Keynote: Cramhole, LaFleur: Indirect Prompt Injection

Keynote: Cramhole, LaFleur: Indirect Prompt Injection

🎙 Diana Kelley 👥 70K 📅 May 4, 2026 ⏱ 24 min 👁 116 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

indirect prompt injectioncontext windowLLMagentic systemssecurity controls

Summary

Diana Kelley, CISO at Noma Security, presents a keynote on indirect prompt injection at the SANS AI Cybersecurity Summit 2026. She uses the metaphor of a ‘cram hole’ to describe the context window of LLMs, where all inputs—system instructions, user prompts, retrieved data, memory, and tool outputs—are flattened into a single token stream. This flattening means the model cannot distinguish between trusted and untrusted content, making it vulnerable to indirect prompt injection. She illustrates this with a real attack on Salesforce agents where sensitive data was exfiltrated via a malicious image URL. Kelley argues that relying on embedded guardrails is insufficient and instead proposes a shift to architectural risk management. She outlines five conceptual trust boundaries: instruction, knowledge, retrieval, memory, and tool action. For each, she suggests practical controls such as input validation, allow-listing, memory hygiene, and human-in-the-loop for high-impact actions. She emphasizes that LLMs are ‘goldfish’ with no inherent memory or judgment, so security must be implemented in the surrounding software. The talk concludes with a call to map these conceptual boundaries to actual system architectures and to assume compromise in AI system design.

185 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the often-overlooked security challenges of LLM-based systems, particularly indirect prompt injection. Kelley’s argument is coherent and well-structured, moving from the fundamental mechanics of LLMs to practical security controls. She uses relatable examples, such as the Chipotle token abuse and a memory mishap, to illustrate abstract concepts. However, the argumentation relies heavily on anecdotal evidence and personal experience rather than empirical data or formal research. The recommendation to focus on architectural boundaries is sound and actionable, but the talk could benefit from more concrete implementation details and references to existing frameworks.

Scientific Rigor, Source Quality, Title Accuracy

The talk demonstrates a good understanding of the subject, but the scientific rigor is moderate. Kelley cites real-world incidents (e.g., Salesforce agent attack) but does not provide formal citations or links to technical reports. The title is catchy but may not clearly convey the technical content to a broad audience. The talk is based on the speaker’s expertise and industry experience, which adds credibility, but it lacks the depth of a peer-reviewed presentation. The description mentions a link to SANS Summits, but no specific sources are cited in the video itself.

202 words

Title / Content Match

The title is catchy and reflects the core topic of indirect prompt injection, though it may be confusing to those unfamiliar with the movie reference.

Quality & Reliability

7/10

The talk is based on the speaker's expertise and real-world examples, but lacks formal citations and detailed technical depth. It provides a high-level overview of indirect prompt injection and practical recommendations, but the claims are not backed by published research or official documentation.

Key Moments

Cited Sources

  • SANS Summits — Link to upcoming SANS Summits for further learning.

Concurring Sources

Contribution & Novelties

The talk reframes indirect prompt injection as an architectural risk management challenge rather than a simple vulnerability to patch. It introduces the concept of five conceptual trust boundaries (instruction, knowledge, retrieval, memory, tool action) and provides practical controls for each. This perspective is valuable for security professionals designing AI systems.

Pour aller plus loin :

89 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher scores in quantity of information and technical level. This indicates a talk that provides a good overview but lacks deep technical detail and rigorous sourcing.

Reliability 6/10

💬 No comments were provided for analysis.