Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan Worcel @OWASPGLOBAL
Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan Worcel  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
Leveraging AI for AppSec presents promise and danger, as let’s face it, you cannot do everything with AI, especially when it comes to security. At our session, we’ll delve into the complexities of AI in the context of auto remediation. We’ll begin by examining our research, in which we used OpenAI to address code vulnerabilities. Despite ambitious goals, the results were underwhelming and revealed the risk of trusting AI with complex tasks.


Our session features real-world examples and a live demo that exposes GenAI’s limitations in tackling code vulnerabilities. Our talk serves as a cautionary lesson against falling into the trap of using AI as a stand-alone solution to everything. We’ll explore the broader implications, communicating the risks of blind trust in AI without a nuanced understanding of its strengths and weaknesses.


In the second part of our session, we’ll explore a more reliable approach to leveraging GenAI for security relying on the RAG Framework. RAG stands for Retrieval-Augmented Generation. It's a methodology that enhances the capabilities of generative models by combining them with a retrieval component. This approach allows the model to dynamically fetch and utilize external knowledge or data during the generation process.

Attendees will leave with a clear understanding of how to responsibly and effectively deploy AI in their programs — and how to properly vet AI tools.

-

Managed by the OWASP® Foundation
owasp.org
Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan WorcelSelf-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving ThreatsAMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary VulnerabilityHow a Clean Security Audit Became a Breach Notification Six Months Later- Track 2OWASP AIVSS Project: What it is, why we need it and how we are doing itOWASP Mobile Application Security (MAS) - Sven Schleier, Carlos HolgueraGetting an LLM to Hack Itself: On AI, Moral Dilemmas, and SecurityLost in Translation: Exploiting Unicode NormalizationOWASP Mobile Application Security (MAS) - Sven Schleier & Carlos HolgueraThe Sentinel-Aura Architecture: Orchestrating Agentic AI for Autonomous Endpoint RemediationOWASP Global Board of Directors Meeting - March 2025(Do Not Publish) Building a Static Analyzer from Scratch
OWASP Foundation |

Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan Worcel

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER