Library / Artificial Intelligence

OSCP for AI: The GenAI Security Sandbox

On Udemy

About this course

Course Overview

Build a comprehensive understanding of AI security by constructing a Vulnerable LLM Cyber Range. Large Language Models are increasingly integrated into various systems, from customer-facing chatbots to critical infrastructure. This hands-on course transitions from theoretical AI safety to practical security testing.

You will develop a functional GenAI Security Lab using Python, Streamlit, and local LLMs such as Ollama, Llama 3, and Phi-3. By assuming the roles of both the Attacker (Red Team) and the Defender (Blue Team), you will learn how to identify vulnerabilities, execute exploits, and implement code-level fixes.

What You Will Build and Test

The course features a modular cyber range with over 15 live labs covering the OWASP Top 10 for LLMs. Key topics include:

  • Prompt Injection: Learn how to bypass chatbot system instructions and safety constraints.
  • Remote Code Execution (RCE): Explore how LLMs can be manipulated into executing shell commands on a host server.
  • Indirect Injection: Understand how external data sources, such as resumes or emails, can compromise the AI models processing them.
  • RAG Data Poisoning: Study methods to corrupt corporate knowledge bases to influence AI output.
  • Model Denial of Service: Identify ways to trap autonomous agents in loops or force unauthorized resource consumption.
  • Training Data Poisoning: Examine how hidden triggers can be planted within a model's training set.

Target Audience

Penetration Testers: Professionals looking to expand their skill set into Generative AI security assessments.

Developers: Software engineers focused on building secure, production-grade LLM applications.

Security Enthusiasts

Ready to start? Continue on Udemy to enroll.

Start learning on Udemy (opens in a new tab)

Prices, discounts and availability are set by Udemy. We may earn a commission when you purchase through links on this site.