Trustworthy Productivity: Securing AI-Accelerated Development

Summary

Disclaimer: This summary has been generated by AI. It is experimental, and feedback is welcomed. Please reach out to info@qconsf.com with any comments or concerns.

The presentation delves into the vulnerabilities and defenses within AI-accelerated autonomous agents operating in a continuous loop of perceiving, reasoning, executing, and observing. Here are the key points discussed:

  1. Vulnerabilities:
    • Memory poisoning during context ingestion.
    • Goal hijacking during reasoning.
    • Blind execution at the action stage.
  2. Defensive Patterns:
    • Provenance Gates: Treat context like a supply chain to prevent unauthorized inputs.
    • Dual-Model Critics: Use multiple AI models to cross-verify decisions.
    • Risk-Weighted Human Oversight: Introduce human checks based on risk scores.
    • Ephemeral Credentials: Use short-lived credentials to minimize abuse.
    • Sandboxed Execution: Contain actions within secure environments.
  3. The React Loop: An agentic loop that encompasses context management, reasoning and planning, and tool action execution.
  4. Threat Modeling:
    • Use of frameworks like Maestro to identify AI-specific threats.
    • Adopt Defense-in-Depth strategies across the agentic loop stages.
  5. Conclusion: The presentation emphasized building trustworthy productivity through layered defenses and encouraging participants to start applying these security measures from day one.

Key Takeaway: Autonomy is powerful, but without proper safeguards, it can lead to catastrophic outcomes. Therefore, a robust security strategy is necessary for AI-driven development.

This is the end of the AI-generated content.


Abstract

Autonomous agents operate in a continuous loop: perceive context → reason → execute tools → observe. Each edge creates distinct attack surfaces. This talk maps vulnerabilities—memory poisoning in context ingestion, goal hijacking during reasoning, blind execution at the action stage. You'll learn defensive patterns for each edge: provenance gates, dual-model critics, risk-weighted human oversight, ephemeral credentials, and sandboxed execution. Illustrated with real industry incidents.


Speaker

Sriram Madapusi Vasudevan

Senior Software Engineer @AWS Agentic AI, Previously Core Team @AWS SAM, AWS Cloudwatch, Core Developer @Openstack

Sriram Madapusi Vasudevan is a Senior Software Engineer at AWS focused on building AI agent-ready developer experiences. Over the past decade, he has worked on large-scale platforms such as AWS CloudWatch, Rackspace Cloud Queues/CDN and open-sourced developer tooling such as AWS SAM CLI, AWS Lambda Builders, and created the AWS Homebrew tap.

Read more
Find Sriram Madapusi Vasudevan at:

From the same track

Session AI/ML

Powering the Future: Building Your GenAI Infrastructure Stack

Wednesday Nov 19 / 01:35PM PST

Behind every productivity leap is a rock-solid platform. Go under the hood with Intuit’s GenOS team to see how vector stores, prompt management, RAG pipelines, and agent orchestration come together to serve ~100 million users.

Speaker image - Merrin Kurian

Merrin Kurian

Distinguished Engineer @Intuit

Session AI/ML

Accelerating LLM-Driven Developer Productivity at Zoox

Wednesday Nov 19 / 11:45AM PST

Over the past year, Zoox has invested in integrating Large Language Models (LLMs) into the entire developer lifecycle through a companywide initiative called Zoox Intelligence (ZI).

Speaker image - Amit Navindgi

Amit Navindgi

Staff Software Engineer, Developer Experience @ Zoox, Leading Applied AI Initiatives

Session AI/ML

AI-Driven Productivity: From Idea to Impact

Wednesday Nov 19 / 02:45PM PST

In this session you'll learn how product leaders turn GenAI enthusiasm into an enterprise-ready blueprint for real productivity gains.

Speaker image - Jyothi Nookula

Jyothi Nookula

Product Leader Director with 13+ Years Driving AI Product & Platform Innovation, Previously @Meta, @Amazon, and @Etsy

Session AI/ML

Choosing Your AI Copilot: Maximizing Developer Productivity

Wednesday Nov 19 / 10:35AM PST

The AI coding agent landscape evolves weekly. This talk compares today’s frontrunners, shows where each shines, and shares prompts, policies, and “rules templates” that turn code suggestions into production-quality output.

Speaker image - Sepehr Khosravi

Sepehr Khosravi

Machine Learning Platform Engineer @Coinbase, Award Winning Instructor @UC Berkeley - Gen-AI Bootcamp, Founder @ AI Scouts