BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Zero-Cloud Threat Modeling: Vector Embedding Archite
 ctures for\n   Automated Vulnerability Detection\n   Tags: AI | DEF CON De
 mo Labs | Intermediate | AppSec | Threat\n   Intel/Hunting | DEF CON Demo 
 Labs\n   When: Saturday\, Aug 8\, 16:00 - 16:45 PDT\n   Where: LVCCW Level
  1 Hall 3 900 (Demo Labs Track 4) - [1]Map\n\n   Description:\n\n   Tradit
 ional threat modeling is a tedious\, manual process prone to\n   human err
 or. Conversely\, modern "AI" threat modeling tools almost\n   universally 
 depend on sending sensitive\, proprietary system\n   architectures to thir
 d-party APIs in cleartext.\n\n   We present AI Threat Modeler (AITM)\, a f
 ully open-source\, zero-cloud\n   application designed to automate archite
 cture-driven STRIDE threat\n   modeling completely offline. AITM fundament
 ally shifts how we analyze\n   system designs by replacing brittle\, keywo
 rd-based regex rules with a\n   local Semantic AI Engine.\n\n   Under the 
 hood\, AITM leverages sentence-transformers and an in-memory\n   FAISS vec
 tor database to embed a comprehensive\, 116+ component\n   knowledge base.
  During analysis\, a custom NetworkX graph builder\n   parses natural lang
 uage or structured architecture descriptions (via\n   spaCy) to map undocu
 mented architectural features to known CVE classes\n   and STRIDE categori
 es.\n\n   Furthermore\, AITM introduces "Architecture Intelligence" using 
 graph\n   traversal algorithms to automatically infer missing trust bounda
 ries\n   and identify multi-step attack chains that standalone component\n
    scanning misses. In this demo\, we will: Walk through the automated\n  
  ingestion of a microservice architecture. Demonstrate how the local\n   F
 AISS engine discovers semantic threats that evade keyword matching.\n   Sh
 ow dynamic attack cha\n\n   SpeakerBio:  Ankit Vashisth\n\n   Ankit Vashis
 th is a Security Engineer with over 4 years of experience\n   in applicati
 on security\, cloud security\, and DevSecOps. He has worked\n   on securit
 y assessments across web\, mobile\, network\, and enterprise\n   systems f
 or global clients. His interests include AI-driven security\n   tooling\, 
 threat modeling\, and security automation. Ankit actively\n   researches w
 ays to apply AI to improve security architecture analysis\n   and vulnerab
 ility detection.\n\n   Links:\n       GitHub - [2]https://github.com/ankit
 spidy007/ai-threat-modeler\n   '\n\n   1. #LVCCW_Level1_Hall3\n   2. https
 ://github.com/ankitspidy007/ai-threat-modeler\n\n\n
DTEND:20260808T234500Z
DTSTART:20260808T230000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)
SUMMARY:Zero-Cloud Threat Modeling: Vector Embedding Architectures for Auto
 mated Vulnerability Detection
END:VEVENT
END:VCALENDAR
