Your LLM Stack Is a 2008 Database With Better Marketing: Why ML Security Is Dominated by Misconfiguration, Not Missing Features
Lovina Dmello
- When
- Tuesday, June 3011:10 AM – 11:30 AM · 20 min
- Where
- Track 5San Francisco, CA · imported from ai.engineer's public schedule feed
About this session
ShadowRay exposed over a billion dollars of data through a missing authentication check. It wasn't a zero-day. It wasn't a clever new attack class. It was a default config someone never flipped off. That story is not the exception in production ML, it's the rule. We synthesized 139 peer-reviewed papers on production ML security across access control, runtime security, infrastructure, and operations. Five findings stood out, and one of them upends how most teams think about ML security: - Misconfiguration, not missing features, is the dominant failure mode. The mechanisms exist. Teams aren't using them, or are using them wrong. - Adversarial defenses impose 15–30% inference overhead, which is why almost no production system actually runs them. - ML-specific security tooling lags general DevOps tooling by years. - Security, data-science, and ops teams operate in expertise silos that create persistent gaps no single team can see. - LLM and multi-tenant GPU threats are evolving faster than defenses (prompt injection, RAG poisoning, GPU side channels). This talk walks through the four-pillar defense-in-depth framework, the six-category threat taxonomy that maps each attack to its primary and secondary defenses, and a four-level security maturity model that matches overhead budgets to deployment contexts. You leave knowing where your stack actually sits and which 3 misconfigurations account for most of the risk.
Speaker
Senior Software Developer, NVIDIA
Lovina Dmello is a senior infrastructure software engineer on the Deep Learning Libraries team at NVIDIA, where she works on building and maintaining the infrastructure that powers the NVIDIA deep learning ecosystem. Before joining NVIDIA, Lovina spent four years at Apple on the Apple Payments and Wallets backend team, and three years at Oracle on the Oracle Cloud Infrastructure team. She earned her master's degree in Computer Science from the University of Georgia, where her thesis focused on ransomware classification using machine learning algorithms. Lovina shares her insights through research papers and writing on AI/ML security, agentic AI systems, TensorRT, deep-learning libraries, and infrastructure best practices.
More in Security
- Through the AI Fog: The architectural decision the next 24 months of agentic security depends on.Tuesday, June 30 · 10:45 AM – 11:05 AM · Track 5
- We Gave an Agent Production Code Access and Then Tried to Sleep at NightTuesday, June 30 · 11:40 AM – 12:00 PM · Track 5
- Agentic Development SecurityTuesday, June 30 · 12:05 PM – 12:25 PM · Track 5
- Using LLMs to Secure Source CodeTuesday, June 30 · 1:30 PM – 1:50 PM · Track 5
- Dual-Surface Architecture: Serving Humans and Agents from the Same Tool LayerTuesday, June 30 · 1:55 PM – 2:15 PM · Track 5
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./aie-worldsfair-2026-import/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./aie-worldsfair-2026-import/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./aie-worldsfair-2026-import/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.