Learn how AI systems are attacked and how they are defended: what is different about software that follows instructions written in its data, how to secure each stage from training data to a running agent, and which defences hold when the model itself has been fooled.
Securing an AI application is ordinary security engineering plus one new fact: a language model cannot reliably tell the instructions it should follow from the text it was merely asked to read. No patch fixes that. Everything distinctive in this course follows from it — especially the working assumption that the model will sometimes be manipulated, and that the system around it must make that survivable.
The course starts at “why is this different from web security?” and ends with a complete security design for a multi-tenant agent platform. It assumes you can program in Go and know what an HTTP API and an access token are. It does not assume a security background.
The stages#
Security work attaches to stages of an application’s life, and the course is organised the same way.
flowchart LR D[":i-list-checks: <b>Design</b><br/><small>threat model</small>"] --> DA[":i-database: <b>Data</b><br/><small>provenance, privacy</small>"] DA --> MO[":huggingface: <b>Model</b><br/><small>supply chain, signing</small>"] MO --> B[":github: <b>Build</b><br/><small>red team, eval gates</small>"] B --> DE[":kubernetes: <b>Deploy</b><br/><small>isolation, secrets</small>"] DE --> R[":i-shield-check: <b>Runtime</b><br/><small>guardrails, policy</small>"] R --> A[":i-bot: <b>Agents</b><br/><small>identity, sandboxes</small>"] A --> O[":i-radar: <b>Operate</b><br/><small>detect, respond</small>"] O -.->|"incidents become tests"| D class D neutral class DA,MO memory class B queue class DE compute class R,A warn class O io
How this course works#
Every lesson follows the same shape:
- The idea in one minute.
- A picture of the attack or the defence, with real tools named. Press Expand to open any diagram full size.
- How it really works — the mechanism, precisely.
- Code — where a mechanism is worth running, a small Go program using only the standard library. Attack demonstrations run against simulated models inside the program; nothing targets a real system.
- Remember this, Try it, Check yourself.
Attacks are explained before defences, because a defence makes sense only once you can see what it stops — and what it does not.
The topics#
| Topic | You will be able to | Level |
|---|---|---|
| The Threat Landscape | Explain what is new, build a threat model for an AI system, and use the OWASP, MITRE and NIST maps | Foundations |
| How Attacks Work | Explain prompt injection, exfiltration, poisoning, supply-chain and resource attacks at the level of mechanism | Basic |
| Securing Each Stage | Apply the right controls at data, model, build, deployment, runtime and operations | Intermediate |
| Securing Agents | Give agents identity and least privilege, design architectures that resist injection, sandbox execution, secure MCP | Advanced |
| Governance and Practice | Map controls to regulation, run a red-team programme, and produce a full security design | Expert |
How it connects to the other courses#
- The systems being secured are designed in AI System Design; its Security by Design topic is the short version of this course.
- Isolation of GPUs and inference servers builds on Inference Engineering.
- Detection builds on Observability Engineering.
What you need#
- Go 1.22 or newer and a terminal. Every program runs offline.
- No GPU, no API key, no lab environment.
A note on scope and ethics#
This course teaches how attacks work so that you can build and test defences for systems you are responsible for. The demonstrations are deliberately self-contained simulations. Test only systems you own or are authorised to test.
A promise about names and versions#
Framework editions, incident references, specification versions and legal dates were checked on 4 October 2026; lessons that depend on them list their sources. Principles — untrusted input, least privilege, isolation, defence in depth — are far older than any model and will outlast the current ones.