
Modern AI systems don’t just rely on static datasets – they depend on continuous streams of real-time data to train and update models and make decisions. But what happens when that data can’t be trusted?
In this talk, Olena Kutsenko explores how streaming data pipelines – often built on systems like Apache Kafka – are becoming a critical yet insufficiently secured attack vector for AI-driven applications.
Rather than targeting models directly, attackers can manipulate the data flowing into them. By injecting, modifying, or replaying events in real-time streams, adversaries can:
Olena will examine how these attacks work in practice, from subtle data drift manipulation to targeted event injection, and why they are difficult to detect using traditional security tools.
The talk will break down the weak points in modern data pipelines:
She will also explore how these risks evolve in systems that continuously retrain or adapt, where corrupted data doesn’t just affect a single decision but becomes embedded in the model itself.
Finally, Olena will discuss defensive strategies that go beyond securing infrastructure: treating data as an attack surface, implementing validation and anomaly detection at the data level, and designing pipelines that can detect and recover from adversarial inputs.
This talk offers a new perspective on AI security – not by focusing on models, but on the data pipelines that feed them, where some of the most impactful and least visible attacks can occur.