Bridging the AI Bias Gap: Proactive Initiatives in Cybersecurity Approaches
Download resourcesAbout this session
Mina Movahedi Shakib, a cyber threat investigator at Bell Canada's SOC, explains what AI bias is and why over-reliance on AI is a new threat per OWASP's Gen AI Top 10. She breaks bias into three sources: data (historical, representation, measurement, labeling, aggregation and reporting bias, illustrated with Amazon's biased hiring tool and racial bias in facial recognition and healthcare), algorithm (age discrimination in a retirement system, zip-code-based credit and lending bias, skewed Facebook ad delivery), and human (developer, confirmation and evaluation bias). She applies this to cybersecurity: biased facial recognition, intrusion detection and malware classification systems, and the vulnerabilities they create, including data poisoning that trains defenders to whitelist real threats as benign. A COMPAS recidivism-scoring case shows Black defendants mislabeled high-risk twice as often as white defendants. She closes with mitigation toolkits such as AI Fairness 360, bias checks at the pre-, in- and post-processing stages, and an action plan built on diversity, transparency, human oversight and governance for developers, security teams, leaders and policymakers.
AI bias in cybersecurity can lead to false positives, security vulnerabilities, and unfair surveillance. This presentation explores bias mitigation strategies, including diverse data, algorithmic fairness, human oversight, and ethical governance to enhance trustworthy AI-driven threat detection.
Key takeaways
- Treat over-reliance on AI output as its own threat category (OWASP LLM09, misinformation): verify AI outputs rather than copy-pasting them, especially for incident classification.
- Check whether your training or reference data represents diverse populations, languages and less-common operating systems; facial recognition accuracy and language support gaps show up first for underrepresented groups.
- Watch for algorithmic proxies, such as zip code, purchase history or language pattern, that recreate the discrimination that fields like age or race would trigger directly.
- Guard against data poisoning: attackers can deliberately seed benign-looking signals to train your OSINT or detection tooling to whitelist real threats.
- Build bias checks into all three LLM stages, pre-processing, in-processing and post-processing, and keep a human-oversight feedback loop rather than treating AI output as a final decision.
Speakers

Mina Movahedi Shakib is a seasoned cybersecurity professional with over a decade of experience in the tech industry. Her foundation in Wireless Networking and Cybersecurity, combined with her current role as a Cyber Threat Investigator at Bell… Read moreRead less
Mina Movahedi Shakib is a seasoned cybersecurity professional with over a decade of experience in the tech industry. Her foundation in Wireless Networking and Cybersecurity, combined with her current role as a Cyber Threat Investigator at Bell Canada's Security Operations Center, makes her a vital asset in safeguarding digital landscapes. Mina thrives in the fast-paced world of threat detection, incident response, and security operations, always seeking innovative ways to advance security measures. Mina is not just about technical expertise; she is a dynamic speaker at numerous in-person and virtual cybersecurity conferences, including HackFest2024, LCL2025, Ottawa CIS 2025, ISC2 Toronto Chapter, 2025 annual cybersecurity summit and CIBC events. She is also deeply committed to mentorship, actively empowering women in technology and fostering the next generation of innovators. Passionate about exploring the intersection of cybersecurity and artificial intelligence, Mina believes in the transformative potential of AI-driven solutions to tackle real-world challenges, especially in enhancing security and efficiency.
