Take an AI system through a complete security review. Threat model the architecture, run adversarial testing to identify weaknesses, implement controls, and produce risk and compliance documentation pre-launch. Work on realistic systems, including an AWS Bedrock RAG agent, a containerized image classifier, a RAG research agent, and a clinical risk model. Start in the defender's seat, building and securing a cloud AI system before seeing attacks. The next two courses cover attacks on classical machine learning and generative and agentic systems, with each attack followed by the control that stops it. The final course covers governance, where you produce risk registers, ATLAS threat models, EU AI Act classifications, fairness audits, model cards, and deletion pipelines.
AI Security Engineer
via Udacity Nanodegree
Overview
Syllabus
- AI Threat Modeling and Operational Defense
- Secure the AI systems your organization is putting into production. You will threat model machine learning architectures with STRIDE-ML, inventory model and dataset dependencies in an ML-BOM, and harden inference endpoints against extraction and abuse. You will filter prompt injection with Bedrock Guardrails, scope IAM roles so a compromised agent cannot reach what it never needed, trace poisoned documents back through a knowledge base, and rate limit an API so runaway cost becomes a manageable event. The work is hands-on in AWS with Python, and it builds toward a capstone where you deploy, harden, and validate a Bedrock RAG agent. Bring working knowledge of Python, cloud fundamentals, and basic security concepts.
- AI Red Teaming and Adversarial Machine Learning
- This course equips you with essential skills to identify and exploit vulnerabilities in AI systems. You will explore the fundamentals of AI red teaming, including theoretical and practical applications of evasion attacks, data poisoning, prompt injection, and vector database attacks. The course also covers advanced topics such as model inversion and quantitative robustness testing, ensuring a comprehensive understanding of AI security threats. You will gain hands-on experience through real-time applications and a capstone project focusing on AI red-teaming strategies to enhance security measures and safeguard against adversarial tactics.
- LLM and Agentic AI Security
- Attack generative and agentic AI systems the way an adversary would, then harden the same systems against the attacks you just ran. You will jailbreak a commercial assistant, plant indirect injections in content a pipeline ingests, hijack an agent through its own data, and hide instructions inside images, then build the hardened system prompts, guardrails, RAG controls, agent boundaries, structured logging, and human-in-the-loop gates that stop them. The course closes with a capstone that red-teams and hardens a RAG-enabled research agent against the OWASP LLM Top 10.
- AI Security Governance, Risk, and Compliance
- Explore the intricacies of AI security through a comprehensive examination of strategies, risk management frameworks, and governance structures. This course equips participants with the tools to implement Explainable AI for security auditing, develop effective AI Acceptable Use Policies, and establish an AI Incident Response Playbook. Engage in practical lessons on NIST AI RMF and MITRE ATLAS for threat modeling and dive into regulatory compliance under the EU AI Act. Participants will also learn to assess third-party AI vendors, manage data privacy, and create metrics dashboards, culminating in a project focused on AI governance for a real-world launch scenario.
Taught by
Kevin Carter, Josh Kalin, and Sohbet Dovranov