Evidence based
Learn from real incidents, provider threat reports, vulnerability disclosures, malicious artifacts, and reproducible security research.
AI security practitioner course
From models to agentic systems: an evidence-grounded course for assessing, securing, monitoring, and investigating the complete AI technology stack.
The model is only one component. The course examines data, retrieval, prompts, tools, agents, identities, application code, infrastructure, operators, and downstream actions as one security-sensitive system.
Learn from real incidents, provider threat reports, vulnerability disclosures, malicious artifacts, and reproducible security research.
Reproduce trust-boundary failures, preserve evidence, implement layered controls, and verify fixes with regression tests.
Connect threat intelligence to architecture, testing, telemetry, detection engineering, incident response, and governance.
2026 course-market research
The syllabus was checked against publicly documented professional training, certification paths, hands-on academies, and cloud-vendor courses. The market is strongest in LLM application testing and offensive AI. This course retains that depth and connects it to architecture, identity, supply chain, production detection, incident response, forensics, and evidence-backed assurance.
SANS, Hack The Box, PortSwigger, OffSec, EC-Council, INE, Practical DevSecOps, Microsoft, AWS, and CSA/Northeastern informed the coverage analysis.
Every major attack exercise continues through observability, layered mitigation, detection, incident handling, and regression testing.
Real incidents, provider observations, disclosures, and reproducible research determine priorities. CTI supports the AI-security engineering—not the reverse.
Course method
The course uses one repeatable method so learners can move from a report or disclosure to a defensible control and a testable security decision.
Consumer and intelligence requirement
Name who needs to decide, which system is in scope, what uncertainty matters, and what evidence threshold supports action.
Technical and adversary procedure
Trace prerequisites, identities, inputs, model or application behavior, state changes, affected assets, and outcomes using precise technical verbs.
Prevention through investigation
Assign controls outside the model, reduce authority and blast radius, define observable signals, and preserve the evidence required for causal reconstruction.
Authorized testing and calibrated judgment
Use isolated course-owned targets, repeatable artifacts, regression tests, source-backed claims, explicit limitations, and confidence that matches the evidence.
The syllabus
Each module has a dedicated page containing its lessons, practical exercises, workbook, assessment, and instructor guidance. Modules 00 and 01 are available now; the remaining modules are being built.
Technical foundation
Master the complete vocabulary and technical mental model used throughout the course: AI and ML problem types, training and inference, neural networks, Transformers, LLM lifecycle, embeddings, RAG, agents, MCP, evaluation, model serving, and MLOps.
Intelligence and architecture
Build the complete AI attack-surface model from real incidents, provider observations, production vulnerabilities, malicious artifacts, and reproducible research. Learn to distinguish observed activity from demonstrated capability and turn evidence into controls and telemetry.
Open moduleFoundation
Model hosted and self-managed AI applications as assets, identities, data flows, policy decisions, and trust boundaries. Find confused-deputy paths and security decisions incorrectly delegated to a probabilistic model.
Under constructionData security
Secure document ingestion, parsing, chunking, embeddings, vector stores, retrieval authorization, source provenance, and deletion. Build and test a tenant-safe RAG pipeline against poisoning and indirect injection.
Under constructionSupply-chain security
Treat models, adapters, tokenizers, datasets, packages, and build pipelines as security-sensitive artifacts. Apply provenance, admission policy, safe formats, signing, isolation, and least-privilege execution.
Under constructionApplication security
Exploit and mitigate direct and indirect prompt injection, prompt leakage, jailbreaks, excessive agency, and unsafe output consumption. Replace prompt-only defenses with authorization, validation, encoding, and egress controls.
Under constructionModel privacy
Measure training-data extraction, membership inference, model inversion, and model extraction against course-owned targets. Evaluate query economics, output controls, differential privacy, and utility trade-offs.
Under constructionAgentic security
Secure planning loops, delegated tools, MCP clients and servers, memory, and agent-to-agent communication. Reproduce tool poisoning and goal hijacking, then implement pinned definitions, scoped authority, approvals, and rollback.
Under constructionAccess control
Separate user, workload, agent, tool, and data-source identities. Prevent authority amplification and cross-tenant access using on-behalf-of flows, scoped credentials, risk-sensitive approvals, revocation, and kill switches.
Under constructionModel and platform security
Evaluate evasion, poisoning, backdoors, transferability, availability attacks, unbounded consumption, and accelerator exposure. Measure attacks and defenses instead of accepting robustness claims at face value.
Under constructionRed and purple teaming
Plan and execute an authorized assessment across model, RAG, application, agent, and infrastructure layers. Combine manual testing with PyRIT, garak, promptfoo, and reproducible evaluation methods.
Under constructionDefensive operations
Design an AI flight recorder for prompts, retrieval, models, tools, memory, approvals, identity, and egress. Build detection-as-code and validate it against benign and malicious replay traces.
Under constructionSecurity operations
Investigate AI-system compromise under incomplete and conflicting evidence. Preserve prompts, retrieval, model versions, tool calls, memory, identities, network activity, and provenance while producing decision-ready intelligence.
Under constructionRisk and governance
Apply NIST AI RMF and related standards to inventory, supplier assessment, risk ownership, acceptance criteria, and release decisions. Require technical evidence for every material control claim.
Under constructionIntegration
Integrate requirements, CI/CD controls, versioning, release gates, rollback, and incident readiness. Attack, detect, contain, correct, regression-test, and defend the release decision for a complete enterprise agent system.
Under constructionCollection plans, source matrices, confidence-rated assessments, behavior mappings, warnings, and decision-oriented briefings.
Threat models, exploit traces, secure architectures, admission policies, detection packs, and regression suites.
Incident timelines, evidence registers, containment plans, playbooks, residual-risk decisions, and executive recommendations.
The course uses complementary frameworks for different jobs; no single list is treated as a complete AI security program.
The current work is focused on lesson plans, isolated lab architecture, reproducible evidence packs, instructor guidance, and assessment rubrics. Enrollment, delivery dates, pricing, and certification details have not been announced.