Resilient AI: Securing Large Language Models
from
Thursday, September 3, 2026 (9:00 AM)
to
Friday, September 4, 2026 (4:00 PM)
Monday, August 31, 2026
Tuesday, September 1, 2026
Wednesday, September 2, 2026
Thursday, September 3, 2026
9:00 AM
Session 1: Introduction to LLMs
-
Simon Razniewski
(
TU Dresden
)
Session 1: Introduction to LLMs
Simon Razniewski
(
TU Dresden
)
9:00 AM - 11:00 AM
Motivates LLM security through real-world incidents, then gives an accessible introduction to LLM internals: tokenization, context windows, the transformer architecture, training stages (pre-training, fine-tuning, RLHF), prompt roles, and how generation works.
11:00 AM
Session 2: LLM Weaknesses & Hacking
-
Himanshu Beniwal
(
TU Dresden
)
Session 2: LLM Weaknesses & Hacking
Himanshu Beniwal
(
TU Dresden
)
11:00 AM - 12:00 PM
Introduces the main attack categories: prompt injection, jailbreaking techniques, training data extraction, hallucination, and supply-chain risks such as system prompt theft and model poisoning.
12:00 PM
Lunch Break
Lunch Break
12:00 PM - 1:00 PM
1:00 PM
Hands-on: Breaking an LLM
-
Siavash Ghiasvand
(
TU Dresden
)
Paramita Mirza
(
TU Dresden
)
Hands-on: Breaking an LLM
Siavash Ghiasvand
(
TU Dresden
)
Paramita Mirza
(
TU Dresden
)
1:00 PM - 3:00 PM
Participants attack a pre-built chatbot through staged challenges—role-play attacks, delimiter manipulation, and indirect injection—aiming to extract the hidden system prompt or bypass safety checks.
3:00 PM
Results & Debrief
Results & Debrief
3:00 PM - 4:00 PM
The group compares which attacks succeeded and why, with discussion of what participants would do differently as developers.
Friday, September 4, 2026
9:00 AM
Session 3: LLMs & Privacy
-
Hermann Diebel-Fischer
(
TU Dresden
)
Session 3: LLMs & Privacy
Hermann Diebel-Fischer
(
TU Dresden
)
9:00 AM - 10:00 AM
Examines how LLMs expose sensitive information: training data memorization, PII leakage, differential privacy and its limits, GDPR requirements, and re-identification attacks.
10:00 AM
Session 4: Guardrails & Defense Mechanisms
Session 4: Guardrails & Defense Mechanisms
10:00 AM - 11:00 AM
Surveys defensive tools—input validation, output filtering, alignment techniques, LLM-as-judge, and prompt firewalls—along with their limitations.
11:00 AM
Session 5: Secure LLM Architecture & Design
Session 5: Secure LLM Architecture & Design
11:00 AM - 12:00 PM
Covers designing secure LLM systems: least privilege for agents, trust boundaries, access control for RAG, logging and auditing, and STRIDE-adapted threat modelling.
12:00 PM
Lunch Break
Lunch Break
12:00 PM - 1:00 PM
1:00 PM
Hands-on: Break & Fix a RAG System
-
Siavash Ghiasvand
(
TU Dresden
)
Paramita Mirza
(
TU Dresden
)
Hands-on: Break & Fix a RAG System
Siavash Ghiasvand
(
TU Dresden
)
Paramita Mirza
(
TU Dresden
)
1:00 PM - 3:00 PM
Participants exploit a deliberately vulnerable RAG pipeline, then fix it with access control and output filtering, documenting their work in a short remediation note.
3:00 PM
Results & Wrap-up
Results & Wrap-up
3:00 PM - 4:00 PM
Groups present findings, facilitators distill a practical pre-shipping checklist, and the workshop closes with further reading and next steps.