Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third Party @OWASPGLOBAL
Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third Party  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/77/Global_AppSec_DC_Red%20vs%20Blue_Final.pdf

Context & Problem Statement
As organizations adopt agentic AI systems where LLMs autonomously plan, decide, and act, they must make sure they’re putting the right protections in place, so they won't unknowingly introduce invisible third-party dependencies. If the right protections aren’t put in place, agentic AI systems can blur traditional boundaries of identity, behavior, and trust. They do this by autonomously forming ephemeral relationships with tools, APIs, and other agents. These connections may be invisible to defenders and to everyone who relies on or uses these systems. In a Red team vs. Blue team context, this creates a dynamic battlefield where defenders must contend with novel threats like prompt injection, goal hijacking, and memory poisoning, while attackers exploit the very autonomy that makes these systems powerful.

Solution
This session presents a practical, AI-aware approach to threat modeling agentic AI systems because enabling AI with third party dependencies or Intergrations in said scenarios requires upfront planning. Using a Red vs. Blue simulation, we dramatize real-world attacks and defenses to expose vulnerabilities such as prompt injection, goal hijacking, and memory poisoning, and how successful exploitation can lead to impersonation, information leakage, and decision drift.

One speaker (Red Team) will demonstrate how attackers can manipulate agentic AI systems using techniques such as:
- Prompt Injection
- Goal Hijacking
- Memory Poisoning

The other speaker (Blue Team) will respond with defense strategies like:
- Agent policy enforcement
- Guardrails and tool access control
- Updated threat modeling frameworks like MAESTRO for dynamic AI behaviors
The session format will be engaging and interactive, showcasing both offense and defense in real-time. Attendees will learn how to adapt traditional frameworks and apply layered mitigations to secure unpredictable, autonomous AI systems.

Value Proposition
In this session, attendees will gain a threat-informed mindset and practical tools to assess and secure AI integrations, using adapted frameworks like STRIDE & MAESTRO and lightweight checklists for architecture reviews. Through a Red vs. Blue simulation, they’ll learn how to evaluate the unique risks of agentic AI systems and walk away with actionable strategies to defend against real-world attack scenarios.

Audience Takeaways
After attending this session, participants will:
- Identify critical risks in third-party AI integrations and agentic systems, including goal hijacking, prompt injection, and memory poisoning.
- Understand how agentic AI differs from traditional architectures and why it challenges conventional security assumptions.
- Adapt threat modeling techniques like STRIDE & MAESTRO to account for autonomy, tool use, and multi-agent orchestration.
- Recognize architectural weak points across model APIs, plugin ecosystems, and agent-based data flows.
- Apply practical checklists and reference models to evaluate AI behavior, identity, and decision-making patterns.
- Use Red vs. Blue simulations to train teams on real-world attack scenarios and implement effective blue team defenses.

Spandana Gorantla (she/her/hers) is a security engineer specializing in application and product security, currently focused on AI threat modeling. With a background spanning cloud security, secure architectures, and product security in fast-paced environments, she brings a practical and approachable lens to emerging security challenges.
Outside of work, Spandana is passionate about making security more accessible, building community, and mentoring aspiring professionals from underrepresented backgrounds. She’s also a big fan of hiking, lifting heavy things, and eating good food — preferably all in the same weekend.
linkedin.com/in/spandana-gorantla

At Adobe, I focus on fortifying AI/ML security and streamlining IAM services, which has significantly elevated our security framework. My expertise in conducting exhaustive application security testing and code reviews has been instrumental in protecting against sophisticated cyber threats. Our team's commitment to enhancing security through these initiatives has led to robust protection mechanisms for emerging technologies.
Previously at Amazon, I honed my skills in security assessments and bug bounty triage, particularly for Amazon Pay products, ensuring the secure integration of new payment instruments. My ability to collaborate effectively with service teams and PMs has facilitated the resolution of critical security issues, contributing to a more secure product ecosystem. Passionate about security innovation, I continue to drive strategic improvements in product security to deliver an uncompromising user experience.
linkedin.com/in/gilles-biagomba

Managed by the OWASP® Foundation
owasp.org
Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third PartySecure Financial Analytics with Homomorphic Encryption and GAN Driven Data Track 2Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan WorcelSelf-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving ThreatsAMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary VulnerabilityHow a Clean Security Audit Became a Breach Notification Six Months Later- Track 2OWASP AIVSS Project: What it is, why we need it and how we are doing itOWASP Mobile Application Security (MAS) - Sven Schleier, Carlos HolgueraGetting an LLM to Hack Itself: On AI, Moral Dilemmas, and SecurityLost in Translation: Exploiting Unicode NormalizationOWASP Mobile Application Security (MAS) - Sven Schleier & Carlos HolgueraThe Sentinel-Aura Architecture: Orchestrating Agentic AI for Autonomous Endpoint Remediation
OWASP Foundation |

Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third Party

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER