World Congress 2024 Aug 20, 2024 Session details

The AI Security Survival Guide: Practical Advice for Stressed-Out Developers

Mackenzie

Attackers are publishing malware using fake dependency names hallucinated by AI assistants. Discover how to defeat prompt injection and safely secure your automated development workflow.

Pause
Mute Enter Fullscreen
#1 about 2 min

Artificial intelligence components in the software supply chain

Integrating language models introduces inherited vulnerabilities into development workflows regardless of direct implementation.

#2 about 3 min

Differentiating language model types for software development

Understanding the safety differences between baseline-tuned completion plugins and instruction-tuned conversational agents informs developer usage.

#3 about 3 min

Evaluating training datasets and open source code quality

Models trained on vast public repositories often ingest and reproduce insecure open source coding patterns.

#4 about 4 min

Identifying and defining prompt injection execution vulnerabilities

Malicious language input bypasses instructions by treating natural language text fields as hidden executable commands.

#5 about 3 min

Demonstrating interactive prompt injection exploits in applications

Practical terminal demonstrations show how direct commands override application-specific master prompts to execute unverified actions.

#6 about 3 min

Exploiting automated email assistant integrations with malicious input

Injecting deceptive commands into external communications manipulates automated assistants into executing unverified internal actions.

#7 about 2 min

Mitigating prompt injection through architectural privilege separation

Implementing third-party security agents and dual-model quarantine systems isolates sensitive operations from untrusted language inputs.

#8 about 5 min

Exploiting artificial intelligence package hallucinations through squatting

Attackers publish malware under the names of non-existent packages frequently fabricated by language models responding to generic prompts.

#9 about 2 min

Securing applications against hallucinated developer dependency attacks

Verifying package legitimacy and utilizing software composition analysis prevents the integration of malicious hallucinated code iterations.

#10 about 4 min

Leveraging purpose-built models for escalated security attacks

Unrestricted malicious models enable attackers to refactor obsolete architectural exploits and automate highly personalized developer spear phishing campaigns.

#11 about 1 min

Defending internal networks against intelligence-augmented phishing threats

Enforcing strict access control and network segmentation limits the blast radius of developer accounts compromised via targeted phishing.

#12 about 2 min

Preventing sensitive data leakage into public language models

Training models on proprietary configuration code creates interactive avenues for extracting hardcoded credentials and internal infrastructure secrets.

#13 about 2 min

Integrating generative models safely without outright prohibition

Banning corporate models encourages risky shadow usage, making developer education and foundational environment security practices essential components of adoption.

Matching moments

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · WWC 2025

2:01 min

The necessity of developer intelligence amidst automated attack generation

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

5:18 min

Addressing psychological safety and ethical risks of AI adoption

Vera Slavnić Vera Slavnić · Europe 2026 Virtual

3:37 min

Managing security risks in AI-accelerated development processes

Carey Liu Carey Liu · WWC Europe 2026

2:31 min

Emerging risks and attack vectors in AI systems

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

Upcoming sessions on this topic

Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Developer Liability in the AI Agent Era: Building Responsibly

Alla Barbalat

Freelancer Trade Show Spokesmodel and Tech Event Host

Alla Barbalat
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić