Session
AI Risks: There Are Monsters in Your LLMs
Your model is not your friend. It is not your enemy either. It is a very convincing instruction follower with access to your data, tools, and possibly production. What could go wrong?
Prompt injection was only the opening act. Modern AI applications browse the web, call APIs, connect to MCP servers, retain memory, and act with limited supervision. A poisoned document, malicious tool, or patient attacker can turn a useful agent into a confused deputy.
We will dissect attack patterns appearing in research and real systems, including indirect prompt injection, data exfiltration, tool poisoning, and Crescendo style jailbreaks. We will examine defenses that hold up, along with popular mitigations that put a better lock on the wrong door, introduce new failure modes, or backfire as soon as the monster learns a new trick.
Finally, we will consider what changes as agents gain more memory, authority, and autonomy. You will leave with a clearer threat model, practical defensive principles, and some important questions to ask before giving a chatbot production credentials.
Andreas Erben
CTO for Applied AI and Metaverse at daenet
Ponte Vedra Beach, Florida, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top