Highlights
- Understand OWASP Top 10 for LLMs
- Execute prompt injection attacks
- Identify indirect injection vectors
- Implement input validation
- Prevent system prompt extraction
- Apply output filtering
- Understand model supply chain risks
- Harden API credential handling
- Conduct a structured security review
- Produce a threat model
Course Details
AI threat landscape overview:
OWASP LLM Top 10 mapped directly to real published incidents and breach case studies
Prompt injection attack lab:
participants attack a live test application using documented techniques in a safe environment
Indirect injection workshop: demonstrating how instructions hidden in uploaded documents and web content can hijack an AI system
Input sanitisation lab: building filters, allowlists, and context boundaries in working code with before and after comparisons
System prompt protection: live extraction attack demonstrations followed by practical defences you can implement immediately
Output filtering build: implementing content classifiers and policy checks on model responses before they reach the user
Supply chain risk session: evaluating risks from third-party models, plugins, and fine-tuned models you did not train yourself
Credential hardening: secrets rotation procedures, least-privilege API key configuration, and common exposure patterns to avoid
Structured security review: running a checklist-based review against a sample AI application and producing a findings list
Threat modelling workshop: building a one-page threat model and a prioritised remediation backlog ready to take into sprint planning
Who should attend
Feedback
4.8 out of 5 average
"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"
Brian Leek, Data Analyst, May 2022