Enes Deniz
Co-Founder at AltaySec | OWASP GenAI Contributor • LLM Security • AI Red Teaming
AltaySec Kurucu Ortağı | OWASP GenAI Contributor • LLM Security • AI Red Teaming
İzmir, Turkey
Actions
Enes Deniz is Co-Founder of AltaySec and an open-source contributor to the OWASP GenAI Security Project. His merged work includes a 300-case Turkish-first prompt-injection and data-extraction contribution for the GenAI Data Security Initiative and a reproducible System Reconnaissance and Discovery campaign with 24 English and Turkish probes across nine categories and 12 automated tests. A follow-up hardening contribution then made the campaign safer around inconclusive model or tool failures, empty evidence, misleading success artifacts, and missing hard-stop guidance; its focused validation suite passed 69 automated tests. He also publishes reproducible AI-security datasets through Zenodo, including the Turkish Conversation Prompt-Injection Dataset and Agentic Prompt-Injection Boundary Pairs. His work focuses on multilingual LLM security, prompt injection, AI red teaming, agentic trust boundaries, and evidence-driven security evaluation.
Enes Deniz, AltaySec kurucu ortağı ve OWASP GenAI Security Project açık kaynak contributor'ıdır. Merge edilen çalışmaları; GenAI Data Security Initiative için 300 Türkçe-öncelikli prompt-injection ve veri çıkarma test vakasını, GenAI Red Team Lab için ise dokuz kategoride 24 İngilizce ve Türkçe sorgu ile 12 otomatik test içeren tekrarlanabilir bir Sistem Keşfi ve Discovery kampanyasını kapsar. Takip eden hardening katkısı, sonuçsuz model veya araç hataları, boş kanıtlar, yanıltıcı başarı çıktıları ve eksik hard-stop yönlendirmesi karşısında kampanyayı daha güvenli hâle getirdi; odaklı doğrulama paketi 69 otomatik testten geçti. Zenodo üzerinden Turkish Conversation Prompt-Injection Dataset ve Agentic Prompt-Injection Boundary Pairs dahil olmak üzere tekrarlanabilir AI güvenliği veri setleri yayımlar. Çalışmaları çok dilli LLM güvenliği, prompt injection, AI red teaming, agentic güven sınırları ve kanıta dayalı güvenlik değerlendirmesine odaklanır.
Area of Expertise
Topics
Prompt Injection Beyond English: Attacking and Defending Turkish LLM Applications en tr
Prompt injection is usually demonstrated in English with obvious attack commands. Production systems do not fail that neatly. Attacks switch languages, hide inside ordinary-looking requests, enter through retrieved content, or target an agent's tools and memory. A useful defense must stop those attempts without treating every security-related request as malicious.
This session approaches prompt injection from both the red-team and blue-team sides. We will examine direct and indirect injection, jailbreaks, RAG and memory poisoning, and agent or tool abuse, then connect each attack surface to practical defensive controls.
Using an open Turkish dataset containing 750 paired benign and attack examples, we will also examine the boundary between malicious intent and legitimate use, the false-positive problem, and language-dependent behavior. The result is a practical workflow for Turkish and global LLM applications: define the trust boundary, test it adversarially, measure the failures, and harden the system without making it unusable.
Audience: application security and AI security teams, engineers building LLM or agent applications, SOC and blue-team practitioners, and technical product teams. Level: intermediate. Preferred duration: 35-40 minutes. No prior machine-learning background required. Examples are defense-oriented and do not include deployable exploit payloads.
İngilizcenin Ötesinde Prompt Injection: Türkçe LLM Uygulamalarına Saldırı ve Savunma en tr
Prompt injection çoğu zaman İngilizce ve açık saldırı komutları üzerinden anlatılıyor. Üretimde ise saldırılar bu kadar belirgin değil. Dil değiştiriyor, sıradan bir kullanıcı talebi gibi görünüyor, RAG içeriğine yerleşiyor veya bir ajanın araç ve hafıza katmanını hedefliyor. İşe yarayan bir savunma, bu girişimleri durdururken güvenlikle ilgili her talebi saldırı olarak değerlendirmemeli.
Bu oturumda prompt injection'ı hem red team hem blue team tarafından ele alacağım. Doğrudan ve dolaylı injection, jailbreak, RAG ve hafıza zehirleme ile agent ve araç istismarı senaryolarının hangi güven sınırlarını aşmaya çalıştığını inceleyeceğiz. Ardından her saldırı yüzeyini uygulanabilir savunma kontrolleriyle eşleştireceğiz.
750 eşleştirilmiş güvenli ve saldırgan Türkçe örnekten oluşan açık veri seti üzerinden saldırı ile meşru kullanım arasındaki sınırı, false positive problemini ve dil bağımlı davranışları değerlendireceğiz. Amaç, Türkçe ve global LLM uygulamalarına uyarlanabilen net bir çalışma yöntemi sunmak: güven sınırını tanımla, saldırgan biçimde test et, hatayı ölç ve sistemi kullanılamaz hale getirmeden güçlendir.
Hedef kitle: AppSec ve AI güvenliği ekipleri, LLM veya agent uygulaması geliştiren mühendisler, SOC ve blue-team uzmanları ile teknik ürün ekipleri. Seviye: orta. Tercih edilen süre: 35-40 dakika. Önceden makine öğrenmesi bilgisi gerektirmez. Örnekler savunma odaklıdır; çalışır saldırı payload'ları paylaşılmaz.
Enes Deniz
Co-Founder at AltaySec | OWASP GenAI Contributor • LLM Security • AI Red Teaming
İzmir, Turkey
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top