CS Colloquium– “From Prompts to Silicon: Security and Privacy Threats Across the LLM Stack,” Nael Abu-Ghazaleh
September 25, 2026 11 a.m.–12 p.m.
Location
Galileo Hall, Pryne
240 Platt Blvd.
Claremont, CA 91711
Contact
Morgan McArdle
mmcardle@g.hmc.edu
909.607.0299
Details
Large language models are now trusted with sensitive data, embedded in consequential decision pipelines, and are hosted on shared, expensive hardware. These factors make them an increasingly attractive target, and not just at the level of what you type into a chat box. In this talk, we'll go on a tour of LLM security and privacy threats, organized around a simple question, looking at different classes of attacks based on attackers' access points.
Abu-Ghazaleh starts where most people think LLM security lives: at the prompt itself, showing how attackers with malicious intent can bypass the model’s safety training. A second group of attacks targets training time, where an attacker who controls even a small slice of a model's training data can plant hidden behaviors that surface only later, including those that enable leaking private information or undermining the safety alignment of the model. Finally, Abu-Ghazaleh goes below the model entirely, to the hardware it runs on: his recent work shows the GPU infrastructure powering today’s LLMs leaks information across users who are supposed to be strongly isolated from each other. Taken together, these attacks show that LLM security isn’t one problem but several, spread across different layers of the stack, including inference time, training time, and hardware and system vulnerabilities. Abu-Ghazaleh closes with where he thinks the most promising defenses lie, and the open questions.
Speaker
Nael Abu-Ghazaleh is a professor in the Computer Science and Engineering Department at the University of California, Riverside. His research is in architecture and system security, and security for emerging systems. He has published over 250 papers in these areas, several of which have been recognized with best paper awards or nominations. His offensive security research has resulted in the discovery of several new attacks on CPUs and GPUs that have been disclosed to companies including Intel, AMD, ARM, Apple, Microsoft, Google and Nvidia, and resulted in patches and modifications to products, and coverage from technical news outlets. He is a member of the Micro Hall of Fame, an ACM distinguished member, an IEEE distinguished speaker and an IEEE Computer Society Distinguished Contributor.
This event is for: faculty, staff, students
Community Connections events provide opportunities for HMC faculty, students and staff to cultivate community, foster open conversations and share important information as together we live out our mission and shape the future of the College.