Header image

Session 2.4e Update: From Prompt Injection to System Compromise: using MITRE ATLAS to Detect and Disrupt the AI-cyber-kill-chain

Tracks
Wednesday, November 18, 2026
11:30 AM - 12:30 PM
Sutherland Theatre

Presentation Outline

AI is not failing in theory. It is already being broken. The question is whether organisations understand how it is being broken well enough to defend it. LLMs and machine learning systems are being integrated into everyday workflows, decision-support tools, security functions, identity processes, software development pipelines and operational environments. This creates a proportional safety challenge: a low-risk productivity assistant does not require the same level of assurance as an AI-enabled identity system, security control, autonomous platform, operational decision aid or safety-related capability. As you know, rapid adoption should not mean accepting blind risk. Recent global research shows AI use is already embedded across organisations and workplaces, while governance, training, and assurance lag behind adoption. This expands the attack surface across both technical and human pathways. The risk is not only an external adversary may attack a model. It is also staff may use public AI tools, upload sensitive information (ITAR information in Defence Copilot), rely on outputs without checking them, or connect AI systems to business processes before the risks are understood. This presentation introduces MITRE ATLAS, the Adversarial Threat Landscape for Artificial-Intelligence Systems, as a practical, evidence-informed framework for understanding how adversaries target AI-enabled systems. Like ATT&CK for enterprise cyber threats, ATLAS provides a structured language for mapping adversary behaviour across tactics, techniques and procedures. It helps teams move from general concern about AI risk to specific questions: 1. How could this system be attacked? 2. Which layer is exposed? 3. What would failure mean? 4. What should be monitored? 5. What should be hardened? 6. What must be recoverable? The session will walk through an AI cyber kill chain from prompt injection to model evasion, data and model poisoning, supply chain exposure, excessive agency, sensitive information disclosure, and system-level compromise. It will also consider real-world examples, including reported fraud involving facial recognition and high-consequence AI misuse, to show why AI assurance must scale with operational risk, mission urgency, system autonomy and consequence of failure. Participants will see how ATLAS can support AI threat assessments, red-team exercises, detection planning, control prioritisation and communication between technical and non-technical stakeholders. The goal is not to block innovation. The goal is to make innovation safer by giving teams a shared language, a structured view of adversary behaviour, and a practical way to identify weaknesses before they become operational failures. The key takeaway is simple: AI-enabled capability can advance with confidence when organisations understand how AI systems break, scale assurance to consequence, and use ATLAS to anticipate, detect and disrupt the AI cyber kill chain. Key takeaways AI systems are already being targeted, so understanding how they fail is essential to defending them. Rapid adoption of LLMs and ML is expanding the attack surface across technical systems, human behaviour, data flows, model pipelines and operational dependencies. AI safety should be proportional: low-risk productivity tools do not require the same assurance as AI-enabled identity systems, security controls, autonomous platforms or safety-related capabilities. MITRE ATLAS provides a structured way to understand adversary behaviour against AI-enabled systems and to support threat assessment, red teaming, detection planning and control prioritisation. The session helps participants move from reacting to AI threats to anticipating and disrupting them using a practical framework grounded in real-world attacker and defender behaviour.


Speaker

Agenda Item Image
Mr Nico Riquelme-Ramirez
Cybersecurity Consultant
QinetiQ

Biography

Meet Nico, a dedicated explorer in the dynamic fields of technology, engineering, and critical thinking. With a career rooted in Defence, Nico has led projects ranging from radar deployment across Australia to navigating the complexities of Information Warfare. Now with QinetiQ, Nico is leveraging expertise in Cyber and Information Security to help clients safeguard their critical assets and people. Before pursuing a Master's in Project Management at ANU, Nico played a key role at Seeing Machines, where he helped develop advanced driver and occupant monitoring systems designed to keep roads safer. Nico’s career also spans global experience with Procter & Gamble, where his Industrial Engineering acumen ensured the safe, and efficient production of diapers… millions of them.
loading