PodParley PodParley

Vulnerabilities In Enterprise AI Workflows With Nicolas Dupont

As AI systems become increasingly integrated into enterprise workflows, a new security frontier is emerging. In this episode of The Secure Developer, host Danny Allan speaks with Nicolas Dupont about the often-overlooked vulnerabilities hiding in vector databases and how they can be exploited to expose sensitive data.

Episode 171 of the The Secure Developer podcast, hosted by Nicolas Dupont, Danny Allan, titled "Vulnerabilities In Enterprise AI Workflows With Nicolas Dupont" was published on December 2, 2025 and runs 34 minutes.

December 2, 2025 ·34m · The Secure Developer

0:00 / 0:00

As AI systems become increasingly integrated into enterprise workflows, a new security frontier is emerging. In this episode of The Secure Developer, host Danny Allan speaks with Nicolas Dupont about the often-overlooked vulnerabilities hiding in vector databases and how they can be exploited to expose sensitive data.

Episode Summary

As AI systems become increasingly integrated into enterprise workflows, a new security frontier is emerging. In this episode of The Secure Developer, host Danny Allan speaks with Nicolas Dupont about the often-overlooked vulnerabilities hiding in vector databases and how they can be exploited to expose sensitive data.

Show Notes

As organizations shift their focus from training massive models to deploying them for inference and ROI, they are increasingly centralizing proprietary data into vector databases to power RAG (Retrieval-Augmented Generation) and agentic workflows. However, these vector stores are frequently deployed with insufficient security measures, often relying on the dangerous misconception that vector embeddings are unintelligible one-way hashes.

Nicolas Dupont explains that vector embeddings are simply dense representations of semantic meaning that can be inverted back to their original text or media formats relatively trivially. Because vector databases traditionally require plain text access to perform similarity searches efficiently, they often lack encryption-in-use, making them susceptible to data exfiltration and prompt injection attacks via context loading. This is particularly concerning when autonomous agents are over-provisioned with write access, potentially allowing malicious actors to poison the knowledge base or manipulate system prompts.

The discussion highlights the need for a "secure by inception" approach, advocating for granular encryption that protects data even during processing without incurring massive performance penalties. Beyond security, this architectural rigor is essential for meeting privacy regulations like GDPR and HIPAA in regulated industries. The episode concludes with a look at the future of AI security, emphasizing that while AI can accelerate defense, attackers are simultaneously leveraging the same tools to create more sophisticated threats.

Links

Follow Us

The Secure World Foundation Podcast Secure World Foundation This podcast features content produced by the Secure World Foundation (SWF), an endowed, private operating foundation that promotes cooperative solutions for space sustainability and the peaceful uses of outer space. The Foundation acts as a research body, convener and facilitator to promote key space security, and other related topics, and to examine their influence on governance and international development. The Future Healthcare Today Podcast Future Healthcare Today Welcome to the Future Healthcare Today podcast. Join us as we explore the rapidly changing healthcare industry from the perspectives of providers, payers, and pharmaceutical and life sciences organizations. In each episode, we'll bring you engaging conversations with industry leaders and technology experts who are driving innovation in search of better patient outcomes and a more efficient healthcare system. We’ll dive into a wide range of topics including telehealth, how AI is changing patient experiences and drug developments, as well as best practices on how to secure critical data and PII. You will gain insights on how to put technology to work to improve patient outcomes, streamline operations, and reduce the costs of innovation. To learn more, check out our website:https://futurehealthcaretoday.com The Secure Woman Podcast Your Lifestylist Im your Lifestylist,Welcome to the Secure Woman podcast. Where I talk about the tools to elevating your thinking, move pass past trauma and we talk about healing is a journey. Our conversations are geared towards help women master their emotions and manifest their dream life, we are moving full throttle pass the pain. This podcast is for those looking to WIN past the pain. Support this podcast: https://podcasters.spotify.com/pod/show/yourlifestylist/support Secure the Future Dave Maasland Secure the Future is een maandelijkse podcast over digitale beveiliging. Met CISO’s, voor CISO’s. Over hoe we vandaag beschermen om morgen veiliger te zijn.Ik ben Dave Maasland en in de Secure the Future podcast ga ik in gesprek met vooraanstaande securityleiders in ons land. Je leert als CISO hoe vakcollega’s naar dit vak kijken, juist in deze tijd. Hoe gaan we om met de huidige ransomwarecrisis? Hoe bereiden we ons voor op dreigingen in de toekomst? Hoe begin je in het CISO-vak? En hoe zet je een sterk securityframework neer?Kortom: het is tijd om CISO’s in Nederland met elkaar te verbinden en meer kennis uit te wisselen. Natuurlijk ga ik ook met hen in gesprek over wie ze zijn als mens en hoe ze hier zijn gekomen.Luister daarom elke maand naar de Secure the Future podcast dé podcast over digitale beveiliging met CISO’s, voor CISO’s.
URL copied to clipboard!