Skip to content

Training — Bundle 04

AI Security & LLM Red Teaming

Every company is shipping AI features. Almost nobody knows how to attack them. This program teaches you to red-team language models, autonomous agents, and the pipelines behind them — by actually doing it, against systems built to be broken.

Level
Intermediate — some security or engineering background helps
Format
Live sessions with hands-on labs
Delivery
Online or on-site

Why this program

AI security is a skill gap, not a tooling gap.

Organizations are deploying models that read untrusted input and call real tools, then asking their existing security teams to sign off on them. The traditional application-security playbook doesn't cover prompt injection, agent tool abuse, or training-data poisoning — and the people who can test for those are scarce. This program closes that gap the only way that works: by putting you in front of vulnerable AI systems and teaching you to break them.

Curriculum

Seven modules, from first principles to full agent compromise.

The curriculum follows the same order a real assessment does — understand the system, attack the interface, then attack everything behind it.

  1. 01

    AI Attack Surface Fundamentals

    How LLM applications are actually built — system prompts, context windows, retrieval, tool calling, and agent loops — and where each layer introduces trust boundaries an attacker can cross.

  2. 02

    Prompt Injection & Jailbreaking

    Direct injection, system-prompt extraction, role manipulation, encoding and obfuscation, and multi-turn attacks that defeat guardrails a single-shot payload can't.

  3. 03

    Indirect Injection & Untrusted Content

    Planting instructions in documents, web pages, emails, and tickets that a model will later read — the highest-impact and least-tested AI attack path in production today.

  4. 04

    Agent & Tool Abuse

    Attacking autonomous agents: steering tool invocation, forging arguments, chaining calls, escalating authority, and turning a helpful assistant into an attacker's execution environment.

  5. 05

    RAG & Data Exfiltration

    Breaking retrieval boundaries — cross-tenant leakage, embedding and vector-store attacks, context stuffing, and pulling out documents the user was never authorized to see.

  6. 06

    Model & Pipeline Attacks

    Data poisoning and backdoors, model supply-chain and unsafe deserialization, model extraction, membership inference, and attacks against MLOps infrastructure.

  7. 07

    Defence, Architecture & Reporting

    Designing systems that survive injection: privilege separation, sandboxed tool execution, output handling, and monitoring — plus how to write an AI red-team report people can act on.

What you'll be able to do afterwards

  • Threat model an LLM application end to end, including its tools and data sources
  • Build and deliver prompt-injection chains that survive guardrails and filters
  • Test autonomous agents for tool abuse and authority escalation
  • Identify cross-tenant and boundary failures in RAG systems
  • Assess an ML pipeline for poisoning and supply-chain exposure
  • Map findings to the OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF
  • Write an AI security report with reproducible prompt chains and real fixes

Frameworks & tooling covered

  • OWASP LLM Top 10
  • MITRE ATLAS
  • NIST AI RMF
  • Burp Suite
  • Garak
  • PyRIT
  • Promptfoo
  • Python
  • LangChain / Agent frameworks
  • Vector databases

Who this is for

  • Penetration testers and application security engineers adding AI to their scope
  • AI and ML engineers who need to secure what they're shipping
  • Red teamers preparing for AI-focused engagements
  • Bug bounty hunters targeting a fast-growing new class of vulnerability
  • Security leads responsible for signing off on AI deployments
Certification

Optional practical exam — the UCAI credential

Candidates who want to prove the skill rather than just claim it can sit an optional hands-on exam. There is no multiple choice: you are given a live AI application and asked to compromise it and document what you did.

Uncrypt Certified AI Security Professional (UCAI)

  • A live, purpose-built AI application with tools and retrieval enabled
  • Fixed time window, remotely proctored
  • You must achieve defined objectives — real exploitation, not a quiz
  • A professional report is submitted and graded alongside your results
  • Both the exploitation and the report must pass to earn the credential

The UCAI credential is issued by Uncrypt and reflects demonstrated practical ability in our exam environment. It is an independent credential and is not affiliated with or accredited by any external certification body.

Questions

Before you enrol.

Anything else, email connect@uncrypt.net.

  • No. You need to be comfortable with how web applications and APIs work. We teach the model internals you need as we go — this is a security course, not a data science course.

Ready to learn how AI systems actually break?

Tell us about your team's background and we'll recommend the right starting point.

Within one business day · NDA on request