From Alert to Action: AI-Powered Automation for Vulnerability Remediation
About this session
Modern software systems generate an overwhelming volume of vulnerability alerts from scanners, dependency audits, and CI/CD pipelines. While detection tools have become highly sophisticated, the real bottleneck in application security is no longer identifying issues but deciding what to fix, how to fix it safely, and how to apply upgrades without breaking production systems.
In this talk, I will share practical lessons from building systems that move beyond vulnerability detection toward AI-assisted remediation and automated software upgrades. We will explore the engineering challenges of turning raw security findings into actionable, safe, and prioritized upgrade decisions.
The session will cover how AI can be used to enrich vulnerability data with contextual understanding of dependency graphs, runtime usage, and upgrade compatibility. I will discuss architectural patterns for generating remediation recommendations, validating them against constraints such as semantic versioning and breaking changes, and integrating human-in-the-loop safeguards to ensure trust and reliability.
Importantly, this talk will also highlight real-world failure modes such as incorrect upgrade suggestions, dependency conflicts, and overconfident model outputs and what engineering patterns helped mitigate them. Rather than focusing on detection or theoretical AI capabilities, the emphasis will be on practical system design decisions required to make remediation workflows usable in production environments.
Attendees will leave with a clear understanding of how to design systems that reduce alert fatigue, improve remediation velocity, and safely integrate AI into the software upgrade lifecycle.
Speaker
Key takeaways
- Vulnerability detection is solved, remediation is the real engineering problem
- Trust in automation requires guardrails, not full autonomy
- AI can accelerate remediation only when grounded in system context and constraints