June 29 – July 2, 2026 · San Francisco, CA · imported from ai.engineer's public schedule feed

AI Engineer World's Fair 2026 — unofficial import demo

Unofficial demo. This programme was imported from the AI Engineer World's Fair's own public schedule feed to show vibeboard at real conference scale. Not affiliated with, or endorsed by, the organisers.

All sessions
SecuritySponsor Session

Your LLM Stack Is a 2008 Database With Better Marketing: Why ML Security Is Dominated by Misconfiguration, Not Missing Features

Lovina Dmello

When
Tuesday, June 3011:10 AM – 11:30 AM · 20 min
Where
Track 5San Francisco, CA · imported from ai.engineer's public schedule feed
Google Calendar

About this session

ShadowRay exposed over a billion dollars of data through a missing authentication check. It wasn't a zero-day. It wasn't a clever new attack class. It was a default config someone never flipped off. That story is not the exception in production ML, it's the rule. We synthesized 139 peer-reviewed papers on production ML security across access control, runtime security, infrastructure, and operations. Five findings stood out, and one of them upends how most teams think about ML security: - Misconfiguration, not missing features, is the dominant failure mode. The mechanisms exist. Teams aren't using them, or are using them wrong. - Adversarial defenses impose 15–30% inference overhead, which is why almost no production system actually runs them. - ML-specific security tooling lags general DevOps tooling by years. - Security, data-science, and ops teams operate in expertise silos that create persistent gaps no single team can see. - LLM and multi-tenant GPU threats are evolving faster than defenses (prompt injection, RAG poisoning, GPU side channels). This talk walks through the four-pillar defense-in-depth framework, the six-category threat taxonomy that maps each attack to its primary and secondary defenses, and a four-level security maturity model that matches overhead budgets to deployment contexts. You leave knowing where your stack actually sits and which 3 misconfigurations account for most of the risk.

Speaker

Lovina Dmello
Lovina Dmello

Senior Software Developer, NVIDIA

Lovina Dmello is a senior infrastructure software engineer on the Deep Learning Libraries team at NVIDIA, where she works on building and maintaining the infrastructure that powers the NVIDIA deep learning ecosystem. Before joining NVIDIA, Lovina spent four years at Apple on the Apple Payments and Wallets backend team, and three years at Oracle on the Oracle Cloud Infrastructure team. She earned her master's degree in Computer Science from the University of Georgia, where her thesis focused on ransomware classification using machine learning algorithms. Lovina shares her insights through research papers and writing on AI/ML security, agentic AI systems, TensorRT, deep-learning libraries, and infrastructure best practices.

More in Security