Offensive AI Exploits and Security (LFWS320)

This one-day course introduces you to attacking and securing LLM-powered applications, covering all 10 attack classes in the OWASP Top 10 for LLM applications.

Suggested prerequisites: Familiarity with web application security (HTTP, REST APIs, input validation, injection attacks), experience with an HTTP interception tool such as Burp Suite or OWASP ZAP, Python proficiency at a read-and-modify level, and basic awareness of LLMs, prompts, RAG and LLM agents with tool calling.

Audience: Penetration testers, red teamers, security engineers and AI/ML engineers, and also AppSec and DevSecOps professionals

LLM applications bring a new class of vulnerabilities that existing playbooks were not designed for. This course gives penetration testers, red teamers, security engineers and AI/ML engineers the offensive skills to find, exploit and remediate them. It is also relevant for AppSec and DevSecOps professionals who are bringing AI into existing pipelines.

You will start with LLM architectures such as RAG, agents and multi-agent systems, and map the attack surface. From there the hands-on labs take you through direct prompt injection, guard bypass, header spoofing, agent tool abuse, indirect injection and SSRF, multi-modal injection, memory poisoning, schema confusion and multi-agent poisoning, ending with a capstone. For each attack you will also look at defenses and recommend LLM-native defensive architectures. All labs are cloud-hosted and ready to go, so you only need a laptop.

The course prepares you to move into AI red-teaming, LLM penetration testing and AI security engineering roles by showing you can assess, exploit and advise on the security of LLM-powered applications. It includes a certificate of completion and a digital badge.

← All Linux Foundation courses