BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.balccon.org//balccon2k26-2026//talk//NJFLGX
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-balccon2k26-2026-NJFLGX@cfp.balccon.org
DTSTART;TZID=CET:20260919T110000
DTEND;TZID=CET:20260919T112000
DESCRIPTION:Every company deploying a public-facing LLM chatbot inherits th
 e full prompt-injection attack surface: jailbreaks\, data exfiltration\, P
 II leakage\, indirect injection via retrieved documents. Single-model clas
 sifiers and regex filters consistently miss novel attacks\, the same way s
 ingle-AV products missed novel malware a decade ago.\n\nThis talk presents
  an open-source defensive architecture that runs five specialist AI agents
  in parallel against every prompt and response\, each looking at a differe
 nt attack dimension (injection patterns\, semantic intent\, encoding trick
 s\, output exfiltration\, PII exposure) and aggregates their verdicts befo
 re the request reaches the upstream LLM. We'll walk through the architectu
 re\, show live attacks bypassing commercial single-model guardrails but ca
 ught by the multi-agent pipeline\, and discuss the latency/cost tradeoffs 
 that make this practical as inline middleware.
DTSTAMP:20260901T070832Z
LOCATION:Pupin
SUMMARY:Defending LLMs with LLMs: A Multi-Agent Approach to Prompt Injectio
 n - Vukasin Dobromirovic
URL:https://cfp.balccon.org/balccon2k26-2026/talk/NJFLGX/
END:VEVENT
END:VCALENDAR
