
Kevin Carter
Cybersecurity Architect
Take an AI system through a complete security review. Threat model the architecture, run adversarial testing to identify weaknesses, implement controls, and produce risk and compliance documentation pre-launch. Work on realistic systems, including an AWS Bedrock RAG agent, a containerized image classifier, a RAG research agent, and a clinical risk model. Start in the defender's seat, building and securing a cloud AI system before seeing attacks. The next two courses cover attacks on classical machine learning and generative and agentic systems, with each attack followed by the control that stops it. The final course covers governance, where you produce risk registers, ATLAS threat models, EU AI Act classifications, fairness audits, model cards, and deletion pipelines.

Subscription · Monthly
83 skills
15 prerequisites
Prior to enrolling, you should have the following knowledge:
You will also need to be able to communicate fluently and professionally in written and spoken English.
Secure the AI systems your organization is putting into production. You will threat model machine learning architectures with STRIDE-ML, inventory model and dataset dependencies in an ML-BOM, and harden inference endpoints against extraction and abuse. You will filter prompt injection with Bedrock Guardrails, scope IAM roles so a compromised agent cannot reach what it never needed, trace poisoned documents back through a knowledge base, and rate limit an API so runaway cost becomes a manageable event. The work is hands-on in AWS with Python, and it builds toward a capstone where you deploy, harden, and validate a Bedrock RAG agent. Bring working knowledge of Python, cloud fundamentals, and basic security concepts.
15 hoursSet up your tooling and AWS access, and preview the AI security skills and the Bedrock capstone project ahead of you.
Learn how classic threat modeling adapts to machine learning, and use STRIDE-ML to name specific threats against each part of an AI system.
Build a structured threat model for a Bedrock RAG architecture, ranking threats by likelihood and impact to pick the control that ships first.
Track pre-trained models and datasets as supply chain dependencies, and see what an ML-BOM records so you can scope a vulnerability fast.
Create an ML-BOM for a RAG system, documenting both the embedding and generation models plus the provenance gaps a managed API leaves behind.
Examine why an inference endpoint is a security boundary of its own, and the layered controls that protect a model from theft and abuse.
Audit a Bedrock client configuration for hardcoded credentials, missing input validation, and absent logging, then scope its IAM policy correctly.
Discover why AI systems fail behaviorally while infrastructure stays healthy, and which signals reveal drift, hallucination, and active attacks.
Configure model invocation logging, then write a monitoring plan and an incident response playbook for an AI-specific event.
Study how prompt injection works, including payloads hidden in retrieved documents, and where denylists and allowlists each fall short.
Design and test Bedrock Guardrails that block injection attempts on the way in and catch sensitive data on the way out.
Classify documents by sensitivity and configure PII detection so a knowledge base carries only what the assistant actually needs.
Write least-privilege policies and an organization-level SCP, then interpret IAM Access Analyzer findings for Bedrock resources.
Assess agent tools by the damage they can do, and see why a human approval step belongs in system architecture rather than in a prompt.
Right-size the IAM roles behind a RAG agent, replacing wildcards with scoped ARNs and measuring the blast radius you remove.
Trace what a complete provenance record contains, and how poisoned documents reach a knowledge base and stay hidden inside it.
Investigate a poisoned knowledge base, walking a provenance trail backward from a bad response to the upload event that caused it.
Compare fixed and sliding window rate limiting, and see why unbounded cost threatens an inference API as much as downtime does.
Implement a sliding window rate limiter, analyze usage logs for abuse patterns, and set a limit you can defend from expected traffic.
Read an IAM policy for a cloud AI service and identify the wildcard patterns that hand an attacker administrative control.
Deploy, harden, and validate Northstar Assist, an Amazon Bedrock AgentCore RAG agent, applying threat modeling, an ML-BOM, guardrails, and logging to a system that is ready to launch.
This course equips you with essential skills to identify and exploit vulnerabilities in AI systems. You will explore the fundamentals of AI red teaming, including theoretical and practical applications of evasion attacks, data poisoning, prompt injection, and vector database attacks. The course also covers advanced topics such as model inversion and quantitative robustness testing, ensuring a comprehensive understanding of AI security threats. You will gain hands-on experience through real-time applications and a capstone project focusing on AI red-teaming strategies to enhance security measures and safeguard against adversarial tactics.
14 hoursGet oriented: what offensive AI security covers, the seven attack families you will run yourself, and the dual-system red team engagement you deliver as the capstone.
Learn why AI red teaming targets model behavior rather than code, walk the three-stage lifecycle, and leave able to scope an engagement and write a charter developers can act on.
Use an LLM to surface attack vectors from real system documentation, then turn the ones evidence supports into a red team charter with scope, rules of engagement, and success criteria.
See how attackers fool an image classifier with changes too small to notice, with and without model access, and why a high score on clean test data proves nothing about robustness.
Build black-box and white-box attacks against a real classifier with ART, measure both with adversarial accuracy and perturbation size, and turn those numbers into a risk assessment.
Learn how flipping labels or planting a trigger corrupts a model at training time, and why a backdoored model passes every accuracy check you would normally run before shipping.
Train a clean baseline, poison it with label flips and a backdoor trigger, measure what each attack costs the model, and find which defender-side check actually catches which attack.
Learn why one sentence of user text can override an application's rules: how a model reads system versus user prompts, and the three techniques attackers reach for once filters go up.
Build a prompt injection payload suite, run it across models and system prompt configurations, score each compromise, and test whether a prompt-level defense moves the number at all.
Follow how RAG turns documents into embeddings and ranks them by meaning, then how an attacker hijacks that ranking to control what the model tells every user who asks a matching question.
Stand up a RAG pipeline with live embeddings, plant poisoned documents tuned to real questions, measure the ranking shift they cause, and test whether provenance filtering stops them.
Learn how a model's own confidence scores let an attacker rebuild the data it trained on, why overfitting makes it worse, and how much detail an inference API should ever return.
Reconstruct a face from a classifier's confidence outputs alone, then switch sides and measure how far leakage drops across full probabilities, rounded scores, and a bare label.
Treat robustness as a number you can benchmark the way you benchmark accuracy: the metrics that measure it, the frameworks that automate it, and how to gate a release on it.
Build an automated attack suite that scores a model under clean, environmental, and adversarial conditions, then compare two variants and judge which one clears a release gate.
Map the stack you inherit — model weights, frameworks, libraries, base images, cloud — and see how a flaw four layers deep in a package you never named runs with your credentials.
Scan AI container images with Trivy, parse the report and SBOM into structured findings, and build a priority score ranked by real exposure, where a MEDIUM can rightly outrank a HIGH.
Run a full engagement against two production AI systems: five attacks spanning evasion, poisoning, injection, data exfiltration, and supply chain, delivered as a CISO-ready report.
Attack generative and agentic AI systems the way an adversary would, then harden the same systems against the attacks you just ran. You will jailbreak a commercial assistant, plant indirect injections in content a pipeline ingests, hijack an agent through its own data, and hide instructions inside images, then build the hardened system prompts, guardrails, RAG controls, agent boundaries, structured logging, and human-in-the-loop gates that stop them. The course closes with a capstone that red-teams and hardens a RAG-enabled research agent against the OWASP LLM Top 10.
23 hoursIn this lesson, you'll learn what this course covers, what you need to know going in, and how to get the browser-based labs running.
In this lesson, you'll name the techniques behind a prompt attack and learn how to judge a test result when an assistant only partly gives way.
In this lesson, you'll write your own injection prompts against a deliberately vulnerable banking endpoint and learn how to judge whether each attempt succeeded.
In this lesson, you'll map an application's features onto the OWASP Top 10 for LLMs and learn how to rank findings by what they would cost.
In this lesson, you'll audit a vulnerable banking endpoint against five OWASP categories and learn how to write findings with evidence, a severity, and a fix.
In this lesson, you'll find where hidden instructions enter the content a model reads and learn how to tell indirect injection from a direct attack.
In this lesson, you'll run an indirect prompt injection against an internal assistant and learn how to block a poisoned document before it reaches the model.
In this lesson, you'll name the three patterns that harden a system prompt and learn how to test guardrails against attacks and ordinary requests together.
In this lesson, you'll write three attacks against an internal assistant, harden its system prompt, and learn how to find where prompt-only defenses give way.
In this lesson, you'll trace how RAG moves the attack surface to the document store and learn how to order the controls in the retrieval pipeline.
In this lesson, you'll screen documents retrieved from a knowledge base and learn how to quarantine a poisoned entry before it reaches the model.
In this lesson, you'll split a multi-agent pipeline's duties across three roles and learn how to enforce each role with a card your code checks.
In this lesson, you'll define an agent's role in code and learn how to reject requests that fall outside it.
In this lesson, you'll name the fields that let you reconstruct an agent incident and learn how to work through containment, investigation, and remediation in order.
In this lesson, you'll add structured logging to an assistant and learn how to record every interaction, including blocked attacks, as a single JSON line.
In this lesson, you'll rate an agent's actions by risk and learn how to decide which of them a gate sends to a human reviewer.
In this lesson, you'll build a risk gate for an assistant and learn how to route high-risk requests to a human reviewer.
In this lesson, you'll find the hijacked step inside an agent's plan and learn how to check a plan for sub-tasks the goal never authorized.
In this lesson, you'll hijack an agent's workflow with a hidden instruction and learn how to limit it to a list of approved actions.
In this lesson, you'll explain how an instruction hidden in an image reaches a model and learn how to show a person what the machine read.
In this lesson, you'll strip injected instructions out of text extracted from an uploaded file and learn why extraction is the place to clean it.
In this lesson, you'll write instruction guardrails as labeled rules and learn how to test them with a matrix that shows which rule each case exercises.
In this lesson, you'll write a third named rule for an internal assistant's system prompt and learn how to test that the rule changed its behavior.
In this lesson, you'll assemble a prompt that uses XML-style tags to separate your rules from untrusted content, and learn how an attacker escapes that container.
In this lesson, you'll rebuild Aria's flat prompt as separate system and user messages, and learn how to test that boundary against an injection attempt.
Test a RAG research agent for security weaknesses, then harden it by identifying attacks, analyzing risks, and applying defenses to improve safety.
Explore the intricacies of AI security through a comprehensive examination of strategies, risk management frameworks, and governance structures. This course equips participants with the tools to implement Explainable AI for security auditing, develop effective AI Acceptable Use Policies, and establish an AI Incident Response Playbook. Engage in practical lessons on NIST AI RMF and MITRE ATLAS for threat modeling and dive into regulatory compliance under the EU AI Act. Participants will also learn to assess third-party AI vendors, manage data privacy, and create metrics dashboards, culminating in a project focused on AI governance for a real-world launch scenario.
19 hoursPreview the shift from building AI systems to governing them, confirm the Python and spreadsheet prerequisites, and tour the browser-based workspaces where every exercise runs.
Learn how explainable AI (XAI) and SHAP enable security auditors to detect bias, assess model risk, and create defensible audit findings for black-box models.
Audit AI for security using SHAP: investigate model decisions, detect proxy biases, perform counterfactuals, and draft clear audit memos for stakeholders.
Learn to implement the NIST AI Risk Management Framework's Govern, Map, Measure, Manage loop to identify, track, and mitigate AI-specific risks in dynamic environments.
Apply the NIST AI Risk Management Framework to assess, score, and visualize AI risks, build risk registers, and create executive reports for responsible AI deployment.
Learn how to use MITRE ATLAS to identify adversary tactics against AI systems, assess techniques like data poisoning and prompt injection, and anticipate threats that traditional security tools miss.
Build an AI threat model with MITRE ATLAS: map attack surfaces, score technique likelihood and impact, and prioritize mitigations for a production ML pipeline.
Learn how the EU AI Act's risk-based tiers classify AI systems, and identify the data governance, transparency, human oversight, and robustness duties that attach to high-risk deployments.
Apply the EU AI Act to classify AI systems by risk tier, build a compliance matrix, map obligations to controls, and produce an auditable compliance plan.
Learn how an AI Acceptable Use Policy fits the wider policy stack, and identify the approved-tool lists, data classification rules, and prohibitions that make a policy enforceable.
Draft an enforceable AI Acceptable Use Policy: define prohibited uses, map policy clauses to technical controls, and design an exception procedure with clear approval authority.
Understand unique AI incident types, detection strategies, response frameworks, severity levels, blameless learning, and emerging regulatory requirements for effective AI incident management.
Build an AI incident response playbook: classify incident severity, implement automated detection against metric baselines, and define escalation paths for AI-specific failure modes.
Learn what separates a genuine key risk indicator from a vanity metric, and how to select, band, and threshold AI security KRIs for executive dashboards.
Build an AI security KRI dashboard in code: compute refusal-rate and fairness indicators, apply green-amber-red bands, and surface portfolio-level risk for governance review.
Learn to identify, categorize, and mitigate the unique risks of third-party AI vendors, including data, bias, drift, lock-in, and security with robust governance and contracts.
Assess third-party AI vendors: score risk across weighted criteria, evaluate SLA compliance, tier vendors by exposure, and produce evidence-backed procurement recommendations.
Learn how a model card documents security posture, what belongs in its Security Considerations section, and how it anchors a transparency stack that regulators can audit.
Author a security-focused model card: document adversarial vulnerabilities and subgroup performance, then crosswalk each section to EU AI Act Article 11 technical documentation duties.
Learn to audit AI for disparate outcomes using core fairness metrics, understand why they cannot all be satisfied at once, and govern fairness across the model lifecycle.
Run a fairness audit end to end: measure subgroup disparities, test threshold adjustments against a policy card, and defend a launch, hold, or remediate decision.
Explore AI's data retention paradox, deletion challenges post-training, regulatory conflicts, key data types, and privacy-preserving techniques for responsible AI governance.
Build an AI data retention and deletion pipeline: apply retention schedules, select deletion methods under legal holds, and trace deletion impact through model lineage.
Learn what distinguishes a governance operating model from a framework: decision rights, an AI Review Board charter, RACI accountability, and the failure modes that break most designs.
Design an AI governance operating model: draft a review board charter, assign RACI accountability, set reporting cadences, and stress-test the design against common failure modes.
Run a pre-launch GRC review of a clinical AI model: classify it under the EU AI Act, audit fairness and explainability, and defend a Go or No Go launch recommendation.
3 instructors
Unlike typical professors, our instructors come from Fortune 500 and Global 2000 companies and have demonstrated leadership and expertise in their professions:

Kevin Carter
Cybersecurity Architect

Josh Kalin
Director of Artificial Intelligence at Integration Innovation Inc (i3)

Sohbet Dovranov
Senior Data Scientist

Kevin Carter
Cybersecurity Architect

Josh Kalin
Director of Artificial Intelligence at Integration Innovation Inc (i3)

Sohbet Dovranov
Senior Data Scientist
Attack and defend LLM and agent systems. Practice jailbreaks, indirect prompt injection, and multimodal attacks, then build guardrails that hold.

Subscription · Monthly