructure security, security of data both at rest and in transit and addresses multi-tenant environments, data origin, history and retention issues. Security of the applications is studied by addressing the issue of securing web applications, APIs and cloud-native applications, as well as the security of the operating systems. A major focus throughout the chapter has been on the various privacy-related aspects such as data ownership and data sharing, data regulation compliance for example the GDPR and guidelines related to data management best practices. The last section draws attention to data pipelines within the cloud focusing on AWS, explaining the available controls in AWS, how auditing can be done and compliance formed and maintained throughout the data lifecycle. Furthermore, it surveys AI/ML pipeline security using Google’s Secure AI Framework and the Generative AI Top 10 Controls, focusing on data integrity, robustness against adversarial conditions and model life cycle management. By these AI-specific controls being integrated with cloud controls, it is possible to build safe, compliant data analytics pipelines. With an emphasis on key areas like infrastructure, data, application security and privacy issues, this chapter provides essential insights for securing cloud-based data analytics pipelines that leverage AI/ML. It offers practical guidance on implementing robust security protocols within AWS, helping businesses safeguard their data, ensure compliance with privacy laws, and strengthen the overall security of AI/ML-driven data analytics systems.