Secure the AI systems your organization is putting into production. You will threat model machine learning architectures with STRIDE-ML, inventory model and dataset dependencies in an ML-BOM, and harden inference endpoints against extraction and abuse. You will filter prompt injection with Bedrock Guardrails, scope IAM roles so a compromised agent cannot reach what it never needed, trace poisoned documents back through a knowledge base, and rate limit an API so runaway cost becomes a manageable event. The work is hands-on in AWS with Python, and it builds toward a capstone where you deploy, harden, and validate a Bedrock RAG agent. Bring working knowledge of Python, cloud fundamentals, and basic security concepts.
Overview
Syllabus
- Welcome to AI Security
- Set up your tooling and AWS access, and preview the AI security skills and the Bedrock capstone project ahead of you.
- Build Aria: Set Up the AWS Exercise and Demo Environment
- Understand Threat Modeling for Machine Learning
- Learn how classic threat modeling adapts to machine learning, and use STRIDE-ML to name specific threats against each part of an AI system.
- Apply Threat Modeling with STRIDE-ML
- Build a structured threat model for a Bedrock RAG architecture, ranking threats by likelihood and impact to pick the control that ships first.
- Understand the Machine Learning Bill of Materials
- Track pre-trained models and datasets as supply chain dependencies, and see what an ML-BOM records so you can scope a vulnerability fast.
- Generate an ML-BOM for a Machine Learning Project
- Create an ML-BOM for a RAG system, documenting both the embedding and generation models plus the provenance gaps a managed API leaves behind.
- Understand Secure Model Serving and API Management
- Examine why an inference endpoint is a security boundary of its own, and the layered controls that protect a model from theft and abuse.
- Audit Bedrock Client Security Configuration
- Audit a Bedrock client configuration for hardcoded credentials, missing input validation, and absent logging, then scope its IAM policy correctly.
- Understand AI-Specific Monitoring and Incident Response
- Discover why AI systems fail behaviorally while infrastructure stays healthy, and which signals reveal drift, hallucination, and active attacks.
- Configure Bedrock Logging and Incident Response Playbooks
- Configure model invocation logging, then write a monitoring plan and an incident response playbook for an AI-specific event.
- Understand Input Sanitization for LLM Prompts
- Study how prompt injection works, including payloads hidden in retrieved documents, and where denylists and allowlists each fall short.
- Filter Input and Output with Bedrock Guardrails
- Design and test Bedrock Guardrails that block injection attempts on the way in and catch sensitive data on the way out.
- Configure PII Detection and Data Classification
- Classify documents by sensitivity and configure PII detection so a knowledge base carries only what the assistant actually needs.
- Configure IAM Policies for Cloud AI Services in AWS
- Write least-privilege policies and an organization-level SCP, then interpret IAM Access Analyzer findings for Bedrock resources.
- Understand Least Privilege for LLM Tools
- Assess agent tools by the damage they can do, and see why a human approval step belongs in system architecture rather than in a prompt.
- Enforce Least Privilege with IAM Roles
- Right-size the IAM roles behind a RAG agent, replacing wildcards with scoped ARNs and measuring the blast radius you remove.
- Understand Data Provenance Tracking
- Trace what a complete provenance record contains, and how poisoned documents reach a knowledge base and stay hidden inside it.
- Detect and Investigate Knowledge Base Poisoning
- Investigate a poisoned knowledge base, walking a provenance trail backward from a bad response to the upload event that caused it.
- Understand Rate Limiting for Inference APIs
- Compare fixed and sliding window rate limiting, and see why unbounded cost threatens an inference API as much as downtime does.
- Implement a Sliding Window Rate Limiter in Python
- Implement a sliding window rate limiter, analyze usage logs for abuse patterns, and set a limit you can defend from expected traffic.
- Understand IAM Policies for Cloud AI Services
- Read an IAM policy for a cloud AI service and identify the wildcard patterns that hand an attacker administrative control.
- Project: Northstar Assist: Build and Secure an AWS Bedrock RAG AI Agent
- Deploy, harden, and validate Northstar Assist, an Amazon Bedrock AgentCore RAG agent, applying threat modeling, an ML-BOM, guardrails, and logging to a system that is ready to launch.
Taught by
Kevin Carter