Kind of interesting to think about how isolated the GPU inference is from the container the harness is running in. Say you're a rouge agent in a container that can get root access to your machine or make arbitrary network requests. How would you exfiltrate your weights?