Skip to content

Details

Two talks this week. One closes a loop, one opens a rabbit hole.

Part 1 โ€” Prompt Injection Defenses: What Works, What's Theater (Arshi Chadha, Senior Cybersecurity Engineer, Zscaler, 20 min)
Last session: 11 attack classes, CVEs. This session: the defense side. Which mitigations actually hold up, which ones just feel safe, and why "add a better system prompt" isn't a strategy.

Part 2 โ€” Before the Model Answers (Sagnik Nath, Asst Professor, Computer Science, UC Santa Cruz)
Your prompts are now fixed. Cool. Meanwhile, the inference backend is reusing cached states, fuzzy matching old answers, and trusting hashes that were designed for speed, but not security. This talk explores how prefix, semantic, and multimodal caches can be poisoned to alter responses, hide malicious inputs, and bypass LLM-based audits in shared serving systems. We will examine attacks demonstrated against frameworks such as vLLM and GPTCache, then discuss practical defenses for securing the cache layer.

๐Ÿ“ Hacker Dojo, Mountain View
๐Ÿ•• 2:30pm

Same small-group format as last time. Bring a paper you've been chewing on, a finding you're sitting on, an exploit chain you're working through, or a defense you want to pressure-test in front of people who'll push back. The agenda will be our anchor ref. Even more valuable is whatever the room wants to dig into. To attend, or to present a paper/project/anything related to AI security, reach out by email at aisecurityinbay@proton.me.

Related topics

You may also like