Attackers Figured Out That Your GenAI Deployment Is the Easiest Way Into Your Enterprise
About This Session
For years the security conversation around AI was about how attackers would use AI as a weapon: deepfakes, automated phishing, AI-generated malware. That conversation is still valid but it is missing something. The more immediate problem is that enterprises have deployed AI systems as first-class infrastructure components, given them access to sensitive data and internal APIs, and connected them to identity systems that can reach most of the organization. That infrastructure is now an attack surface, and it is one that most enterprise security programs have not finished building controls around.
I published research on adversarial attacks against cloud AI workloads that received the Best Paper Award at IEEE ICAIC 2025. The core finding from that work and from the production security programs I run is consistent: the attack paths into enterprise AI systems are not exotic. They rely on the same principles as web application attacks from fifteen years ago, applied to an environment where the security discipline is still catching up. Prompt injection is the new SQL injection. Over-permissioned AI service accounts are the new over-privileged database users. And just like those earlier problems, the window before attackers routinely exploit these patterns at scale is closing.
This session covers the adversarial threat landscape for enterprise GenAI deployments with enough technical grounding to be actionable but framed for the risk and security leadership audience that has to make resourcing and prioritization decisions. I'll walk through the attack classes: direct and indirect prompt injection, training data extraction, model inversion, and the abuse of AI agent tool access to pivot through enterprise infrastructure. For each I'll cover what realistic exploitation looks like, what evidence it leaves behind, and what controls actually reduce the risk in enterprise environments that are already running these systems.
The second half of the session addresses the strategic question CISOs are actually wrestling with: how do you build a security program around AI systems that are changing faster than your risk assessment cycles? I'll cover the framework we use to continuously evaluate AI deployment risk, the metrics that matter for board reporting, and the organizational changes that separate enterprises that are managing AI risk from enterprises that are hoping nothing goes wrong.
The organizations in this room are past the question of whether to deploy AI. The question now is how to do it without handing attackers a new category of access to everything you've spent years trying to protect.
Attendees will leave with an adversarial threat model for enterprise GenAI, a prioritized set of controls mapped to realistic attack paths, and a framework for continuous AI risk assessment that keeps pace with deployment velocity.
I published research on adversarial attacks against cloud AI workloads that received the Best Paper Award at IEEE ICAIC 2025. The core finding from that work and from the production security programs I run is consistent: the attack paths into enterprise AI systems are not exotic. They rely on the same principles as web application attacks from fifteen years ago, applied to an environment where the security discipline is still catching up. Prompt injection is the new SQL injection. Over-permissioned AI service accounts are the new over-privileged database users. And just like those earlier problems, the window before attackers routinely exploit these patterns at scale is closing.
This session covers the adversarial threat landscape for enterprise GenAI deployments with enough technical grounding to be actionable but framed for the risk and security leadership audience that has to make resourcing and prioritization decisions. I'll walk through the attack classes: direct and indirect prompt injection, training data extraction, model inversion, and the abuse of AI agent tool access to pivot through enterprise infrastructure. For each I'll cover what realistic exploitation looks like, what evidence it leaves behind, and what controls actually reduce the risk in enterprise environments that are already running these systems.
The second half of the session addresses the strategic question CISOs are actually wrestling with: how do you build a security program around AI systems that are changing faster than your risk assessment cycles? I'll cover the framework we use to continuously evaluate AI deployment risk, the metrics that matter for board reporting, and the organizational changes that separate enterprises that are managing AI risk from enterprises that are hoping nothing goes wrong.
The organizations in this room are past the question of whether to deploy AI. The question now is how to do it without handing attackers a new category of access to everything you've spent years trying to protect.
Attendees will leave with an adversarial threat model for enterprise GenAI, a prioritized set of controls mapped to realistic attack paths, and a framework for continuous AI risk assessment that keeps pace with deployment velocity.
Speaker
Advait Patel
Site Reliability Engineer (AIOps Security) - Broadcom
Advait Patel is a Senior Site Reliability Engineer at Broadcom and the creator of DockSec, an open-source, AI-powered Docker security analyzer.
Advait is a Docker Captain, Google Developer Expert (google cloud, and AI) and regular speaker at major security and developer conferences, including QConAI Boston, SANS CloudSecNext, OWASP GlobalAppSec US, OWASP SnowFROC, PlatformCon, Linux Security Summit North America, O’Reilly Media AI CodeCon, Redgate Cloud Summit, DataWeek, Open Cloud Security Conference, CornCon, ISACA, Silicon Valley Cybersecurity Conference, and IEEE Cloud Summit. He is an active contributor to the Cloud Security Alliance’s AI Control Matrix (AICM) and has authored implementation guidelines focused on securing LLM workloads and AI pipelines in enterprise environments.
Advait is a Docker Captain, Google Developer Expert (google cloud, and AI) and regular speaker at major security and developer conferences, including QConAI Boston, SANS CloudSecNext, OWASP GlobalAppSec US, OWASP SnowFROC, PlatformCon, Linux Security Summit North America, O’Reilly Media AI CodeCon, Redgate Cloud Summit, DataWeek, Open Cloud Security Conference, CornCon, ISACA, Silicon Valley Cybersecurity Conference, and IEEE Cloud Summit. He is an active contributor to the Cloud Security Alliance’s AI Control Matrix (AICM) and has authored implementation guidelines focused on securing LLM workloads and AI pipelines in enterprise environments.