One Poisoned Artifact Can Steer Your AI: How Robust Are Your LLM-Assisted Security Workflows? @FIRSTdotorg
One Poisoned Artifact Can Steer Your AI: How Robust Are Your LLM-Assisted Security Workflows?  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 4 hours ago
Cheng-Lin Yang (CyCraft AI Lab, Taiwan, TW), Yen-Shan (Lily) Chen (CyCraft AI Lab, TW)

As SOCs, CSIRTs, and incident‑response teams adopt LLM and RAG systems for alert triage, investigation, and automation, they introduce a new attack surface: data‑level manipulation in the artifacts these systems ingest. This session shows how a single attacker‑crafted item — such as a phishing email, chat transcript, incident note, or external report — can be formatted so that retrieval baits are consistently surfaced by embedding models and malicious instructions are attended to by generative LLMs. Rather than exploiting model internals, attackers simply shape document structure to steer what the system retrieves and what it outputs.

We will walk through a live, end‑to‑end demonstration of how such an artifact biases retrieval, influences generation, and ultimately alters the analyst‑facing narrative of an investigation. The session concludes with practical, low‑cost defenses that SOCs and CSIRTs can deploy immediately to harden AI‑augmented workflows and detect adversarial influence before it reaches decision‑makers.

---

Dr. Yang Cheng-Lin, the data science director at CyCraft Technology, holds a PhD in Artificial Intelligence from the University of Edinburgh. His focus is on security issues in AI applications. His notable work has been featured at prestigious academic conferences like EMNLP and NeurIPS, and his expertise has been showcased at various cybersecurity conferences, including the FIRST CTI Summit, Black Hat USA, Code Blue Japan, HITCon Enterprise, and SINCON.

Yen-Shan (Lily) Chen is a data scientist at CyCraft Technology, where she currently focuses on research into potential vulnerabilities in Retrieval-Augmented Generation (RAG) frameworks and developing methods to evaluate them. Lily has previously presented at major cybersecurity conferences such as Code Blue Japan and SINCON, and she also published her work at the renowned ACL conference.
One Poisoned Artifact Can Steer Your AI: How Robust Are Your LLM-Assisted Security Workflows?The Vulnerability Identity CrisisSpeeding Up Vulnerability Triage: Automating Context Retrieval with AI AgentsPanel: Tips and Tricks to Run a CSIRT in Low-income and Fragile ContextsEngaging with the Media to Foster Cybersecurity ResilienceEvading in Plain Sight: How Adversaries Beat User-Mode Protection EnginesVulnrichment PlaygroundBenchmarking Your Constituency: A Practical Framework for CERTs with Results from Academic SectorBillions of Indicators, Zero Action: How We Fixed ThatCritical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is Now
FIRST |

One Poisoned Artifact Can Steer Your AI: How Robust Are Your LLM-Assisted Security Workflows?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER