AI Con USA 2025 - AI Security
Thursday, June 12
Shadow Vulnerabilities in AI/ML Data Stacks - What You Don’t Know CAN Hurt You
Thursday, June 12, 2025 - 2:40pm to 3:25pm
The adoption of open-source AI software introduces a new family of vulnerabilities to organizations. Some components in AI, like model serving, include Remote Code Execution (RCE) by design, like when loading pre-trained models from external sources. Traditional SCA and SAST approaches are not built for the AI ecosystem leaving a huge & insecure attack surface. The irony is that in the AI ecosystem, security issues such as remote code execution are actually a feature and not a bug, often specified explicitly in the docs, which most devs don’t read. AI models are often downloaded from...