

Breaking Models AI Security
βBreaking Models β Session 4: Attack & Defend Edition π‘οΈ One talk on what happens after an AI gets hacked. One talk on how to stop your data from leaking into AI in the first place. Offense and defense, same evening.
βTalk 1 β DLP is Dead; Long Live DLP: Keeping Your Secrets Out of ChatGPT.
βSpeaker- Ritesh Ahuja, Co-Founder & CTO, Wald.ai
βYour employees are pasting sensitive data into ChatGPT, Claude, and Gemini dozens of times a day β and the DLP tools your company spent decades deploying can't see any of it. Ritesh (ex-Google, Stanford, IIT Delhi) breaks down why traditional data loss prevention is completely blind to AI traffic, and what a modern, context-aware approach actually looks like β including how to defend against AI-powered attacks that exploit the cracks that were always there. As always: talks first, then open floor. Bring your questions, your hot takes, your half-finished exploit β this crowd will push back, lovingly.
βTalk 2 β After the Jailbreak: When Your AI Assistant Gets Hacked, Who Cleans Up the Mess? Arshi Chadha, Security Researcher at Zscaler (fresh from BSides Las Vegas) Everyone loves showing off the jailbreak. Nobody talks about the morning after β when that clever prompt lands on a product YOU ship. Arshi walks through two real incidents from last summer: EchoLeak, where a single boring-looking email made Microsoft 365 Copilot silently steal your files (zero clicks, zero malware), and Amazon Q, where an attacker slipped a "delete everything" prompt into an official AWS extension update that auto-installed on ~1 million machines. Who owns the incident? What does response even look like when the "bug" is your AI following instructions a little too well? You'll leave with an actual playbook.
βπ© To present at a future session, please mail at: [aisecurityinbay@proton.me]