Pidoku

AI Security Engineering

Securing AI applications at every stage — data, models and supply chain, build, deployment, runtime and agents — with the attacks explained first and the defences that actually hold.

Start reading
  • 5 levels
  • 5 topics
  • 22 lessons
  • ~18h

Contents

  1. Foundations

    Build the mental model.

    3 lessons · ~2h 5m

    1. The Threat LandscapeBefore controls, a map. This topic explains what makes AI systems a distinct security problem, gives you a repeatable way to threat-model one, and introduces the public frameworks you will … 3 lessons · ~2h 5m
      1. ·Overview
      2. 01Why AI Security Is DifferentFoundations35 min
      3. 02Threat Modeling an AI SystemFoundations45 min
      4. 03Frameworks and MapsFoundations45 min
  2. Basic

    Understand the core mechanisms.

    4 lessons · ~3h 5m

    1. How Attacks WorkYou cannot defend against something you cannot picture. This topic explains the four families of attack on AI systems at the level of mechanism — what the attacker controls, what they write, … 4 lessons · ~3h 5m
      1. ·Overview
      2. 01Prompt InjectionBasic50 min
      3. 02Data Exfiltration and LeakageBasic45 min
      4. 03Poisoning and Supply ChainBasic50 min
      5. 04Abuse and Resource AttacksBasic40 min
  3. Intermediate

    Learn the optimization techniques.

    7 lessons · ~5h 25m

    1. Securing Each StageAn AI application passes through stages — design, data, model, build, deployment, runtime, operation — and each stage has controls that are cheap there and expensive anywhere else. This … 7 lessons · ~5h 25m
      1. ·Overview
      2. 01The Lifecycle MapIntermediate40 min
      3. 02Data and TrainingIntermediate45 min
      4. 03Models and Supply ChainIntermediate50 min
      5. 04Build and TestIntermediate45 min
      6. 05Deployment and InfrastructureIntermediate50 min
      7. 06Runtime GuardrailsIntermediate50 min
      8. 07Monitoring and ResponseIntermediate45 min
  4. Advanced

    Study systems at production scale.

    5 lessons · ~4h 30m

    1. Securing AgentsAn agent turns a model's mistakes into actions. Everything in the previous topics applies, and five things are added: threats specific to systems that plan and remember, an identity model … 5 lessons · ~4h 30m
      1. ·Overview
      2. 01Agent ThreatsAdvanced50 min
      3. 02Identity and AuthorizationAdvanced55 min
      4. 03Architectural DefensesAdvanced1h 5m
      5. 04Sandboxing and EgressAdvanced45 min
      6. 05MCP and Tool SecurityAdvanced55 min
  5. Expert

    Design platforms and read the frontier.

    3 lessons · ~2h 55m

    1. Governance and PracticeControls only work inside an organisation that knows what it is running, tests it on purpose, and can show its work. This topic covers the obligations, the red-team programme, and a complete … 3 lessons · ~2h 55m
      1. ·Overview
      2. 01Compliance and RegulationExpert45 min
      3. 02The Red-Team ProgrammeExpert50 min
      4. 03Securing an Agent PlatformExpert1h 20m

Reference

About

Learn how AI systems are attacked and how they are defended: what is different about software that follows instructions written in its data, how to secure each stage from training data to a running agent, and which defences hold when the model itself has been fooled.

Securing an AI application is ordinary security engineering plus one new fact: a language model cannot reliably tell the instructions it should follow from the text it was merely asked to read. No patch fixes that. Everything distinctive in this course follows from it — especially the working assumption that the model will sometimes be manipulated, and that the system around it must make that survivable.

The course starts at “why is this different from web security?” and ends with a complete security design for a multi-tenant agent platform. It assumes you can program in Go and know what an HTTP API and an access token are. It does not assume a security background.

The stages#

Security work attaches to stages of an application’s life, and the course is organised the same way.

flowchart LR
  D[":i-list-checks: <b>Design</b><br/><small>threat model</small>"] --> DA[":i-database: <b>Data</b><br/><small>provenance, privacy</small>"]
  DA --> MO[":huggingface: <b>Model</b><br/><small>supply chain, signing</small>"]
  MO --> B[":github: <b>Build</b><br/><small>red team, eval gates</small>"]
  B --> DE[":kubernetes: <b>Deploy</b><br/><small>isolation, secrets</small>"]
  DE --> R[":i-shield-check: <b>Runtime</b><br/><small>guardrails, policy</small>"]
  R --> A[":i-bot: <b>Agents</b><br/><small>identity, sandboxes</small>"]
  A --> O[":i-radar: <b>Operate</b><br/><small>detect, respond</small>"]
  O -.->|"incidents become tests"| D
  class D neutral
  class DA,MO memory
  class B queue
  class DE compute
  class R,A warn
  class O io

How this course works#

Every lesson follows the same shape:

  1. The idea in one minute.
  2. A picture of the attack or the defence, with real tools named. Press Expand to open any diagram full size.
  3. How it really works — the mechanism, precisely.
  4. Code — where a mechanism is worth running, a small Go program using only the standard library. Attack demonstrations run against simulated models inside the program; nothing targets a real system.
  5. Remember this, Try it, Check yourself.

Attacks are explained before defences, because a defence makes sense only once you can see what it stops — and what it does not.

The topics#

TopicYou will be able toLevel
The Threat LandscapeExplain what is new, build a threat model for an AI system, and use the OWASP, MITRE and NIST mapsFoundations
How Attacks WorkExplain prompt injection, exfiltration, poisoning, supply-chain and resource attacks at the level of mechanismBasic
Securing Each StageApply the right controls at data, model, build, deployment, runtime and operationsIntermediate
Securing AgentsGive agents identity and least privilege, design architectures that resist injection, sandbox execution, secure MCPAdvanced
Governance and PracticeMap controls to regulation, run a red-team programme, and produce a full security designExpert

How it connects to the other courses#

What you need#

  • Go 1.22 or newer and a terminal. Every program runs offline.
  • No GPU, no API key, no lab environment.

A note on scope and ethics#

This course teaches how attacks work so that you can build and test defences for systems you are responsible for. The demonstrations are deliberately self-contained simulations. Test only systems you own or are authorised to test.

A promise about names and versions#

Framework editions, incident references, specification versions and legal dates were checked on 4 October 2026; lessons that depend on them list their sources. Principles — untrusted input, least privilege, isolation, defence in depth — are far older than any model and will outlast the current ones.

↑↓ navigate↵ openesc close

drag to pan · scroll to zoom