
AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025
Keywords
Summary
134 words
Critical Evaluation
Value of the Information & Strength of the Argument
The talk provides valuable insights into the emerging security challenges of AI agents, supported by concrete examples and personal experiences. The argumentation is solid, as the speaker systematically addresses each threat category with evidence and practical implications. She effectively argues that AI agents introduce new attack vectors while also reminding that traditional vulnerabilities persist. The talk is persuasive and well-structured, making a strong case for proactive security measures.
Scientific Rigor, Source Quality, Title Accuracy
The speaker demonstrates scientific rigor by referencing real incidents and providing links to resources in the description. However, the talk lacks formal citations and relies on anecdotal evidence and personal experience. The title accurately reflects the content, and the talk is well-organized. The speaker’s credibility as a security researcher adds to the reliability of the information.
139 words
Title / Content Match
The title accurately reflects the content, which covers building, defending, and attacking AI-enabled applications.
Quality & Reliability
8/10
The talk is given by a recognized security researcher with a PhD in AI and cybersecurity, and includes real-world examples and references to actual incidents. However, it is a conference talk with limited depth and no formal citations, so the score is high but not perfect.
Chapters
Cited Sources
- Xbow Blog: Akamai CloudTest XXE — Referenced as a resource for a specific vulnerability example.
- YOW! Conference Session Page — Full abstract and session details.
- Katie Paxton-Fear's Website — Speaker's personal site.
- Katie Paxton-Fear's GitHub — Speaker's GitHub profile.
- Katie Paxton-Fear on LinkedIn — Speaker's LinkedIn profile.
- Katie Paxton-Fear on Bluesky — Speaker's Bluesky profile.
Concurring Sources
- OWASP Top 10 for LLM Applications — Provides a list of common vulnerabilities in LLM applications, aligning with the talk's themes.
- Anthropic's Responsible Scaling Policy — Discusses safety measures for AI, relevant to the talk's discussion of AI security.
Dissenting Sources
- AI agents are not a security threat — Some argue that AI agents are not fundamentally different from other software and that existing security measures suffice. This talk challenges that by highlighting novel attack vectors.
External References
Contribution & Novelties
The talk provides a comprehensive overview of AI agent security threats, synthesizing current knowledge and real-world examples. It highlights the often-overlooked attack surface of agent frameworks and the potential for AI to be used in offensive operations. The speaker’s perspective as a security researcher adds credibility.
Pour aller plus loin :
- OWASP Top 10 for LLM Applications — Relevant framework for AI security.
- Prompt Injection Attack — Key attack vector discussed.
- Model Context Protocol (MCP) — Official site for MCP, the protocol mentioned in the talk.
86 words
Radar Profile
The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a talk that is informative and credible but not overly technical. The overall balance suggests a well-rounded presentation suitable for a broad technical audience.
💬 No comments were provided for analysis.