
OWASP Boston Chapter Meeting - October 2026
About the event
OWASP Boston Chapter Meetups aim to connect app sec enthusiasts and talk on any topic in application security. Doors open at 6:30pm and the presentation starts at 7pm. Pizza and soda will be provided. This will be an in person meetup only.
*ONLY HUMANS ALLOWED! PLEASE BRING AN ID AS THIS IS REQUIRED BY OUR HOSTS. YOUR NAME IN THE REGISTRATION FORM SHOULD MATCH THE ONE ON YOUR ID*
Thank you to our sponsors Maze (http://www.mazehq.com)
Talk Title - Prompt Injection as an Architectural Primitive by Shubham Santosh Upadhyay
Talk Description - Prompt injection is usually treated as one problem with one fix: detection. This talk argues it is three distinct problems (type confusion\, control-flow hijacking\, and causal provenance) and presents experimental evidence that detection cannot solve the hard one. Across four detector families\, imperative injections were caught reliably\, but semantically poisoned documents corrupted agent decisions in 100% of runs while every detector scored at chance. I derive why false positives compound with pipeline depth\, making screening mathematically untenable in multi-step agents\, and close with architectural requirements that actually address the problem. Code and results are open source.
About the speaker - I'm an AI security engineer at a large enterprise technology company\, where I focus on threat modeling agentic pipelines\, MCP server security\, and secure-by-default architectures for GenAI workloads. This talk is based on my independent research paper on prompt injection\, with a fully reproducible experiment harness on GitHub.




