Attacking AI @OWASPGLOBAL
Attacking AI  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 3 weeks ago
Attacking AI is a one of a kind session releasing case studies, tactics, and methodology from Arcanum’s AI assessments in 2024 and 2025. While most AI assessment material focuses on academic AI red team content, “Attacking AI” is focused on the task of assessing AI enabled systems. Join Jason as he discusses his seven point methodology to assessing these systems and releases Arcanum’s prompt injection taxonomy and other resources for aspiring testers.

Jason Haddix
Arcanum Information Security
CEO

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security and the field CISO for flare.io. Arcanum is a world class assessment and training company. Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

Managed by the OWASP® Foundation
owasp.org
Attacking AIOWASP Board of Directors 2026 Officer ElectionsI Dont Trust AI Agents (And Neither Should You): Building Production-Ready Architectures - Track 1Ignoring the Hype: How to Design Your Cloud Architecture Regardless of Your Cloud of ChoiceTowards the next generation OWASP CRS ruleset languageOWASP DevSecOps Maturity Model (DSOMM) - Timo PagelAutomating Security Test Cases Based On ASVS - Aram HovsepyanOWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis - Track 1Uncovering 100k Security ViolationsSupercharge Your APPSEC Program with OWASP - Appdome Consumer Mobile Security Report and OWASP MASVSOWASP Global AppSec EU 2025 Closing CeremonyPractical Software Supply Chain Security Solutions - Robert Marion
OWASP Foundation |

Attacking AI

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER