About This Session
Many organizations have rapidly adopted Generative Artificial Intelligence (GenAI) tooling, using it to enhance productivity, facilitate customer interactions, and boost sales. However, most companies – even those with strong cybersecurity programs and AI governance – lack awareness of the ways GenAI tooling can be manipulated by malicious actors to bypass controls and reveal confidential data.
Using technical case examples, this talk highlights techniques attackers use to manipulate GenAI tools such as chatbots into revealing sensitive information. These include appeals to GenAI’s human-like desire to “get along” and “help” and its propensity to become “distracted” or “intimidated” if competing or forceful requests occur. Then, this talk will then showcase how these techniques are used to supercharge common intrusion tactics such as prompt injection, command injection and privilege escalation during the initial access and exploitation phase of an adversary’s attack path.
Attendees will take away a clear understanding of common methods used by adversaries to manipulate GenAI tools and bypass existing controls, as well as concrete guidance on how to incorporate these techniques into their own penetration testing programs to preemptively identify weaknesses.
Speaker
Celina Stewart
Director of Cyber Risk Management - Neuvik
Celina Stewart is the Director of Cyber & AI Risk Management at Neuvik, a cybersecurity services company. Celina specializes in designing and optimizing cybersecurity programs, taking a risk-based approach to cyber strategy, cybersecurity program development, and alignment of technical controls to reduce business risk, including risks from Artificial Intelligence (AI).
Celina is a recognized thought leader in risks associated with Generative Artificial Intelligence (GenAI) and Generative Adversarial Networks (GAN). She has been a featured speaker at high profile events such as SecurityWeek’s AI Risk Summit, CloudX, Blue Team Con and more. Her research focuses on the intersection of AI and cybersecurity, exploring topics such as emerging risks, AI and Insider Threat, and AI Governance.