World Congress 2023 Sep 27, 2023

A hundred ways to wreck your AI - the (in)security of machine learning systems

Balázs Kiss

Are your machine learning models secretly harboring critical vulnerabilities? Discover how to defend your AI infrastructure against novel data poisoning attacks and traditional remote code execution exploits.

Pause
Mute Enter Fullscreen
#1 about 4 min

Understanding the landscape of AI capabilities and risks

How widespread AI adoption introduces new security challenges and failure modes.

#2 about 2 min

Addressing security flaws in AI-generated code

Why relying on AI for code generation can introduce outdated or flawed validation logic.

#3 about 2 min

Fundamental problems in machine learning model training

How overfitting, catastrophic forgetting, and bad input data compromise model reliability.

#4 about 2 min

Misusing AI for malware generation and physical evasion

How attackers leverage AI to automate exploitation, mutate malware, and bypass image recognition.

#5 about 2 min

Corrupting AI models and software supply chains

How malicious training data and compromised dependencies inject backdoors into AI applications.

#6 about 2 min

Utilizing industry threat models for AI security

Navigating frameworks from OWASP, NIST, and MITRE to understand and mitigate machine learning vulnerabilities.

#7 about 3 min

Categorizing threats across the machine learning lifecycle

Differentiating between novel machine learning threats and traditional software vulnerabilities affecting AI systems.

#8 about 1 min

Exploiting models through adversarial evasion samples

How imperceptible modifications to input data force machine learning models to make incorrect decisions.

#9 about 2 min

Poisoning data to manipulate model behavior

Injecting malicious data during training phases to alter decision boundaries and trigger targeted failures.

#10 about 2 min

Stealing confidential data through model extraction attacks

Using model inversion and excessive requests to extract sensitive training data or replicate proprietary models.

#11 about 3 min

Generating adversarial samples against digit recognition models

A live demonstration using the Adversarial Robustness Toolbox to trick an MNIST model into misreading financial digits.

#12 about 3 min

Preventing remote code execution in PyTorch models

Why loading unverified PyTorch models stored in the Pickle format exposes systems to arbitrary code execution.

#13 about 2 min

Securing developer wrapper code around machine learning models

Addressing traditional software bugs like exposed API keys and command injection in open-source AI wrappers.

#14 about 1 min

Replacing the Pickle format with secure serialization alternatives

Migrating to standard HDF5 or static serialization formats to prevent arbitrary code execution vulnerabilities.

Matching moments

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · World Congress 2025

2:31 min

Emerging risks and attack vectors in AI systems

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

3:18 min

Core AI security risks and data poisoning

Liran Tal Liran Tal · LIVE

4:55 min

Core principles of manipulating artificial intelligence models

Mirko Ross · World Congress 2023

1:46 min

Introduction to machine learning security and robustness

Nura Kawa · World Congress 2023

2:31 min

Understanding data poisoning and model bias risks

Keno Dreßel Keno Dreßel · World Congress 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 25, 2026 · 11:40–12:10

Stage 9

You Can’t Re-Run Sunlight: Designing ML Data Architectures for Physical AI

An Phan

Senior Data Infrastructure Engineer @ Hippo Harvest

An Phan
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Stage 4

Managing Abuse in the Era of AI Agents

Eli-Shaoul Khedouri

CEO of Intuition Machines

Eli-Shaoul Khedouri
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 4

It's Not About the Models

Bob Wambach

VP, Market and Customer Insights

Bob Wambach