Course Outline
Introduction to AI Threat Modeling
- Understanding the vulnerabilities inherent in AI systems
- Comparing the AI attack surface with that of traditional systems
- Key attack vectors across data, model, output, and interface layers
Adversarial Attacks on AI Models
- Exploring adversarial examples and perturbation techniques
- Distinguishing between white-box and black-box attacks
- Methods such as FGSM, PGD, and DeepFool
- Visualizing and generating adversarial samples
Model Inversion and Privacy Leakage
- Reconstructing training data from model outputs
- Membership inference attacks
- Privacy concerns in classification and generative models
Data Poisoning and Backdoor Injections
- How manipulated data alters model behavior
- Trigger-based backdoors and Trojan horse attacks
- Strategies for detection and data sanitization
Robustness and Defense Techniques
- Adversarial training and data augmentation
- Gradient masking and input preprocessing
- Model smoothing and regularization approaches
Privacy-Preserving AI Defenses
- Fundamentals of differential privacy
- Noise injection and privacy budget management
- Federated learning and secure aggregation
AI Security in Practice
- Threat-informed model evaluation and deployment
- Applying ART (Adversarial Robustness Toolbox) in real-world scenarios
- Industry case studies: analyzing real-world breaches and their mitigations
Conclusion and Future Directions
Requirements
- A solid grasp of machine learning workflows and model training processes
- Proficiency in Python and common ML frameworks like PyTorch or TensorFlow
- Basic knowledge of security or threat modeling concepts is beneficial
Target Audience
- Machine learning engineers
- Cybersecurity analysts
- AI researchers and model validation teams
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us