Securing a Generative AI Implementation

eyrsec

BSides NYC 2024 · Day 1 · Tech - Other

In this insightful talk, Nandita Joshi, a Senior Product Security Engineer at Zendesk, delves into the critical and rapidly evolving domain of **Generative AI (Gen-AI) security**. Titled "Securing a Generative AI Implementation," her presentation aims to demystify the core components of Gen-AI and Large Language Models (LLMs), providing a foundational understanding before dissecting the myriad of new attack vectors they introduce. Joshi's expertise in web applications and API security, coupled with her recent focus on AI, positions her uniquely to bridge traditional security paradigms with the novel challenges presented by AI.

AI review

A competent survey of the OWASP LLM Top 10 dressed up as original research, delivered by someone with genuine AppSec credentials but no apparent firsthand offensive AI work. The content is almost entirely a repackaging of publicly available frameworks with a GPT-2 demo and a reference to a third-party incident report standing in for actual findings.

Watch on YouTube