AI/ML Model Security — OWASP LLM Top 10 and Adversarial ML
An advanced training on AI and ML system security covering the full OWASP LLM Top 10, adversarial ML techniques, and LLM red teaming. The program addresses model attacks (prompt injection, data poisoning, model extraction), MLOps pipeline security, training data protection with differential privacy and federated learning, and building secure AI applications with guardrails, content filtering, and monitoring. Participants conduct practical attacks and implement defenses in a lab environment.
Why choose this training?
The rapid adoption of AI and LLM models in organizations creates a new attack surface that traditional cybersecurity approaches do not cover. Prompt injection, data poisoning, model extraction, and jailbreaking are real threats that require specialized knowledge at the intersection of IT security and machine learning. The OWASP LLM Top 10 formalizes these threats, but knowing them is not enough — practical skills in both conducting attacks and implementing defenses are essential.
This two-day training combines the offensive perspective (adversarial ML, LLM red teaming) with the defensive one (guardrails, monitoring, MLOps security). Participants work in a prepared lab environment where they independently conduct attacks on AI models and applications, then implement countermeasures. The program addresses the full model lifecycle — from training data security, through MLOps pipelines, to monitoring production AI applications.
What makes our approach unique?
EITT combines years of experience in cybersecurity training with rapidly evolving knowledge of AI system threats. Our instructors are practitioners who combine penetration testing experience with ML and LLM competencies — which is critical in a field that demands expertise in both domains simultaneously. With a team of over 500 experts and experience from more than 2,500 trainings, we build programs that translate into real-world AI system defense capabilities.
The program is deliberately condensed into two intensive days to maximize hands-on exercise time. Each module includes attack and defense scenarios conducted in an isolated lab. The training is available online and onsite, and participants receive access to materials and tools for continued independent practice of AI red teaming techniques.
Benefits
- Identify and assess OWASP LLM Top 10 threats in the context of real deployments
- Conduct adversarial ML attacks against classification and generative models in lab exercises
- Perform LLM red teaming using jailbreaking and prompt leaking techniques
- Secure MLOps pipelines — model registry, supply chain, and training environments
- Implement guardrails and content filtering to protect AI applications from misuse
- Design AI security monitoring with anomaly detection and alerting
- Apply training data privacy techniques compliant with GDPR requirements
Who is this training for?
Prerequisites
- Basic understanding of AI/ML concepts (models, training, inference)
- Cybersecurity fundamentals (attacks, defense, threat modeling)
- Basic Python proficiency (required for lab exercises)
- Familiarity with LLM APIs (OpenAI, Anthropic, or similar) is helpful
Training program
Module 1: OWASP LLM Top 10 — Prompt Injection, Data Poisoning, Model DoS, and Supply Chain
- OWASP LLM Top 10 overview — threat classification for LLM applications
- Prompt injection — direct and indirect techniques, attack and defense
- Data poisoning — manipulating training and fine-tuning data
- Model Denial of Service — resource exhaustion and query-based DoS
- Supply chain vulnerabilities — risks in dependencies and pre-trained models
- Insecure output handling and excessive agency — limiting LLM permissions
Module 2: Adversarial ML — Evasion, Extraction, and Inversion Attacks
- Adversarial ML attack taxonomy — evasion, poisoning, extraction, inference
- Evasion attacks — input perturbations that fool classifiers
- Model extraction — stealing models through systematic API querying
- Model inversion — reconstructing training data from model responses
- Membership inference — determining if specific data was in the training set
- Adversarial ML tooling — ART, Foolbox, TextAttack
Module 3: LLM Red Teaming — Jailbreaking and Prompt Leaking
- LLM red teaming methodology and structured approaches
- Jailbreaking — techniques for bypassing LLM safety mechanisms (DAN, roleplay, encoding)
- Prompt leaking — extracting system prompts and hidden instructions
- Automated red teaming — tools and frameworks (Garak, PyRIT)
- AI vulnerability reporting — format, severity, and recommendations
- Building an AI red team program within an organization
Module 4: ML Pipeline Security — MLOps Security and Model Registry
- Threats in MLOps pipelines — from data to deployment
- Model registry security — signing, versioning, and access control
- Supply chain security — verifying models from Hugging Face and Model Zoo
- Training environment security — isolation, monitoring, and auditing
- CI/CD for ML — vulnerability scanning and security testing in pipelines
- Secrets and credentials management in ML workflows
Module 5: Training Data Protection and Privacy — Differential Privacy and Federated Learning
- Privacy threats to training data — leakage and reconstruction
- Differential privacy — principles and implementation in model training
- Federated learning — training without centralizing data
- Training data anonymization and pseudonymization
- GDPR compliance in the context of AI systems
- Training data auditing — detecting PII and sensitive information
Module 6: Building Secure AI Applications — Guardrails, Content Filtering, and Monitoring
- Secure AI application architecture — defense in depth
- Guardrails — input and output validation, topic restrictions
- Content filtering — detecting harmful, toxic, and sensitive content
- AI security monitoring — anomaly detection and alerting
- Incident response for AI systems — procedures and playbooks
- Compliance and governance — AI security policies in organizations
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
Does the training include practical attacks on AI models, or is it theory only?
The training has a strong hands-on component. Participants conduct adversarial ML attacks against classification models, perform LLM red teaming with jailbreaking and prompt leaking techniques, test prompt injection on prepared AI applications, and implement defenses — guardrails, content filtering, and monitoring. All exercises are conducted in an isolated lab environment.
Is this training designed for pentesters or ML engineers?
The training is designed for both audiences and deliberately bridges the offensive and defensive perspectives. Pentesters learn the specifics of AI system attacks (adversarial ML, jailbreaking, prompt injection), while ML engineers learn to secure pipelines and applications against these attacks. The value lies in understanding both sides — attacker and defender.
Is the OWASP LLM Top 10 covered in its latest version?
Yes — the training curriculum is updated to reflect the latest published version of the OWASP LLM Top 10. We discuss each of the ten threat categories with specific attack examples, real-world incidents, and defense recommendations. The training extends beyond the OWASP document itself by adding adversarial ML context and practical red teaming exercises.
How does the training address GDPR compliance for AI systems?
The training data privacy module directly addresses GDPR requirements — we cover differential privacy as a mechanism for protecting data during training, federated learning as an alternative to data centralization, training dataset anonymization techniques, and PII detection audits. This is not a legal training, but participants learn the technical mechanisms that support regulatory compliance.
Why choose EITT for AI security training?
EITT has a team of over 500 IT experts and experience from more than 2,500 delivered trainings, including cybersecurity and AI. Our AI security training is led by specialists who combine penetration testing experience with ML systems knowledge — which is essential in this interdisciplinary field. The curriculum is regularly updated with the latest attack techniques and defenses, including current OWASP LLM Top 10 versions.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.