Nothing Looks Broken: Investigating AI When the Model Behaves

No ratings

Presented at BSidesCharm 2026 by

Traditional DFIR assumes that compromise produces artifacts, failures, or clearly malicious inputs. AI systems challenge that assumption. Models can be trained, deployed, and perform “as expected” while still producing harmful, biased, or manipulated outcomes. This talk explores how data poisoning and manipulation in AI systems often target results rather than content, making traditional IOC-based detection ineffective. Using a DFIR mindset, the session focuses on how investigators can identify behavioral, temporal, and statistical indicators that suggest something is wrong even when no individual data point appears malicious. Attendees will leave with a practical framework for thinking about AI investigations, emphasizing baselining, change correlation, and forensic readiness over perfect attribution.