Lead Product & Infrastructure Security at EigenLabs
Anto Joseph leads product and infrastructure security at EigenLabs. His work focuses on AI-native vulnerabilities — the class of security flaws that arise from how modern AI systems are built rather than from mistakes in application code — and on translating cutting-edge academic security research into practical, hands-on offensive tradecraft for red teamers and security researchers.
11:00-12:55 PDT | Friday, Aug 7th 2026 | Adversary Village Hands-on Activity Area, Las Vegas Convention Center Hands-on Lab
For thirty + years, hacking has meant finding flaws in code people wrote: memory corruption, injection, and logic bugs. AI systems fail differently. Their vulnerabilities live in the weights or the supporting fixtures. Caches that speed up inference, embeddings that supposedly anonymize data, weights that execute code, training corpora memorization, misalignment, reward hacking and the structural inability of a language model to separate instructions from data. These are some of the AI-native bugs. They exist because of how these systems are built, not because a developer made a mistake, and no traditional AppSec tool will find them. As enterprises deploy LLM assistants, agents, and RAG pipelines into the adversary's path, this bug class is becoming the new attack surface.
This lab walks you through live exploitation and defenses in a contained environment. Built on peer-reviewed work from NDSS, USENIX Security, IEEE S&P/SaTML, CCS, and ICLR (2023-2026).
We will cover attacks across Model Serving side channels, prefix cache attacks, speculative decoding, the AI supply chain, dataset poisoning, sleeper-agent backdoors that survive safety training, and trojaned LoRA adapters. We will also have examples of the classic prompt and chat template injection bugs baked in CTF style.
Every lab is built on released artifacts: papers, code, datasets, and open models. Attendees leave with a working understanding of modern AI systems, how AI-native vulnerability research works and a method they can run on their next engagement.
Who should attend: red teamers, pentesters, and security researchers fluent in traditional exploitation who want the AI-native equivalent.
Prerequisites: a laptop with admin access that can run Docker. A MacBook Pro with 128 GB of memory is preferred if you like to run models locally.
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!