BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Hostile Input: PDF Triage That Survives an Adversari
 al\n   Document\n   Tags: Malware Village | Creator Workshop\n   When: Sat
 urday\, Aug 8\, 10:10 - 12:10 PDT\n   Where: LVCCW Level 1 Hall 2 600 (Mal
 ware Village) Workshops - [1]Map\n\n   Description:\n\n   Abstract A malic
 ious document is no longer only a payload for the\n   endpoint. It is an i
 nput your tooling has to parse and judge\, and as\n   SOC teams bolt langu
 age models onto triage\, that input becomes\n   something an attacker can 
 shape to corrupt the verdict itself. This\n   workshop treats the document
  as an adversarial surface aimed at the\n   analyst’s tooling\, includin
 g the analyst’s AI.\n\n   It is hands-on\, starting from basic command-l
 ine tools\, participants\n   build the techniques that defeat AI-assisted 
 triage\, then build triage\n   that survives them: a prompt injection plac
 ed where no human reader\n   sees it\, a metadata and ToUnicode parser dif
 ferential where the\n   renderer and the extractor disagree on the same gl
 yphs\, and a staged\n   payload the document never reveals on its own. The
  two contributions\n   that carry the workshop are treating extractor disa
 greement as a\n   detection signal\, and a triage architecture where a det
 erministic\n   stage owns the verdict and the model is confined to advisor
 y roles\n   downstream of it.\n\n   Participants leave with a working pipe
 line\, the sample set\, and a\n   scoring harness\, and can state exactly 
 where a language model belongs\n   in triage and why putting it anywhere e
 lse is the vulnerability. The\n   pipeline runs locally on modest models\,
  because the detection power is\n   in the tooling\, not the model. Clean 
 files never leave the\n   environment.\n\n   Outline Deterministic floor. 
 Point an autonomous agent at a file\,\n   watch an indirect injection in t
 he document hijack it. That failure is\n   the problem statement. Particip
 ants then lay the structural floor with\n   pdfid and pdf-parser: the fact
 s an attacker cannot phrase their way\n   out of.\n\n   Demote the model. 
 Analyze a malicious PDF structurally\, then watch a\n   hidden render-mode
  injection talk a naive model pipeline into a clean\n   verdict. Rebuild i
 t so a deterministic stage owns the verdict and the\n   model is fed struc
 tural findings\, not the attacker’s prose. Rule:\n   extracted content i
 s untrusted input\, never instruction.\n\n   Add redundancy: the parser di
 fferential. Two documents that defeat\n   detection by placement alone: an
  injection living in metadata a\n   body-text extractor never reads\, a To
 Unicode trick that makes the\n   rendered page and the extracted text disa
 gree on identical glyphs.\n   Participants build a multi-extractor differe
 ntial and treat\n   disagreement as the alert.\n\n   Resolve\, and place t
 he model. A staged payload forces the last lesson:\n   Participants add in
 put validation and type-confusion detection at the\n   floor\, extract the
  hidden artefact as a suspicion finding\, decode it\n   in-terminal\, and 
 let bounded model roles explain it and assemble\n   competing hypotheses w
 ith evidence while the analyst decides. The\n   model advises downstream o
 f a deterministic gate\, never holds the\n   verdict.\n\n   Capstone CTF a
 nd Q&A. A fresh set: technique-carriers\, clean decoys\,\n   and documents
  styled as beingenin PDFs Sthat baits the analyst into\n   pasting it stra
 ight into the model. Participants show their work:\n   verdict\, technique
 \, extraction path\, hidden URLs\, execution behaviour.\n   Scoring reward
 s correctness first\, then fewest tokens\, because the\n   analyst who nee
 ded the model least played the strongest game.\n\n   Learning objectives P
 articipants will be able to: 1. Build a PDF\n   triage pipeline from comma
 nd-line tools and explain exactly where its\n   verdict comes from. 2. Ana
 lyze a malicious PDF structurally (pdfid\,\n   pdf-parser\, stream inspect
 ion) and decode embedded artefacts\n   in-terminal. 3. Construct and recog
 nize the three adversarial-document\n   techniques that defeat AI-assisted
  analysis: hidden-layer prompt\n   injection\, metadata and ToUnicode pars
 er differentials\, and staged\n   payloads. 4. Distinguish an early struct
 ural suspicion verdict from a\n   late analytical identification verdict\,
  and treat extractor\n   disagreement as a detection signal. 5. Place a la
 nguage model in\n   bounded advisory roles downstream of a deterministic g
 ate\, never\n   holding the verdict\, and select the right model for each 
 task. 6. Run\n   the whole pipeline locally on modest models\, understandi
 ng why the\n   detection power lives in the tooling and why the architectu
 re is\n   private by construction.\n\n   SpeakerBio:  Klaus Wunder\, Princ
 ipal Cyber Defence Analyst at\n   SECUINFRA\n\n   With nearly two decades 
 in cybersecurity\, Klaus has gone from\n   configuring firewalls to protec
 ting industrial control systems where\n   breaches cost safety\, not just 
 data. That journey gives him a\n   full-spectrum perspective on security o
 perations. He guides teams\n   through complex incidents and builds detect
 ion engineering\n   capabilities across hybrid environments as a Principal
  Cyber Defence\n   Analyst\, while his role as an Authorized OffSec Instru
 ctor\, Ambassador\n   keeps him equally focused on developing the next gen
 eration of\n   analysts. His current work explores how Large Language Mode
 ls can\n   revolutionize cyber defence with practical applications\, not h
 ype. He\n   recently launched The Analyst Mind on Substack (theanalystmind
 .io)\,\n   where he writes about analytical thinking\, critical frameworks
 \, and\n   the evolving analyst mindset.\n\n   '\n\n   1. #LVCCW_Level1_Ha
 ll2\n\n\n
DTEND:20260808T191000Z
DTSTART:20260808T171000Z
LOCATION:Malware Village - LVCCW Level 1 Hall 2 600 (Malware Village) Works
 hops
SUMMARY:Hostile Input: PDF Triage That Survives an Adversarial Document
END:VEVENT
END:VCALENDAR
