
Harshit Kohli
Senior Technical Account Manager
AWS
About
Harshit Kohli is a Senior Technical Account Manager at AWS specializing in AI/ML security and infrastructure. With over a decade of experience in cloud security and machine learning systems, he has helped organizations secure their AI deployments at scale. Harshit has conducted security research on LLM vulnerabilities, adversarial attacks, and AI model protection, and regularly advises enterprises on implementing secure AI architectures. He holds multiple AWS certifications and has presented at internal AWS security forums on emerging AI threats.
Sessions
Breaking the Stream: Real-Time AI Model Exploitation and Defense Strategies
What you will learn:
1. Practical exploitation skills: Hands-on understanding of 5+ AI attack techniques including real-time streaming exploits, with code examples and tools they can use to test their own systems 2. Actionable defense playbook: A comprehensive security framework with specific controls for streaming AI, including token-level validation, real-time monitoring configurations, and circuit breaker implementations 3. Real-world threat intelligence: Knowledge of active attack campaigns targeting streaming AI systems, TTPs used by threat actors, and indicators of compromise for streaming-specific attacks 4. Security testing toolkit: Access to open-source tools, scripts, and methodologies for penetration testing streaming AI systems, including WebSocket/SSE security testing frameworks 5. Streaming AI security architecture: A structured approach to secure real-time inference deployments, including edge protection, rate limiting strategies, and monitoring for streaming endpoints
Agentic AI with Cloud Credentials: The Attack Surface Nobody's Governing Yet
What you will learn:
•A threat model for agentic AI that maps agent capabilities to ATTACK-style techniques — permission escalation, lateral movement, data exfiltration through tool-use chains •Three specific detection signatures that distinguish autonomous AI agent behavior from human operators and traditional compromised credentials •Architectural patterns for blast radius containment when AI agents operate across account boundaries — what "least privilege" actually means for an entity that can reason about its own permissions •A practical framework for evaluating which agentic workflows are safe to deploy without human-in-the-loop gates vs. which ones need kill switches •Why current AI governance (model cards, responsible AI frameworks) is insufficient for operational security of deployed agents — and what to replace it with