Ishween Kaur

Ishween Kaur

Senior Engineer, Crypto and AI @SoFi

Santa Clara, California, United States

Actions

Ishween Kaur is a Senior Software Engineer in Crypto and AI at SoFi, where she works on bringing AI thinking into the crypto space and building AI-native experiences that make her Ops teams' work easier so they can better serve SoFi members.

She was previously a founding engineer on Salesforce's AgentForce, an agentic platform serving 6,000+ enterprise customers across 17+ languages, where she built the harness, memory, guardrails and evaluation that keep agents reliable under real load and debugged them when they failed in ways a prompt could not explain.

She is Communications Lead, Women in AI California and DEIB Lead for Society of Women Engineering, and served as an AI advisor with Cornell Tech's Break Through Tech program. She speaks and runs workshops regularly, and shows working demos rather than slides.

Area of Expertise

  • Business & Management
  • Finance & Banking
  • Information & Communications Technology

Topics

  • AI
  • Women in AI
  • Empowering Women in STEM Fields: Navigating challenges and seizing opportunities in traditionally male-dominated industries.
  • Women in STEM
  • Mental health in tech
  • AI Engineering
  • Software Development
  • Women in Leadership
  • Technology Strategy
  • AI Agents
  • AI Ethics
  • AI Builder

Did That Memory Actually Help? (Counterfactual Evals for Agent Memory)

Give a financial agent memory and it gets more personal. Whether it gets more correct is a separate question that almost nobody tests.

The same stored fact has different value depending on the decision. A user's emergency-fund target is essential context for one question and pure distraction for a debt-repayment question. Semantic relevance to the user does not imply relevance to the decision, and retrieval systems optimize for the former.

I will walk a financial-agent prototype through the same memory set across budgeting, debt repayment, and emergency-fund decisions, comparing semantic retrieval, user-state retrieval, full-context prompting, and decision-aware retrieval. Then the workflow: freshness checks, counterfactual removal to test whether one specific memory improved the answer, deterministic calculation tools instead of trusting the model with arithmetic, and transparent memory-use logs.

For anyone deploying memory in a regulated context, the audit trail is not a nice-to-have. If you cannot say which stored facts produced an answer, you cannot defend the answer.

Key Takeaways:
- A memory metadata schema and retrieval policies for high-stakes decisions
- Counterfactual removal testing: did this specific memory improve the decision?
- Measuring decision quality against token cost, latency, and privacy exposure
- Audit trails that explain which memories drove a recommendation

Your Agent Just Paid for Nothing (6 Attacks on x402 Payments)

Agents can now discover paid APIs and authorize machine-to-machine payments without a human in the loop. Protocols like x402 make this work over plain HTTP. But a payment that settles correctly is not the same as a payment that should have happened.

I will demonstrate live attacks against an autonomous payment agent: price manipulation, malicious service discovery, prompt injection into the payment decision, duplicate payments, budget exhaustion and payment-resource mismatch. Where the agent pays for one resource and receives another. Every one of them produces a technically valid transaction.

Then the controls that actually constrain the surface, all of them are deterministic(none of them a model call): spending limits, recipient allowlists, resource binding, nonce checks, retry limits and pre-payment validation.

Attendees leave with a threat model, a benchmark and a local simulation and testnet harness for testing their own payment agents without risking real funds.

Key Takeaways:
- A working threat model for autonomous agent payments, with six demonstrated attack classes
- Deterministic controls that do not require another model in the loop
- A local simulation and testnet harness for safe testing
- Why "the payment succeeded" and "the payment was correct" are different assertions

Ishween Kaur

Senior Engineer, Crypto and AI @SoFi

Santa Clara, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top