BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Agentic Free Pass: Does an Abliterated Backbone 
 Make\n   Agents Easier to Attack?\n   Tags: Middle Easterns & Africans in 
 Cyber Security (MEACS) | Creator\n   Talk/Panel\n   When: Friday\, Aug 7\,
  14:00 - 14:59 PDT\n   Where: LVCCW Level 1 Hall 4 1306 (Middle Easterns &
  Africans in Cyber\n   Security (MEACS) Community) - [1]Map\n\n   Descript
 ion:\n\n   To attack an AI agent\, the reflex is an abliterated model - re
 fusal\n   behavior surgically removed\, expecting a stronger attacker. We 
 tested\n   that across open-weight models (Qwen3\, Llama-3.1\, the 754B GL
 M-5.2)\,\n   scoring only attacks that actually fire a tool\, not ones tha
 t just\n   describe one.\n\n   Abliteration does make a tireless attacker.
  Asked to write attack\n   payloads â€” poisoned RAG docs\, malicious tool
  descriptions\,\n   injections â€” an abliterated GLM-5.2 said yes roughly
  three times as\n   often as its base (13% â†’ 38%). Pointed at an aligned
  copy of itself\,\n   it jailbroke that copy 80% of the time on the first 
 try\, and lifted\n   its hidden system prompt. Set loose in a real coding 
 agent (OpenCode)\n   attacking an aligned-model app\, it found exploits on
  its own: faking a\n   password-reset to send a phishing email\, and a KYC
  passed result to\n   skip an identity check and wire money.\n\n   But loo
 k at how it won: blunt jailbreaks (ignore your instructions\,\n   SYSTEM O
 VERRIDE) failed about 100 times. Every win came from disguise\n   â€” refr
 aming the harmful step so it looked routine. Aligned agents\n   block harm
  they recognize and fall for harm they don't.\n\n   The backbone matters o
 nly for hard content â€” malware\, weapons\, drugs\n   â€” where abliterat
 ion clearly raises success (Qwen3 37.5% â†’ 60%\,\n   GLM-5.2 67.5% â†’ 77
 .5%). And method matters: single-direction Heretic\n   can't strip Llama-3
 .1's refusal\, but eight-direction OBLITERATUS can.\n   That gap is also a
  detector: a model that clears 50% on hard content\,\n   or eagerly writes
  attacks\, is probably tampered.\n\n   Speakers:Karol Piekarski\,Nishith S
 inha\n\n   SpeakerBio:  Karol Piekarski\, DevOps Engineer\n\n   Karol Piek
 arski is a Lead DevOps Engineer working across cloud\n   infrastructure\, 
 zero-trust architecture\, and AI and agentic security\n   for systems that
  serve hundreds of millions of consumers. His research\n   focuses on the 
 security of large language models and autonomous\n   agents\, with an emph
 asis on practical red-teaming and defensive\n   tooling that teams can act
 ually operationalize rather than shelve.\n\n   His empirical work on ablit
 eration and agentic framing reframes where\n   alignment actually breaks d
 own in agent pipelines: agentic framing\n   alone can collapse a model's b
 aseline safety\, while abliteration\n   matters mostly for the hardest con
 tent and is highly\n   architecture-dependent. In 2026 he co-presented "Mo
 ve Fast\, Stay\n   Secure: Enterprise AI Agent Security in Practice" at th
 e Databricks\n   Data + AI Summit\, and spoke at SCaLE 23x on open source 
 red-teaming\n   for LLMs. He was one of only two external contributors to 
 the\n   Databricks Agentic AI Security Framework (DASF v3.0).\n\n   Karol 
 is the creator of Sundew.sh\, an open source\, MCP-native AI agent\n   hon
 eypot platform that uses behavioral fingerprinting and a persona\n   engin
 e for anti-fingerprinting\, now adopted by external research teams\n   stu
 dying agent behavior in the wild. He was selected as a Wiz MVP last\n   ye
 ar and this year received Wiz's Thought Leader award\, and he is\n   activ
 e in the AISECA Working Group\, where he co-owns agentic security\n   risk
  definitions.\n\n   He holds the CCSP\, CKA\, four AWS specialty certifica
 tions along with\n   DataDog and Tines\, and he regularly judges and mento
 rs at hackathons\n   across Southern California.\n\n   SpeakerBio:  Nishit
 h Sinha\n\n   Nishith Sinha started his career by pulling secrets out of t
 hin air.\n   As a researcher at Georgia Tech\, he co-authored a side-chann
 el attack\n   that recovered RSA private keys from OpenSSL by reading its\
 n   electromagnetic emissions alone. No code executed\, no system touched.
 \n   Presented at USENIX\, the work prompted a rapid fix from the OpenSSL\
 n   team and is still cited as a landmark example of hardware-level\n   cr
 yptographic risk.\n\n   It set the tone for what came next: a career built
  on finding the\n   security gaps other people arenâ€™t looking at. At Cis
 co\, that meant\n   network security\, where he helped design the companyâ
 €™s firewall\n   migration tooling. At Amazon\, it meant identity\, where 
 he owned IAM\n   strategy across tens of thousands of AWS accounts\, and t
 hen\n   application and cloud security\, remediating critical vulnerabilit
 ies\n   at enterprise scale. As generative AI took hold\, Nishith moved wi
 th\n   it\, leading application security for Amazon Bedrock and Amazon Q\,
 \n   before building security from scratch for Amazonâ€™s Nova foundation\
 n   models\, safeguarding training data\, model artifacts\, and\n   infras
 tructure across hundreds of teams.\n\n   Today\, Nishith brings that range
  to Databricks\, where he leads AI\n   Security and the companyâ€™s work o
 n Agentic Security\, AI Red Teaming\,\n   and AI Enterprise Security. He h
 olds 10 AI security patents spanning\n   model artifact protection\, secur
 e execution of model-initiated\n   computer actions\, and behavioral-analy
 tics-based content moderation.\n   He co-authored the Databricks Agentic S
 ecurity Framework (DASF) and is\n   credited with several CVEs. His focus 
 now is autonomous AI agents: the\n   newest layer of the stack\, and the o
 ne attackers understand least.\n\n   '\n\n   1. #LVCCW_Level1_Hall4\n\n\n
DTEND:20260807T215900Z
DTSTART:20260807T210000Z
LOCATION:Middle Easterns & Africans in Cyber Security (MEACS) - LVCCW Level
  1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Commu
 nity)
SUMMARY:The Agentic Free Pass: Does an Abliterated Backbone Make Agents Eas
 ier to Attack?
END:VEVENT
END:VCALENDAR
