SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Prompt injection is one of the most critical and misunderstood risks in modern AI systems, especially as applications evolve from simple chatbots to autonomous, agentic workflows.
This talk takes a deep dive into prompt injection by unpacking what prompts are, where they come from, and why untrusted instructions hidden in user input, external content, tools, and memory can fundamentally alter AI behavior. We will examine direct and indirect prompt injection, contrast chatbot risks with agent-specific risks, and explore how single-agent and multi-agent systems expand the attack surface and blast radius. Through real-world examples, common payload patterns, multi-hop injection scenarios, and the challenges introduced by long context windows, attendees will gain a practical understanding of how these attacks work in practice.
The session will close with OWASP-aligned mitigations and broader defensive strategies to help security practitioners, developers, and architects build more resilient AI applications.


Vis Chirravuri brings more than 20 years of cybersecurity experience to SANS SEC545 and SEC546, with deep work in AI security, AppSec, DevSecOps, product security governance, and software supply chain security.
Read more about Viswanath (Vis) ChirravuriElevate your skills in the epicenter of U.S. policy and defense. This D.C. area event offers elite training, plus access to monuments, museums, and networking opportunities in a city that never stops.
