Skip to main content

Agentic AI Security Risks: Threat Modeling with Shaked Reiner

N2K NetworksMay 2, 202521 min104 views
26 connections·40 entities in this video

Understanding Agentic AI

  • 💡 Agentic AI refers to systems where an LLM controls the program's flow, enabling autonomous actions like web browsing or code execution.
  • ⚡ Unlike traditional LLMs, agentic systems can perform actions in the real world, making vulnerabilities more severe.

Threat Landscape of Agentic AI

  • 🎯 Research systematically maps the threat landscape, focusing on how known LLM vulnerabilities apply to agentic systems.
  • ⚠️ Traditional access vectors (server-level attacks) remain relevant, alongside a new surface of LLM-based attacks like prompt injections and model manipulations.

Identity and Access Management Challenges

  • ❓ The industry is still determining how to classify AI agents (users, machines, bots), complicating traditional IAM.
  • 🔑 Granting agents permissions, access tokens, and accounts is necessary for them to act, but requires careful consideration of their identity and access levels.
  • 📈 Overprivileging agents is a severe risk, as an attacker with limited access might manipulate an agent with broader permissions to perform actions they couldn't otherwise.

Lifecycle Management and Best Practices

  • 🔒 Organizations must trust the base LLM models and the developers of agents, or carefully monitor their own custom-developed agents.
  • ⚙️ Agent behavior can be drastically altered by changing instructions or system prompts, necessitating monitoring of these configuration files.
  • ✅ Key recommendations include: never trust the LLM, validate and sanitize LLM outputs, limit the LLM's scope of action, apply the principle of least privilege, manage credentials diligently, and implement robust security monitoring and threat detection.

Future of Agentic AI and Cybersecurity

  • 🚀 The pace of AI development is extremely fast, making it a moving target for security professionals.
  • 🔮 Agentic AI will likely look vastly different in a year or two, with enhanced functionality and productivity.
  • ⚔️ New, advanced attack vectors exploiting AI agents are expected to emerge, requiring novel security measures.
Knowledge graph40 entities · 26 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters8 moments

Key Moments

Transcript75 segments

Full Transcript

Topics12 themes

What’s Discussed

Agentic AILLM SecurityThreat ModelingPrompt InjectionModel ManipulationIdentity and Access ManagementOverprivilegingLeast PrivilegeCybersecurityAI AgentsCyberArkSecurity Researcher
Smart Objects40 · 26 links
Concepts· 24
Companies· 8
People· 5
Media· 1
Products· 2