Keynote: Cramhole, LaFleur: Indirect Prompt Injection

SANS Institute ยท Beginner ยท๐Ÿง  Large Language Models ยท1w ago
Keynote: Cram it up your Cramhole, LaFleur: Understanding and Managing Indirect Prompt Injection ๐ŸŽ™๏ธ Diana Kelley, CISO at Noma Security ๐Ÿ“ Presented at SANS AI Cybersecurity Summit 2026 Indirect prompt injection is not just another vulnerability to patch. It is a structural reality of how large language models operate. This session explores how the context window, or ""cram hole,"" contributes to the success of prompt injection exploits and why that reality fundamentally reshapes how we must think about trust, control, and data boundaries in AI systems. Attendees will learn how system instructions, user inputs, retrieved content, and tool outputs blend into a single token stream. The model does not see trust levels or privilege boundaries. Because models cannot reliably distinguish between authoritative instructions and malicious content, and because nondeterminism makes simple refusal strategies brittle, relying on embedded guardrails alone is insufficient. By reframing indirect prompt injection as an architectural risk management challenge, this session shifts the focus from patching to design. Participants will leave with practical guidance on designing resilient AI systems that assume compromise, limit blast radius, and build layered controls that reduce harm even when injection attempts succeed. Explore upcoming SANS Summits to continue learning from leading voices in cybersecurity: https://go.sans.org/summits
Watch on YouTube โ†— (saves to browser)
Sign in to unlock AI tutor explanation ยท โšก30

Related AI Lessons

โšก
Build AI Compliance SaaS with RAG
Build a scalable AI-powered compliance monitoring SaaS with RAG and regulatory alerts to help businesses stay on top of regulatory changes
Dev.to AI
โšก
How We Cut LLM API Costs by 94%: A 3-Layer Caching Strategy
Cut LLM API costs by 94% using a 3-layer caching strategy without sacrificing quality or performance
Dev.to AI
โšก
I Asked AI to Teach Algebra. The First Result Was Slop. Hereโ€™s How We Fixed It.
Learn how to improve AI-generated educational content by refining prompts and fine-tuning models, as demonstrated by a project to create an AI-generated algebra course
Medium ยท Machine Learning
โšก
AI Is Like a Super Smart Toy Box โ€” But It Still Needs You
Discover how AI can augment human capabilities, but still requires human input and oversight to function effectively
Medium ยท AI
Up next
5 Levels of AI Agents - From Simple LLM Calls to Multi-Agent Systems
Dave Ebbelaar (LLM Eng)
Watch โ†’