AI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir Sadon @OWASPGLOBAL
AI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir Sadon  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
owasp2024globalappsecsanfra.sched.com/event/1g3Ym/ai-goat-a-damn-vulnerable-ai-infrastructure

Compromising AI infrastructure can have devastating consequences, making it a prime target for attackers. Often, a simple misconfiguration or vulnerability in AI applications is all it takes to compromise the entire system. Many developers are not fully aware of the threat landscape and end up deploying vulnerable AI infrastructures. Traditional pentesting tools like DVWA and bWAPP have helped the infosec community understand popular web attack vectors, but there is a gap when it comes to AI environments. In this talk, we introduce AI Goat, a deliberately vulnerable AI infrastructure featuring vulnerabilities based on the OWASP AI Top 10. AI Goat mimics real-world AI applications but includes added vulnerabilities, providing security enthusiasts and pen-testers with an easy-to-deploy and destroy platform to learn how to identify and exploit AI vulnerabilities. The deployment scripts will be open-source and available after the talk.

-

Managed by the OWASP® Foundation
owasp.org
AI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir SadonThe History of the OWASP Developer GuideOWASP AI Exchange experts on the future of security for AI - Panel hosted by Chloé Messdaghi5 Steps to VEX Success: Managing the End-to-End Workflow - Cortez Frazier Jr.AppSec Israel HighlightSo You Want To Be An OWASP Speaker?Defending Against New Phishing Attacks that Abuse OAuth Authorization Flows - Jenko HwongSecurity Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification202010 October 2020 Global Board MeetingConnecting the dots: 5 lessons learned from an 8 year journey of an AppSec Program track 1Beyond the Checklist: Building an AppSec Culture That Engineers Don’t DreadOWASP Software Assurance Maturity Model (SAMM) - Aram Hovsepyan, Sebastien Deleersnyder
OWASP Foundation |

AI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir Sadon

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER