Loading…
Thursday November 5, 2026 11:30am - 12:15pm PST
Deputies, like agentic AI models, do things on your behalf. A confused deputy does more than it should on your behalf. How do you unconfuse an inherently confused deputy? By telling it what it can and cannot do? But what if it gets confused, again?

Current LLM technology is not capable of being completely immune to prompt injection. It is going to happen. This means the security boundaries for voice agents cannot live solely inside the model's instructions. They have to live in the infrastructure around them. The right design assumes the model will be compromised and ensures that when it is, nothing irreversible happens.

This talk will discuss several of the defense-in-depth elements needed to create and deploy secure voice-based AI-powered agents. These elements will include defenses against transcription manipulation, agent goal drift, tool-abuse, data exfiltration through retrieval, and system-prompt extraction. Each control's effectiveness will be measured by: is it still effective even if the language model does exactly what the attacker asked?

You'll leave with a prioritized, vendor-neutral set of controls you can implement now. You will also gain a better understanding of the necessary defense-in-depth elements when deploying any type of agent. And finally, you'll walk away with a single phrase you can apply to every AI system you're responsible for, voice or not: "would this survive a fully compromised LLM?"
Speakers
avatar for Brian Cardinale

Brian Cardinale

Principal Security Researcher, SecureCoders
Brian Cardinale is the Principal Security Researcher at SecureCoders. He holds a CISSP and has spent his career breaking things that aren't supposed to break. Brian built VoiceGoat, the first open-source vulnerable voice AI agent, and leads RedCaller's research into adversarial testing... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom C (Street Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link