Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems @OWASPGLOBAL
Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 3 weeks ago
While Red Team AI research often focuses on attacking models in isolation or proof of concepts on enterprise Copilots, real-world AI/ML systems integrate complex tool chains and guardrails that create a different attack surface. In this 45-minute talk, we discuss our experience focused on threat model-informed dynamic testing for indirect prompt injection. The approach follows a structured workflow of target profiling, guardrail analysis, tool enumeration, and automated testing. Our findings from production testing highlight the need for repetitive, automated approaches to reliably exploit deployed AI/ML systems. Finally, we will release a set of open-source labs including built-in guardrails for practical exercise work.

Will Vandevanter
Trail of Bits
Security Engineer - AI/ML

Will Vandevanter is a Security Engineer at Trail of Bits on the AI/ML team, where he performs security audits across all layers of AI/ML infrastructure. Will has previously spoken at Blackhat, DEFCON, OWASP and a number of other conferences. He has also released popular open source tools and trained hundreds through in-person and online courses.

@willvandevanter
linkedin.com/in/willis-vandevanter-82a0501...
trailofbits.com (blog)

Managed by the OWASP® Foundation
owasp.org
Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML SystemsUnlocking Secure Development: A Deep Dive into OWASP ASVSNavigating the complex and rapidly evolving world of product and application security regulationsModernizing the Application Penetration Engagement and Reporting Lifecycle - Ryan ArmstrongSecuring Distributed Systems with Privacy-Aware Governance and ML Controls - Track 2Breaking the Black Box - Using the OWASP Threat Model Library to End Security via ObscurityHackuracy: Boosting AST accuracy through hacking - Andres RoldanO My Data: OData Injection attack in Microsoft Power Platform and UiPath - Amichai ShulmanBuilding a Static Analyzer from ScratchHidden Risks of Integrating AI: Extracting Private Data with Real-World ExploitsThreat Modeling Developer Behaviour: The Psychology of Bad CodeLiving off Microsoft Copilot - Michael Bargury
OWASP Foundation |

Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER