When Agents Go Rogue: A Threat Model and Defense Framework for Agentic AI Systems
About This Session
As enterprises rush to deploy agentic AI systems — autonomous agents that plan, reason, and execute multi-step tasks across tools and APIs — the security community is confronting an entirely new threat landscape. Unlike traditional LLM deployments, agentic systems can take irreversible real-world actions, exfiltrate data through tool calls, and propagate attacks across integrated environments.
This talk presents a practitioner-built threat model for agentic AI, developed through hands-on work building and securing production agentic systems at Microsoft. Drawing on real-world deployment experience, I will introduce a structured taxonomy of agentic AI failure modes — from prompt injection through orchestration chains to privilege escalation via tool misuse — and map each to concrete, implementable defenses.
Key topics covered:
• Why existing LLM security frameworks (OWASP Top 10 for LLMs, MITRE ATLAS) are insufficient for agentic architectures
• A novel threat model covering agent memory poisoning, cross-agent trust exploitation, and tool-layer attacks
• Defense-in-depth patterns: identity-aware orchestration, agent sandboxing, guardrail design, and behavioral monitoring
• Case studies from production agentic deployments illustrating real attack surfaces and mitigations
Attendees will leave with a practical, immediately applicable framework for assessing and hardening their own agentic AI deployments — not theory, but battle-tested patterns from the field.
Learning Objectives:
1. Understand why agentic AI introduces fundamentally new security risks beyond traditional LLM threats
2. Apply a structured threat model to identify attack surfaces in their own agentic systems
3. Implement concrete defense patterns including agent sandboxing, identity-aware orchestration, and behavioral guardrails
This talk presents a practitioner-built threat model for agentic AI, developed through hands-on work building and securing production agentic systems at Microsoft. Drawing on real-world deployment experience, I will introduce a structured taxonomy of agentic AI failure modes — from prompt injection through orchestration chains to privilege escalation via tool misuse — and map each to concrete, implementable defenses.
Key topics covered:
• Why existing LLM security frameworks (OWASP Top 10 for LLMs, MITRE ATLAS) are insufficient for agentic architectures
• A novel threat model covering agent memory poisoning, cross-agent trust exploitation, and tool-layer attacks
• Defense-in-depth patterns: identity-aware orchestration, agent sandboxing, guardrail design, and behavioral monitoring
• Case studies from production agentic deployments illustrating real attack surfaces and mitigations
Attendees will leave with a practical, immediately applicable framework for assessing and hardening their own agentic AI deployments — not theory, but battle-tested patterns from the field.
Learning Objectives:
1. Understand why agentic AI introduces fundamentally new security risks beyond traditional LLM threats
2. Apply a structured threat model to identify attack surfaces in their own agentic systems
3. Implement concrete defense patterns including agent sandboxing, identity-aware orchestration, and behavioral guardrails
Speaker
Vaishnavi Gudur
Senior Software Engineer - Microsoft
Vaishnavi Gudur is a Senior Software Engineer at Microsoft, where she specializes in full-stack development and AI-driven systems optimization. With a strong foundation in both engineering and research, Vaishnavi is passionate about transforming traditional software practices through the integration of emerging technologies like artificial intelligence, explainable models, and predictive analytics.
She is the author of Leveraging AI for Improved Requirements Engineering, a groundbreaking research paper that explores how AI can revolutionize the most foundational—and often overlooked—stage of the software development lifecycle. Her work spans technical innovation, thought leadership, and real-world implementation, with a focus on building scalable systems that enhance developer producti...
She is the author of Leveraging AI for Improved Requirements Engineering, a groundbreaking research paper that explores how AI can revolutionize the most foundational—and often overlooked—stage of the software development lifecycle. Her work spans technical innovation, thought leadership, and real-world implementation, with a focus on building scalable systems that enhance developer producti...