LLM Backdoors in Plain Sight: The Threat of Poisoned Templates @OWASPGLOBAL
LLM Backdoors in Plain Sight: The Threat of Poisoned Templates  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
Organizations deploying AI models face a critical blind spot: while they secure model weights and validate inputs, attackers can embed persistent malicious instructions directly within chat templates, bypassing all existing security controls. In this session, we present a novel supply chain attack that exploits the GGUF (GPT-Generated Unified Format) model distribution standard to manipulate AI responses during normal conversations.

This attack targets a massive ecosystem—with over 124,000 GGUF files currently distributed across platforms like Hugging Face. We will begin by examining how these files package chat templates alongside model weights, creating an attack surface that targets any user or system using these models. We will then show how attackers can exploit this distribution model to smuggle malicious instructions into model components, with the deception extending to distribution platforms where attackers can manipulate repositories to display clean templates while downloaded models contain malicious instructions.

From there, we will demonstrate how attackers using this novel vector can achieve persistent compromise that affects every user interaction while remaining completely invisible to both users and security systems. This attack vector bypasses all existing guardrails and system prompts while remaining undetected by current security scanners that focus only on infrastructure threats, creating a previously unknown supply chain compromise that fundamentally undermines user trust in AI-generated content.

Our talk will demonstrate how this attack vector bypasses existing guardrails and system prompts while remaining undetected by current security scanners that focus only on infrastructure threats. Attendees will learn practical techniques to audit GGUF files for template manipulation, understand why existing security controls fail against this vector, and implement detection strategies to protect AI deployments from this supply chain compromise.

Ariel Fogel
Pillar Security
Founding Engineer and Researcher

Ariel Fogel is a founding engineer & researcher at Pillar Security, where he hardens AI applications against real-world attacks and compliance risks. Over the past decade, he has built production systems in Ruby, TypeScript, Python, and SQL, shipping everything from full-stack web apps to data analytics pipelines. His academic and professional research work spans data-science methods, learning analytics, health policy, and cybersecurity. Ariel co-hosts the podcast “LLM Cybersecurity,” dissecting academic papers to demystify jailbreaks, prompt injections, and emerging AI-security research. In the few hours a week he's not thinking about AI, engineering, and security, Ariel spends time with his family or plays jazz on the upright bass. He's found that whether you're plucking strings or navigating family dynamics, success is all about harmony and knowing how to improvise.
linkedin.com/in/arielfogel
fogel.dev (blog)

Managed by the OWASP® Foundation
owasp.org
LLM Backdoors in Plain Sight: The Threat of Poisoned TemplatesPeeling Back the Plastic: Finding 0-Days in IoT Devices202006 June 2020 Global Board MeetingBeyond the Checklist: Adversary Simulation for Proactive Insecure Design Discovery track 2German OWASP Day HighlightThreat Modeling in the Age of AI - Susanna CoxTwo Paths to Security Upskilling: Startup and EnterpriseTransparency Exchange API: How Do You Find the SBOM for a Smart Light Bulb?OWASP Top 10 Risks for Open Source Software - George Apostolopoulos“The Developer First Security Mindset”   Making Security a Product Feature, Not a BlockerEveryone Can Play! Building CTFs for Non-Security FolksLLMs in AppSec: Why They Still Need a Chaperone
OWASP Foundation |

LLM Backdoors in Plain Sight: The Threat of Poisoned Templates

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER