Attacking AI systems

At Seattle Bsides 2025, I demonstrated novel vulnerabilities introduced by generative AI models. I explored the history of prompt injection, explained it in detail. Last, I ran a live demo with an AI-integrated logstics system that I created, where the audience helped me craft various prompt injection attempts. During this demo, we were able to successfully get to an OS command injection vulnerability in the AI plugin through prompt injection.