Get in Touch

Course Outline

The AI Threat Landscape

  • Why AI security differs: non-determinism, opaque reasoning, and prompts as attack surfaces.
  • Attack taxonomy: training-time vs. inference-time vs. supply chain attacks.
  • The ML adversary model: who attacks AI systems and their motivations.

OWASP Top 10 for LLM Applications

  • Prompt injection: direct and indirect attack vectors.
  • Insecure output handling and cross-plugin request forgery.
  • Training data poisoning and supply chain vulnerabilities.
  • Model denial of service, sensitive information disclosure, and excessive agency.
  • Hands-on lab: exploiting each OWASP category against a test application.

Prompt Injection and Jailbreak Red Teaming

  • Taxonomy of injection techniques: direct, indirect, multi-turn, and multi-modal.
  • Automated red-teaming using Giskard, Garak, and custom fuzzing tools.
  • Jailbreak classification and defense evaluation.
  • Building a red-team harness for continuous LLM security testing.

Model-Level Attacks and Defenses

  • Model extraction: stealing model weights and functionality via API queries.
  • Membership inference: determining if specific data was part of the training set.
  • Adversarial examples: perturbations designed to fool classifiers and embeddings.
  • Data poisoning: corrupting training data to induce backdoors or degrade performance.

Input and Output Security Controls

  • Advanced input sanitization beyond traditional web defenses.
  • Output filtering: managing toxicity, PII leakage, and hallucinated code execution.
  • Guardrails as security infrastructure: utilizing NeMo, Guardrails AI, and custom policies.
  • Enforcing structured outputs as a security boundary.

AI Supply Chain Security

  • Model provenance: verifying model authenticity and integrity.
  • Dependency scanning for ML frameworks and model formats.
  • Secure model serving: sandboxing, network isolation, and least-privilege access.
  • Vetting fine-tuned and community models for embedded malware.

Operational Security for AI Systems

  • Access control for model endpoints, vector stores, and agent tools.
  • Audit logging for every model interaction and decision.
  • Incident response for AI-specific breaches: when the model itself is compromised.
  • Continuous security testing within CI/CD pipelines for ML workflows.

Building an AI Security Program

  • AI security maturity models and roadmaps.
  • Integrating AI security into existing AppSec and cloud security programs.
  • Governance frameworks and emerging regulations for AI systems.
  • Creating and maintaining an organizational AI security playbook.

Requirements

  • Experience in deploying ML models or LLM applications in production environments.
  • Familiarity with core security concepts, including authentication, authorization, and threat modeling.
  • Proficiency in Python for conducting adversarial testing exercises.

Audience

  • Security engineers expanding their expertise into AI/ML threat landscapes.
  • ML engineers responsible for ensuring model safety and robustness.
  • Red team members incorporating AI systems into their testing scope.
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories