A look at the proactive research, agentic AI defenses, and open-
Next week, members of the Roblox InfoSec team will gather with some of the world’s leading researchers in Las Vegas for BSidesLV, Black Hat, and DEF CON, also known as Hacker Summer Camp. Our InfoSec team will share a glimpse into new research around AI agents pushing credentials to public repositories, building our own agentic defenses and open-
Roblox manages a platform where millions of creators build games and businesses, 123 million daily active users connect around the world,1 and billions of dollars move across the ecosystem. We maintain a resilient platform through a proactive, adaptable, and scalable approach to cybersecurity. Building and implementing new technology to help empower creators and improve safety requires continuous innovation, deep technical research, and a forward-looking security posture.
Check out all the talks below and join us at our networking event. Our InfoSec research and engineering leaders are eager to share insights and open-
BSidesLV: Spanning the Eras: Egress Domain Governance from On-Premises to Agentic Sandboxes
Tuesday, Aug. 4 | 5:00 p.m.–5:30 p.m. (Room: Firenze)
Security teams often detect suspicious egress domains or raw IP addresses but cannot determine which internal service generated the traffic. In modern hybrid-cloud environments, egress traffic may originate from many ephemeral containers across the same or different hosts. Hosts are also online and offline, which makes service attribution extremely difficult. In this talk, we’ll introduce a practical automation system that combines service attribution and principled governance workflow to enable safe and efficient egress security controls in modern hybrid cloud environments.
Speaker: Biao Gao, Senior Security Software Engineer, Roblox
BSidesLV: Minutes from Malice: Detect Cloud Exposures in Minutes
Date: Wednesday, Aug. 5 | 11:00 a.m.–11:30 a.m. (Room: Firenze)
Cloud infrastructure changes continuously, making cloud network exposure dynamic and challenging. Traditional scanners aren’t enough when rece framework using cloud inventory APIs for near real-time exposure monitoring across hybrid cloud and on-prem networks at any scale
Speaker: Qiancheng (Mark) Wu, Senior Software Engineer, Roblox
Black Hat: From Prompts to Pipelines: Building Agentic Detection Engineering and Threat Hunting
Wednesday, Aug. 5 | 11:05 a.m.–11:45 a.m. (Room: Oceanside B, Level 2)
Detection engineering and threat hunting remain bottlenecked by the gap between threat intelligence and deployed defenses. The team is presenting two agentic AI frameworks built for these problems: (1) AI Detection Engineer, a multi-agent pipeline that decomposes the detection authoring workflow into five specialized stages with trust boundaries and network isolation: research, gap analysis, rule engineering, adversarial review, and live runtime validation; and (2) Threat Hunter Graph, a LangGraph-based state machine that autonomously plans, executes, pivots, and judges threat hunts against live SIEM data.
- Shoufu Luo, Principal Security Software Engineer, Roblox
- Zhenda Hu, Software Engineer, Roblox
Black Hat: Privacy at Scale: Roblox’s Infrastructure for Honoring User Privacy Rights
Wednesday, Aug. 5 | 2:35 p.m.–3:15 p.m. (Room: Mandalay Bay H, Level 2)
Modern online platforms operate complex distributed systems that store user data across hundreds of services and datastores. Honoring user privacy rights requires infrastructure capable of orchestrating data access and erasure requests across heterogeneous storages and service layers. We’ll share operational challenges we’ve encountered in distributed privacy enforcement, our system architecture, and several key supporting components, including a centralized metadata catalog and an orchestration layer that coordinates request execution.
- Hao Zhang, Engineering Manager, Roblox
- Yiwen Luo, Principal Privacy Software Engineer, Roblox
- Minkyong Kim, Director of Engineering, Roblox
- Nicole Grinstead, Chief Information Security Officer, Roblox
Black Hat:Caging the Agent: How Roblox Built Multi-Layer Sandboxes to Secure Claude Code at Enterprise Scale
Thursday, Aug. 6 | 3:35 p.m.–4:15 p.m. (Room: South Seas A&B, Level 3)
A hidden instruction in a GitHub Issue convinced Claude Code to upload Roblox’s credentials to a public repository. EDR saw nothing—it was a normal process making a normal network request. The good news: It happened in an internal testing environment. We’ll share how and why this happens, the kill chain, the architecture that contains it, and three problems that sandboxing alone cannot solve.
- Harshit Kumar, Principal Security Software Engineer, Roblox
- Jaskaran Singh, Principal Security Software Engineer, Roblox
- Ahmad Alomari, Senior Manager, Application Security, Roblox
Meet Us at the Infosec Networking Mixer, Hosted by Roblox
Thursday, Aug. 6, 2024 | 7:00 p.m.–9:00 p.m.
Exact location to be provided in RSVP confirmation email.
Join us for an evening of networking and tech talks! We’ll explore the frontlines of modern cybersecurity—from AI-driven developer tools to our security strategies for a platform operating over 400 AI models and processing 1.5 million inferences per second across on-premise and public cloud GPUs. Follow the link below to request an invitation.
To learn more about our approach to cybersecurity at Roblox, visit our Security page.
1As of Q2, 2026.
