More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS2 - Words As Weapons: Breaking AI and Agents; Then Securing Them

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  Pavan “pavanreddysec” Reddy

Level of Difficulty: Beginner, Intermediate

Abstract:

Most "AI security" talks stop at the slide that says "prompt injection is bad." This workshop does the opposite. Attendees spend four hours inside a working, vulnerable production-style AI system - a mock car dealership backed by a real LLM, a real database, and real tool calls - and learn to break it, watch it break, then put it back together with defenses that actually hold.

You will:

(1) manipulate prices and inventory using direct and indirect prompt injection,

(2) reproduce an EchoLeak-style zero-click data exfiltration against a RAG pipeline,

(3) execute a model-extraction attack against a deployed classifier, and

Each of these modules will layer in defenses one at a time to see how the AI reacts. We close by mapping everything to OWASP LLM Top 10, OWASP Agentic Top 10, NIST AI RMF, and MITRE ATLAS.

Built for red teamers handed AI in scope, blue teamers watching agents deploy faster than detections exist, AppSec engineers who used to own the API and now own a chat window, and developers curious what "prompt injection" looks like when it costs money. No prior AI-security background required.

Pre-Requisites:

REQUIRED:

·      High-level familiarity with what an LLM is and how a chat-based assistant calls a backend.

·      Basic understanding of HTTP / REST APIs (request/response, status codes, JSON bodies).

·      Basic understanding of relational databases (SELECT/UPDATE; not required to write SQL from scratch).

HELPFUL BUT NOT REQUIRED:

·      Prior exposure to retrieval-augmented generation (RAG), embeddings, or LLM tool-calling.

·      Prior exposure to OWASP LLM Top 10, OWASP Agentic Top 10, or NIST AI RMF.

NOT REQUIRED:

·      Any prior adversarial-ML or AI-red-teaming experience.

·      Any prior offensive-security background.

·      Any cloud account, paid API key, or installed development environment beyond a modern browser.

Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops