Here Be Dragons: Threat Modeling AI Systems with OWASP Threat Dragon
About this Event
AI systems create failure modes traditional security reviews often miss: prompt injection, sensitive data exposure, retrieval manipulation, unsafe tool use, overreliance on model output, and weak monitoring.
In this hands-on workshop, participants will threat model a realistic AI system: an internal RAG assistant that uses enterprise documents, a vector database, identity controls, logging, and a third-party LLM. Using OWASP Threat Dragon and OWASP AI threat references, participants will map the system, identify trust boundaries, surface AI-specific threats, prioritize the most consequential scenarios, and turn them into a practical risk backlog.
This is a working session, not a lecture. The goal is to move from vague AI risk concerns to concrete threats, controls, owners, and decisions.
Where is it happening?
Event Location & Nearby Stays:
USD 7.18



















