Artificial Intelligence is only as trustworthy as the data it learns from. As organizations increasingly adopt AI and Large Language Models (LLMs) for critical business functions, attackers are shifting their focus from exploiting deployed models to compromising the training data itself. Data poisoning and backdoor attacks represent a growing class of threats capable of manipulating AI behavior without altering the underlying algorithms, making them difficult to detect through traditional security controls.
This session explores how seemingly legitimate training data can be weaponized to influence model predictions, introduce hidden backdoors, and compromise decision-making in AI systems. Drawing on real-world incidents and research—including Microsoft’s Tay chatbot, the Microsoft 365 Copilot “Confused Pilot” attack, vulnerabilities in medical LLMs, and supply-chain risks associated with public datasets—the session highlights the evolving landscape of AI security threats.
Participants will gain a practical understanding of various data poisoning techniques, including feature collision, support vector machine (SVM) poisoning, bullseye polytope attacks, and backdoor poisoning. Through a live demonstration using IBM’s Adversarial Robustness Toolbox (ART), attendees will witness how poisoned datasets can manipulate AI models and how hidden triggers can activate malicious behaviors.
The session will also distinguish data poisoning from prompt injection, discuss the business and security implications of compromised AI pipelines, and present practical strategies for securing AI training data, validating datasets, strengthening the AI supply chain, and implementing robust defenses against poisoning attacks. Attendees will leave with actionable insights to help build resilient, trustworthy, and secure AI systems.
Key Takeaways
- Mechanisms of Data Poisoning: Understand how data poisoning and backdoor attacks compromise AI models from within training pipelines.
- Real-World Incident Analysis: Learn from high-profile AI security incidents and evaluate their enterprise and business impacts.
- Live Hands-on Demonstrations: Experience live attack demonstrations using the IBM Adversarial Robustness Toolbox (ART).
- Poisoning vs. Prompt Injection: Clearly differentiate between data poisoning at training/retrieval time and inference-time prompt injection attacks.
- Defense Strategies: Discover practical techniques to detect, prevent, and mitigate AI poisoning attacks across datasets and supply chains.
- Trustworthy AI Architecture: Gain actionable best practices for architecting resilient and secure enterprise AI systems.
Target Audience
- Cybersecurity Professionals, Security Researchers, and Penetration Testers.
- AI/ML Engineers, Data Scientists, and DevSecOps Practitioners.
- CISOs, Security Leaders, GRC Professionals, and Technology Architects.
- Students, Academics, and AI Security Enthusiasts.
Prerequisites
- A basic understanding of Artificial Intelligence (AI) and Machine Learning (ML) concepts.
- Basic knowledge of cybersecurity principles and common attack techniques.
- Familiarity with Large Language Models (LLMs) and the AI lifecycle is helpful but not mandatory.
- No prior experience with IBM Adversarial Robustness Toolbox (ART) is required.