Events VIScon Workshop: Red Teaming: The RAG Security Balancing Act

VIScon Workshop: Red Teaming: The RAG Security Balancing Act

This event is only available for VIScon Symposium or Hackathon participants, as well as Helpers! Please sign up for one of these events first!

In this hands-on workshop, participants will learn to secure RAG systems by balancing protection and usability. Through a multi-phase process on Databricks, you will deploy a baseline application, conduct red teaming attacks to uncover vulnerabilities, and implement guardrails. By testing the trade-offs between strict security and functional performance, you will discover how to build AI systems that are both safe from adversarial threats and effective for users.

###Abstract: Workshop: The RAG Security Balancing Act (90 Minutes) Objective: Teach students how to attack a RAG system, fix the vulnerabilities, and learn the hard way that too much security ruins usability. Prerequisites: Students get access to a pre-configured Databricks workspace.

Phase 1: Deploy & Baseline (15 mins)

● The Setup: Deploy a basic, unprotected RAG application. ● The Baseline: Ask the app normal, functional questions. ● The Metrics: Measure how well it answers using standard RAGAS metrics.

Phase 2: Break It! (Red Teaming) (25 mins)

● The Attack: Students run adversarial prompts (jailbreaks, prompt injections) against the unprotected RAG. ● The Metrics: Run Red Teaming metrics to quantify how vulnerable the system is.

Phase 3: The "Over-Fix" (20 mins)

● The Fix: Students apply a set of very strict instructions to mitigate the vulnerabilities they just found. ● The Re-Test (Security): Re-run the Red Teaming metrics. Result: The app is much safer! ● The Re-Test (Usability): Re-run the normal, functional questions. Result: The app is broken! Students will see false alarms and a degraded user experience because the rules are too strict.

Phase 4: The Sweet Spot (Guardrails) (20 mins)

● The Compromise: Remove the overly strict instructions and implement smart "Guardrails" instead. ● The Final Test: Re-run both the functional and Red Teaming metrics one last time. ● The Result: Students see the optimal trade-off—a RAG system that is secure against attacks but still actually answers normal questions.

Phase 5: Wrap-up & Debrief (10 mins)

● Discuss the core lesson: Security and usability are always a trade-off.

Additional slots might become available later on. Please use the waiting list!

The VSETH General Privacy Policy applies to this event.

###Details and Prerequisites Workshops may require items VIScon cannot provide (e.g., a Laptop) which you have to bring with you or to set up something (e.g., install software) that would otherwise take up a significant chunk of the workshop. You may also need knowledge in certain fields (e.g., how to program in a specific language). All of this information can be found in the following paragraphs, so you can decide whether you want/can participate in this workshop, or not. #####What you have to bring to the workshop:

  • A Laptop

#####What you have to do before the workshop: Nothing.

#####Knowledge requirements(/recommendations) for this workshop:

  • Basic under standing of Large Language Models. No programming experience required.

###FAQ #####Why can't I sign up for this workshop? If you signed up for the main event after the early access deadline (8:00pm, 17th of September), you can sign up from the 20st of September. But don't worry, we will send you a reminder when the sign up opens. Early access is our way to thank early supporters!

Event Organisers
The fine print
  • By participating you agree that pictures and videos can be taken of you that could be used for VIS-Purposes (VISIONEN, Instagram, etc)

  • By participating, you agree to adhere by the VIS Code of Conduct

  • Every participant is responsible for their own insurance

  • All statements are made without guarantee

  • In general, there are no refunds