Get in Touch

Course Outline

The AI Threat Landscape

  • Why AI security differs: non-determinism, opaque reasoning, and prompts as an attack surface.
  • Attack taxonomy: distinguishing between training-time, inference-time, and supply chain attacks.
  • The ML adversary model: understanding who attacks AI systems and their motivations.

OWASP Top 10 for LLM Applications

  • Prompt injection: exploring direct and indirect attack vectors.
  • Insecure output handling and cross-plugin request forgery.
  • Training data poisoning and supply chain vulnerabilities.
  • Model denial of service, sensitive information disclosure, and excessive agency.
  • Hands-on lab: exploiting each OWASP category against a test application.

Prompt Injection and Jailbreak Red Teaming

  • Taxonomy of injection techniques: direct, indirect, multi-turn, and multi-modal.
  • Automated red-teaming using Giskard, Garak, and custom fuzzing tools.
  • Jailbreak classification and evaluation of defense mechanisms.
  • Constructing a red-team harness for continuous LLM security testing.

Model-Level Attacks and Defenses

  • Model extraction: stealing model weights and functionality via API queries.
  • Membership inference: determining whether specific data was part of the training set.
  • Adversarial examples: perturbations designed to fool classifiers and embeddings.
  • Data poisoning: corrupting training data to induce backdoors or degrade performance.

Input and Output Security Controls

  • Advanced input sanitization beyond traditional web defenses.
  • Output filtering for toxicity, PII leakage, and hallucinated code execution.
  • Guardrails as security infrastructure: utilizing NeMo, Guardrails AI, and custom policies.
  • Using structured output enforcement as a security boundary.

AI Supply Chain Security

  • Model provenance: verifying model authenticity and integrity.
  • Dependency scanning for ML frameworks and model formats.
  • Secure model serving practices: sandboxing, network isolation, and least-privilege access.
  • Vetting fine-tuned and community models for embedded malware.

Operational Security for AI Systems

  • Access control for model endpoints, vector stores, and agent tools.
  • Audit logging for every model interaction and decision made.
  • Incident response protocols for AI-specific breaches, including when the model itself is compromised.
  • Implementing continuous security testing in CI/CD for ML pipelines.

Building an AI Security Program

  • Establishing an AI security maturity model and roadmap.
  • Integrating AI security into existing AppSec and cloud security programs.
  • Navigating governance frameworks and emerging regulations for AI systems.
  • Creating and maintaining an organizational AI security playbook.

Requirements

  • Experience deploying ML models or LLM applications in production environments.
  • Familiarity with core security concepts, including authentication, authorization, and threat modeling.
  • Proficiency in Python for conducting adversarial testing exercises.

Target Audience

  • Security engineers expanding their focus into AI/ML threat surfaces.
  • ML engineers responsible for ensuring model safety and robustness.
  • Red team members incorporating AI systems into their testing scope.
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories