This talk explores the hidden risks in apps leveraging modern AI systems — especially those using large language models (LLMs) and retrieval-augmented generation (RAG) workflows — and demonstrates how sensitive data, such as personally identifiable information (PII) and social security numbers, can be extracted through real-world attacks. We demonstrate model inversion attacks targeting fine-tuned models and embedding inversion attacks on vector databases, among others.
DEF CON 33 - Exploiting Shadow Data in AI Models and Embeddings
calendar_today
October 20, 2025
domain
ironcore-labs