SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Prompt injection is one of the most critical and misunderstood risks in modern AI systems, especially as applications evolve from simple chatbots to autonomous, agentic workflows.
This talk takes a deep dive into prompt injection by unpacking what prompts are, where they come from, and why untrusted instructions hidden in user input, external content, tools, and memory can fundamentally alter AI behavior. We will examine direct and indirect prompt injection, contrast chatbot risks with agent-specific risks, and explore how single-agent and multi-agent systems expand the attack surface and blast radius. Through real-world examples, common payload patterns, multi-hop injection scenarios, and the challenges introduced by long context windows, attendees will gain a practical understanding of how these attacks work in practice.
The session will close with OWASP-aligned mitigations and broader defensive strategies to help security practitioners, developers, and architects build more resilient AI applications.


Mark loves the ever-changing landscape of security and views it as a puzzle that must be solved. He especially loves the challenges in ICS security, where the cyber meets the physical. There is no greater success than a safe and effective process.
Read more about Mark BristowAs one of SANS’ most anticipated annual events, CDI 2026 offers a flagship training experience in D.C. Join top-tier instructors for cutting-edge courses. This is the definitive end-of-year training event—designed for defenders ready to level up.