Program JavaZone

Foredrag Onsdag 2. september

The 1% Problem: An Introduction to AI Security

Room 8

Engelsk 45 min AI Security

Lars Smeby

Lars is a developer and security consultant at Blank. For the past 13 years he has worked across the full stack on a wide range of technologies, delivered security training, and performed penetration tests. He also sits on the OWASP Oslo chapter committee.

AI is rapidly becoming embedded in every layer of our stack, from integrated product features to the autonomous agents used to write code. This shift has created an unfamiliar attack surface that many developers are navigating for the first time. We have spent decades learning to secure deterministic systems, but AI introduces a fundamentally different set of risks that require a new way of thinking.

In this talk, we will explore the core mechanics of Large Language Models to see why their probabilistic nature makes them inherently difficult to secure. The session navigates the most critical threats identified by both the OWASP Top 10 for LLM Applications and the separate Top 10 list for Agentic Applications, focusing specifically on how prompt injection can compromise both your users and your development environment. We will look at examples of how AI in the real world has gone wrong, and also see how your AI coding tools introduce threats directly into your workflow.

This talk is for all developers. You'll get an introduction to the security risks when working on AI features or using AI coding tools.

  1. Bootiful Spring Boot 4 Room 1
  2. Let’s create a tiny LLM library together Room 2
  3. My Year with Claude: Building Midimeria - music production analytics Room 3
  4. Talk to me Java! Room 4
  5. What RSCs can do in Next.js today Room 5
  6. Sunset as a Service: Når målet er EOL Room 6
  7. The best way to fetch multi-level hierarchies from a RDBMS using Java Room 7
  8. Conways lov i praksis Room 6
  9. Metodikk som tvangstrøye Room 6