Beyond Vibe Coding: Building Reliable AI AppSec Tools

Emily Choi-Greene

BSides NYC 2025 (0x05) · Day 1 · Tech - Other

In "Beyond Vibe Coding: Building Reliable AI AppSec Tools," Emily Choi-Greene delves into the critical intersection of artificial intelligence and application security, advocating for the strategic application of AI to solve pressing security challenges. While acknowledging the pervasive "AI hype," Choi-Greene emphasizes that Large Language Models (LLMs) are powerful tools when applied appropriately, particularly in the realm of AppSec. The talk addresses the burgeoning landscape of software development, where AI-driven "vibe coding" makes software creation more accessible than ever, paradoxically leading to a surge in potential security vulnerabilities.

AI review

Competent, practitioner-level survey of applied LLM techniques for AppSec — honest about failure modes, grounded in real production constraints, and meaningfully above the vendor-hype baseline. But it's a well-organized tutorial on techniques (RAG, tool use, CoT, LLM-as-Judge) that are already widely documented, not original research, and the threat modeling use case never gets specific enough to be genuinely instructive.

Watch on YouTube