Ghost in the Grid: Hijacking AI Agents Through Hidden Channels in OT/ICS Networks
About This Session
AI agents are now operating inside the Purdue Model. At Levels 2 and 3, they are reading SCADA outputs, interpreting HMI screens and camera feeds, and issuing commands to supervisory systems and controllers. The security community has not caught up. No existing OT security layer watches what these agents perceive or act on.
This session presents original research into a new class of attack: steganographic prompt injection against Vision Language Models operating in live industrial environments. Attackers embed hidden instructions inside camera frames, HMI screenshots, maintenance PDFs, and sensor data visualizations using techniques. The agent extracts the payload, interprets it as a legitimate operational instruction, and acts on it. No network anomaly. No signature match. No alert.
We walk through three attack vectors mapped to the Purdue Model:
Steganographic injection into camera feeds at Level 3, targeting a Vision Language Model processing quality control imagery in a simulated manufacturing environment.
Trust laundering across a multi-agent supervisory chain at Level 2, where a poisoned input to Agent A propagates as trusted context to Agent B without ever appearing in a single suspicious message.
Adversarial audio perturbations targeting voice-enabled autonomous systems on the factory floor.
Each vector is demonstrated live, followed by a detection and mitigation walkthrough using a perception-layer security architecture that intercepts agent inputs before inference. The architecture integrates into existing OT network designs without requiring changes to PLC, historian, or SCADA configurations.
We close with a mapping of these attack patterns to MITRE ATT&CK for ICS and the NIST AI Risk Management Framework, giving asset operators a compliance-ready vocabulary for communicating risk to leadership and auditors.
This session presents original research into a new class of attack: steganographic prompt injection against Vision Language Models operating in live industrial environments. Attackers embed hidden instructions inside camera frames, HMI screenshots, maintenance PDFs, and sensor data visualizations using techniques. The agent extracts the payload, interprets it as a legitimate operational instruction, and acts on it. No network anomaly. No signature match. No alert.
We walk through three attack vectors mapped to the Purdue Model:
Steganographic injection into camera feeds at Level 3, targeting a Vision Language Model processing quality control imagery in a simulated manufacturing environment.
Trust laundering across a multi-agent supervisory chain at Level 2, where a poisoned input to Agent A propagates as trusted context to Agent B without ever appearing in a single suspicious message.
Adversarial audio perturbations targeting voice-enabled autonomous systems on the factory floor.
Each vector is demonstrated live, followed by a detection and mitigation walkthrough using a perception-layer security architecture that intercepts agent inputs before inference. The architecture integrates into existing OT network designs without requiring changes to PLC, historian, or SCADA configurations.
We close with a mapping of these attack patterns to MITRE ATT&CK for ICS and the NIST AI Risk Management Framework, giving asset operators a compliance-ready vocabulary for communicating risk to leadership and auditors.
Speaker
Ram Rajagopalan
Founder CEO - neuralcy
Ram Rajagopalan is the Founder and CEO of Neuralcy, an AI security company focused on detecting and neutralizing threats to AI agents operating in critical infrastructure, OT/IoT, and physical AI environments. He leads original research into steganographic attack channels against Vision Language Models and multi-agent systems, with provisional patent applications covering multimodal hidden-prompt detection and runtime AI agent defense mechanisms. Prior to Neuralcy, he held senior technology leadership roles across enterprise software and infrastructure at Amazon, Qualcomm, ResMed, Jina AI, Appen AI and Hughes
