Beyond Interactions: Hacking Chatbots Like a Pro

No ratings

Presented at BSides Denver 2024 by

​​​​In an era where AI-driven chatbots seamlessly integrate into our daily lives, it's high time we understand the risks caused by vulnerabilities associated with these chatbots.In this talk, we will explore common vulnerabilities encountered in AI chatbots, highlighting the top three categories most susceptible to exploitation: Prompt Injection, Insecure Output Handling, and Training Data Poisoning. Through a combination of live hacking demonstrations and real-world attack scenarios, we will illustrate how malicious actors leverage these vulnerabilities to compromise sensitive information, propagate misinformation (e.g., spreading fake news articles), etc. By the conclusion of our talk, participants will have gained a deeper awareness of the challenges inherent in securing AI chatbots and will be equipped with actionable insights to bolster their defenses. We will also extend an invitation to participants to use our lab exercise, where they can further explore and exploit additional attack paths beyond those covered in the talk.