webappsec.dev

$less ~/slides/securing-ai-agents-in-practice

// deck 02 · SIGS — Security Interest Group Switzerland

From Prompt Injections to Rogue Actions

Securing AI Agents in Practice

SIGS — Security Interest Group Switzerland · Zürich · 2026· 76 slides· Lukas Weichselbaum

pdf ↓ 5.0 MB

  1. Slide 1: From Prompt Injections
  2. Slide 2: About Me
  3. Slide 3: Acknowledgement
  4. Slide 4: Agenda
  5. Slide 5: The promise and
  6. Slide 6: Welcome to the New Era driven by AI Agents
  7. Slide 7: Prompt Injection
  8. Slide 8: Prompt Injection (continued)
  9. Slide 9: Prompt Injection Interest
  10. Slide 10: Prompt Injection Interest (continued)
  11. Slide 11: Prompt Injection - Real World Example
  12. Slide 12: Security challenges of
  13. Slide 13: Security challenges of (continued)
  14. Slide 14: Security challenges of (continued)
  15. Slide 15: Questions to consider
  16. Slide 16: Security challenges of
  17. Slide 17: Questions to consider
  18. Slide 18: Security challenges of
  19. Slide 19: Questions to consider
  20. Slide 20: Security challenges of
  21. Slide 21: Security challenges of (continued)
  22. Slide 22: Questions to consider
  23. Slide 23: Key risks associated
  24. Slide 24: The Problem
  25. Slide 25: This is made worse by the Lethal Trifecta
  26. Slide 26: .Rogue Actions
  27. Slide 27: Sensitive Data Disclosure
  28. Slide 28: Risks mapped to the Agent
  29. Slide 29: Demo
  30. Slide 30: An Example Travel Agent (ADK)
  31. Slide 31: Google Secure AI Framework Proprietary & Confidential
  32. Slide 32: Travel Agent Vulnerability #1 : Data Exfiltration
  33. Slide 33: Your Booking
  34. Slide 34: Travel Agent Vulnerability #1 : Data Exfiltration
  35. Slide 35: Google Secure AI Framework Proprietary & Confidential
  36. Slide 36: Google Secure AI Framework Proprietary & Confidential (continued)
  37. Slide 37: But both agent output and actions can be
  38. Slide 38: Travel Agent Vulnerability #2 : Rogue Actions
  39. Slide 39: Travel Agent Vulnerability #2 : Rogue Actions (continued)
  40. Slide 40: Google Secure AI Framework Proprietary & Confidential
  41. Slide 41: Google Secure AI Framework Proprietary & Confidential (continued)
  42. Slide 42: Core principles for
  43. Slide 43: Agent security principles
  44. Slide 44: Principle 1: Agents must have well-defined human controllers
  45. Slide 45: Principle 2: Agent powers must have limitations
  46. Slide 46: Principle 3: Agent actions and planning must be observable
  47. Slide 47: Agent security principles
  48. Slide 48: Controls relevant to AI
  49. Slide 49: Google’s approach:
  50. Slide 50: Google’s hybrid, defense-in-depth approach to AI agent security
  51. Slide 51: Google’s hybrid, defense-in-depth approach to AI agent security (continued)
  52. Slide 52: Demo
  53. Slide 53: Travel Agent Vulnerability #1 : Data Exfiltration
  54. Slide 54: Markdown Sanitization Helps Prevent Data
  55. Slide 55: Google Secure AI Framework Proprietary & Confidential
  56. Slide 56: Google Secure AI Framework Proprietary & Confidential (continued)
  57. Slide 57: Security challenges of
  58. Slide 58: Travel Agent Vulnerability #2 : Rogue Actions
  59. Slide 59: Policy Engine Can Prevent Rogue Actions
  60. Slide 60: Policy Engine Can Prevent Rogue Actions (continued)
  61. Slide 61: Google Secure AI Framework Proprietary & Confidential
  62. Slide 62: Google Secure AI Framework Proprietary & Confidential (continued)
  63. Slide 63: Example API for Policy Engine
  64. Slide 64: Security challenges of
  65. Slide 65: Google’s hybrid, defense-in-depth approach to AI agent security
  66. Slide 66: Google’s hybrid, defense-in-depth approach to AI agent security (continued)
  67. Slide 67: Google’s hybrid, defense-in-depth approach to AI agent security (continued)
  68. Slide 68: Navigating the future
  69. Slide 69: Hybrid Agent Security Strategy
  70. Slide 70: 70
  71. Slide 71: 71
  72. Slide 72: AI VRP
  73. Slide 73: 73
  74. Slide 74: 74
  75. Slide 75: 75
  76. Slide 76: Thank
1 / 76

// key slides

  1. 25The lethal trifecta: sensitive data, untrusted context, the power to act
  2. 34Demo: an injected review makes the travel agent exfiltrate a door code
  3. 50Google's defense in depth: policy enforcement, reasoning defenses, testing
  4. 59The policy engine: allow, deny, or ask the user

// what you take away

  • Nothing known stops a model acting on an injected prompt, so layer the defenses.
  • A poisoned booking page leaks a door code through a markdown image URL.
  • A policy engine asks the user before a destructive tool call goes through.