Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
The AI Threat Landscape
- Why AI security diverges from traditional models: non-determinism, opaque reasoning, and prompts as attack surfaces
- Categorizing attacks: training-time vs. inference-time vs. supply chain threats
- The ML adversary model: understanding who attacks AI systems and their motivations
OWASP Top 10 for LLM Applications
- Prompt injection: analyzing direct and indirect attack vectors
- Unsafe output handling and cross-plugin request forgery
- Training data poisoning and supply chain vulnerabilities
- Model denial of service, sensitive data exposure, and excessive agency
- Practical lab: exploiting each OWASP category against a test application
Prompt Injection and Jailbreak Red Teaming
- Taxonomy of injection methods: direct, indirect, multi-turn, and multi-modal approaches
- Automated red-teaming using Giskard, Garak, and custom fuzzing tools
- Classifying jailbreak attempts and evaluating defense effectiveness
- Developing a red-team harness for ongoing LLM security testing
Model-Level Attacks and Defenses
- Model extraction: stealing weights and functionality through API queries
- Membership inference: determining whether specific data was included in the training set
- Adversarial examples: creating perturbations that deceive classifiers and embeddings
- Data poisoning: corrupting training data to create backdoors or degrade performance
Input and Output Security Controls
- Input sanitization techniques that go beyond standard web defenses
- Output filtering: addressing toxicity, PII leaks, and hallucinated code execution
- Guardrails as security infrastructure: utilizing NeMo, Guardrails AI, and custom policies
- Enforcing structured outputs as a key security boundary
AI Supply Chain Security
- Model provenance: verifying the authenticity and integrity of models
- Scanning dependencies in ML frameworks and model formats
- Secure model serving: implementing sandboxing, network isolation, and least-privilege access
- Vetting fine-tuned and community models for embedded malware
Operational Security for AI Systems
- Managing access controls for model endpoints, vector stores, and agent tools
- Maintaining audit logs for all model interactions and decisions
- Incident response for AI-specific breaches, including cases where the model itself is compromised
- Integrating continuous security testing into CI/CD for ML pipelines
Building an AI Security Program
- Establishing an AI security maturity model and strategic roadmap
- Integrating AI security into existing AppSec and cloud security frameworks
- Navigating governance frameworks and emerging regulations for AI systems
- Creating and maintaining a comprehensive organizational AI security playbook
Requirements
- Hands-on experience deploying ML models or LLM applications in production environments.
- Solid grasp of core security concepts, including authentication, authorization, and threat modeling.
- Proficiency in Python to support adversarial testing tasks.
Target Audience
- Security engineers broadening their expertise into AI/ML threat landscapes.
- ML engineers tasked with ensuring model safety and robustness.
- Red team professionals incorporating AI systems into their testing scope.
14 Hours