Program

/

CODE BLUE 2026

Time Table

Static Analysis for AI Applications: From Taint Tracking to Exploit Generation

AITrace is an open-source static analysis tool that traces user-controlled data through AI framework call chains across files and generates working exploit payloads from confirmed attack paths. AITrace builds a cross-file call graph, runs bidirectional BFS from HTTP sources to LLM and execution sinks, confirms which paths are reachable, and emits codebase-specific PoC payloads for confirmed findings. AITrace works in three layers: -Pattern analysis - Covers OWASP AI security Framework -Cross-file taint tracking - Detect attack paths across files with bidirectional call graph analysis -LLM verification - Uses AI to confirm exploitability and generate codebase-specific remediation The result: A complete AI Bill of Materials, confirmed attack paths, and working exploit payloads - all from static analysis.

  • Location :

    • Track 3(Room 3)

  • Category :

    • Bluebox

  • Share :

Speakers

  • アリーシャ・グプタ の写真

    Alisha Gupta

    アリーシャ・グプタ

    Alisha Gupta is a Staff Security Engineer with 10+ years building enterprise security at scale. She specializes in AI Security, Cloud Security, and AppSec — operating at the frontier of Shadow AI, one of enterprise security's fastest-growing blind spots.

    Her work includes architecting AI asset discovery frameworks to detect unauthorized agents across multi-cloud environments, embedding AIBOM pipelines into CI/CD, and defining governance models for secure AI adoption. She has designed security systems spanning cloud automation with Terraform, IAM governance, secure SDLC, vulnerability management at scale, and supply chain security — always making security the default shape of systems.

    She holds an M.Tech in Cybersecurity from NIT Kurukshetra and has published research on DDoS defense at IEEE. She speaks for practitioners with implementation depth, hard-won enterprise lessons, and zero generic advice.