AI security practitioner course

AI Security Engineering

From models to agentic systems: an evidence-grounded course for assessing, securing, monitoring, and investigating the complete AI technology stack.

15 modules Intermediate–advanced Lab intensive CTI evidence base

Security for the complete AI system

The model is only one component. The course examines data, retrieval, prompts, tools, agents, identities, application code, infrastructure, operators, and downstream actions as one security-sensitive system.

Evidence based

Learn from real incidents, provider threat reports, vulnerability disclosures, malicious artifacts, and reproducible security research.

Attack and defend

Reproduce trust-boundary failures, preserve evidence, implement layered controls, and verify fixes with regression tests.

Operationally grounded

Connect threat intelligence to architecture, testing, telemetry, detection engineering, incident response, and governance.

2026 course-market research

Built to connect the disciplines other courses separate

The syllabus was checked against publicly documented professional training, certification paths, hands-on academies, and cloud-vendor courses. The market is strongest in LLM application testing and offensive AI. This course retains that depth and connects it to architecture, identity, supply chain, production detection, incident response, forensics, and evidence-backed assurance.

Compared across the market

SANS, Hack The Box, PortSwigger, OffSec, EC-Council, INE, Practical DevSecOps, Microsoft, AWS, and CSA/Northeastern informed the coverage analysis.

Not only red teaming

Every major attack exercise continues through observability, layered mitigation, detection, incident handling, and regression testing.

CTI is the evidence spine

Real incidents, provider observations, disclosures, and reproducible research determine priorities. CTI supports the AI-security engineering—not the reverse.

Course method

Every module follows evidence to engineering

The course uses one repeatable method so learners can move from a report or disclosure to a defensible control and a testable security decision.

  1. Frame the decision

    Consumer and intelligence requirement

    Name who needs to decide, which system is in scope, what uncertainty matters, and what evidence threshold supports action.

  2. Reconstruct the mechanism

    Technical and adversary procedure

    Trace prerequisites, identities, inputs, model or application behavior, state changes, affected assets, and outcomes using precise technical verbs.

  3. Design and instrument controls

    Prevention through investigation

    Assign controls outside the model, reduce authority and blast radius, define observable signals, and preserve the evidence required for causal reconstruction.

  4. Validate and communicate

    Authorized testing and calibrated judgment

    Use isolated course-owned targets, repeatable artifacts, regression tests, source-backed claims, explicit limitations, and confidence that matches the evidence.

Evidence language matters: a confirmed incident, provider-observed misuse, disclosed vulnerability, malicious artifact, demonstrated research result, forecast, and constructed scenario lead to different conclusions. Framework labels never replace source evidence.

The syllabus

Fifteen modules from technical foundations to secure delivery

Each module has a dedicated page containing its lessons, practical exercises, workbook, assessment, and instructor guidance. Modules 00 and 01 are available now; the remaining modules are being built.

  1. AI, Machine Learning & LLM Foundations

    Technical foundation

    Master the complete vocabulary and technical mental model used throughout the course: AI and ML problem types, training and inference, neural networks, Transformers, LLM lifecycle, embeddings, RAG, agents, MCP, evaluation, model serving, and MLOps.

  2. AI Security Threat Landscape

    Intelligence and architecture

    Build the complete AI attack-surface model from real incidents, provider observations, production vulnerabilities, malicious artifacts, and reproducible research. Learn to distinguish observed activity from demonstrated capability and turn evidence into controls and telemetry.

    Open module
  3. Architecture, Trust Boundaries & Threat Modeling

    Foundation

    Model hosted and self-managed AI applications as assets, identities, data flows, policy decisions, and trust boundaries. Find confused-deputy paths and security decisions incorrectly delegated to a probabilistic model.

    Under construction
  4. Data, Ingestion, Embeddings & RAG Security

    Data security

    Secure document ingestion, parsing, chunking, embeddings, vector stores, retrieval authorization, source provenance, and deletion. Build and test a tenant-safe RAG pipeline against poisoning and indirect injection.

    Under construction
  5. Models, Dependencies & AI Supply Chain

    Supply-chain security

    Treat models, adapters, tokenizers, datasets, packages, and build pipelines as security-sensitive artifacts. Apply provenance, admission policy, safe formats, signing, isolation, and least-privilege execution.

    Under construction
  6. Prompt Injection, Jailbreaks & Output Handling

    Application security

    Exploit and mitigate direct and indirect prompt injection, prompt leakage, jailbreaks, excessive agency, and unsafe output consumption. Replace prompt-only defenses with authorization, validation, encoding, and egress controls.

    Under construction
  7. Privacy, Memorization, Extraction & Inference

    Model privacy

    Measure training-data extraction, membership inference, model inversion, and model extraction against course-owned targets. Evaluate query economics, output controls, differential privacy, and utility trade-offs.

    Under construction
  8. Agents, Tools, MCP & Memory

    Agentic security

    Secure planning loops, delegated tools, MCP clients and servers, memory, and agent-to-agent communication. Reproduce tool poisoning and goal hijacking, then implement pinned definitions, scoped authority, approvals, and rollback.

    Under construction
  9. Identity, Authorization, Tenancy & Approvals

    Access control

    Separate user, workload, agent, tool, and data-source identities. Prevent authority amplification and cross-tenant access using on-behalf-of flows, scoped credentials, risk-sensitive approvals, revocation, and kill switches.

    Under construction
  10. Adversarial ML, Robustness & Infrastructure

    Model and platform security

    Evaluate evasion, poisoning, backdoors, transferability, availability attacks, unbounded consumption, and accelerator exposure. Measure attacks and defenses instead of accepting robustness claims at face value.

    Under construction
  11. Threat-Informed AI Security Testing

    Red and purple teaming

    Plan and execute an authorized assessment across model, RAG, application, agent, and infrastructure layers. Combine manual testing with PyRIT, garak, promptfoo, and reproducible evaluation methods.

    Under construction
  12. Telemetry, Monitoring & Detection Engineering

    Defensive operations

    Design an AI flight recorder for prompts, retrieval, models, tools, memory, approvals, identity, and egress. Build detection-as-code and validate it against benign and malicious replay traces.

    Under construction
  13. CTI, Incident Response & AI-Native DFIR

    Security operations

    Investigate AI-system compromise under incomplete and conflicting evidence. Preserve prompts, retrieval, model versions, tool calls, memory, identities, network activity, and provenance while producing decision-ready intelligence.

    Under construction
  14. Governance, Risk, Procurement & Assurance

    Risk and governance

    Apply NIST AI RMF and related standards to inventory, supplier assessment, risk ownership, acceptance criteria, and release decisions. Require technical evidence for every material control claim.

    Under construction
  15. Secure AI Delivery & Purple-Team Capstone

    Integration

    Integrate requirements, CI/CD controls, versioning, release gates, rollback, and incident readiness. Attack, detect, contain, correct, regression-test, and defend the release decision for a complete enterprise agent system.

    Under construction

What learners will produce

Threat intelligence

Collection plans, source matrices, confidence-rated assessments, behavior mappings, warnings, and decision-oriented briefings.

Engineering evidence

Threat models, exploit traces, secure architectures, admission policies, detection packs, and regression suites.

Operational readiness

Incident timelines, evidence registers, containment plans, playbooks, residual-risk decisions, and executive recommendations.

Core foundations

The course uses complementary frameworks for different jobs; no single list is treated as a complete AI security program.

Development status

The current work is focused on lesson plans, isolated lab architecture, reproducible evidence packs, instructor guidance, and assessment rubrics. Enrollment, delivery dates, pricing, and certification details have not been announced.