AI Con USA 2025 - AI Security

Thursday, June 12

Gal Elbaz
Oligo Security
T11

Shadow Vulnerabilities in AI/ML Data Stacks - What You Don’t Know CAN Hurt You

Thursday, June 12, 2025 - 2:40pm to 3:25pm

The adoption of open-source AI software introduces a new family of vulnerabilities to organizations. Some components in AI, like model serving, include Remote Code Execution (RCE) by design, like when loading pre-trained models from external sources. Traditional SCA and SAST approaches are not built for the AI ecosystem leaving a huge & insecure attack surface. The irony is that in the AI ecosystem, security issues such as remote code execution are actually a feature and not a bug, often specified explicitly in the docs, which most devs don’t read. AI models are often downloaded from...