This event is only available for VIScon Symposium or Hackathon participants, as well as Helpers! Please sign up for one of these events first!
In this hands-on workshop, participants will learn to secure RAG systems by balancing protection and usability. Through a multi-phase process on Databricks, you will deploy a baseline application, conduct red teaming attacks to uncover vulnerabilities, and implement guardrails. By testing the trade-offs between strict security and functional performance, you will discover how to build AI systems that are both safe from adversarial threats and effective for users.
###Abstract: Workshop: The RAG Security Balancing Act (90 Minutes) Objective: Teach students how to attack a RAG system, fix the vulnerabilities, and learn the hard way that too much security ruins usability. Prerequisites: Students get access to a pre-configured Databricks workspace.
Phase 1: Deploy & Baseline (15 mins)
● The Setup: Deploy a basic, unprotected RAG application. ● The Baseline: Ask the app normal, functional questions. ● The Metrics: Measure how well it answers using standard RAGAS metrics.
Phase 2: Break It! (Red Teaming) (25 mins)
● The Attack: Students run adversarial prompts (jailbreaks, prompt injections) against the unprotected RAG. ● The Metrics: Run Red Teaming metrics to quantify how vulnerable the system is.
Phase 3: The "Over-Fix" (20 mins)
● The Fix: Students apply a set of very strict instructions to mitigate the vulnerabilities they just found. ● The Re-Test (Security): Re-run the Red Teaming metrics. Result: The app is much safer! ● The Re-Test (Usability): Re-run the normal, functional questions. Result: The app is broken! Students will see false alarms and a degraded user experience because the rules are too strict.
Phase 4: The Sweet Spot (Guardrails) (20 mins)
● The Compromise: Remove the overly strict instructions and implement smart "Guardrails" instead. ● The Final Test: Re-run both the functional and Red Teaming metrics one last time. ● The Result: Students see the optimal trade-off—a RAG system that is secure against attacks but still actually answers normal questions.
Phase 5: Wrap-up & Debrief (10 mins)
● Discuss the core lesson: Security and usability are always a trade-off.
Additional slots might become available later on. Please use the waiting list!
The VSETH General Privacy Policy applies to this event.
###Details and Prerequisites Workshops may require items VIScon cannot provide (e.g., a Laptop) which you have to bring with you or to set up something (e.g., install software) that would otherwise take up a significant chunk of the workshop. You may also need knowledge in certain fields (e.g., how to program in a specific language). All of this information can be found in the following paragraphs, so you can decide whether you want/can participate in this workshop, or not. #####What you have to bring to the workshop:
- A Laptop
#####What you have to do before the workshop: Nothing.
#####Knowledge requirements(/recommendations) for this workshop:
- Basic under standing of Large Language Models. No programming experience required.
###FAQ #####Why can't I sign up for this workshop? If you signed up for the main event after the early access deadline (8:00pm, 17th of September), you can sign up from the 20st of September. But don't worry, we will send you a reminder when the sign up opens. Early access is our way to thank early supporters!
Event Organisers
- Kaushik Vempati
Main Organiser
- Luigi Pizza
Co-organiser
- Theo Trahtenbroit
Co-organiser
- Niklas Tischler
Co-organiser
- Stanislav Drozhilkin
Co-organiser
The fine print
-
By participating you agree that pictures and videos can be taken of you that could be used for VIS-Purposes (VISIONEN, Instagram, etc)
-
By participating, you agree to adhere by the VIS Code of Conduct
-
Every participant is responsible for their own insurance
-
All statements are made without guarantee
-
In general, there are no refunds