AIアプリケーションの静的解析:テイントトラッキングからエクスプロイト生成まで
DAY 2
11:00-
11:40
AITraceは、ファイル境界を越えるAIフレームワークのコールチェーンを通じてユーザー制御データを追跡し、確認された攻撃パスから実際に動作するエクスプロイトペイロードを自動生成する、オープンソースの静的解析ツールである。 AITraceは、ファイル横断的なコールグラフ(呼び出しグラフ)を構築し、HTTP入力源(ソース)からLLMや実行処理(シンク)に向けて双方向の幅優先探索(BFS)を実行する。これにより、どのパスが実際に到達可能であるかを確認し、特定された脆弱性に対してコードベース固有のPoCペイロードを出力する。 AITraceは、以下の3つのレイヤーで機能する。 パターン解析:OWASP AIセキュリティフレームワークに対応する。 ファイル横断タイント追跡:双方向コールグラフ解析を用いて、ファイルをまたぐ攻撃パスを検出する。 LLM検証:AIを利用して悪用可能性を確認し、コードベース固有の修復策(レミディエーション)を生成する。 その結果、静的解析のみから、完全なAI部品構成表(AI Bill of Materials: AIBOM)、確認された攻撃パス、そして実際に動作するエクスプロイトペイロードが得られる。
-
Location :
-
Track 3(Room 3)
-
-
Category :
-
Bluebox
-
-
Share :
Speakers
-
Alisha Gupta
アリーシャ・グプタ
Alisha Gupta is a Staff Security Engineer with 10+ years building enterprise security at scale. She specializes in AI Security, Cloud Security, and AppSec — operating at the frontier of Shadow AI, one of enterprise security's fastest-growing blind spots.
Her work includes architecting AI asset discovery frameworks to detect unauthorized agents across multi-cloud environments, embedding AIBOM pipelines into CI/CD, and defining governance models for secure AI adoption. She has designed security systems spanning cloud automation with Terraform, IAM governance, secure SDLC, vulnerability management at scale, and supply chain security — always making security the default shape of systems.
She holds an M.Tech in Cybersecurity from NIT Kurukshetra and has published research on DDoS defense at IEEE. She speaks for practitioners with implementation depth, hard-won enterprise lessons, and zero generic advice.