Look beyond the model
Data, retrieval, identity, tools, application logic, people, and operations determine the real risk.
Learn / AI security
Learn to test, defend, and govern AI systems without crossing the line.
A practical, beginner-friendly learning path for AI security: foundations, safe labs, machine learning, LLM threats, red teaming, detection, cloud controls, and governance.
From foundations to incident response.
Foundation, testing, and defense.
Local, synthetic, or explicitly authorized.
Current frameworks and links checked.
How this is different
The source PDF supplied a useful beginner topic map. This adaptation replaces unsafe live-target examples, outdated tool snippets, and unqualified claims with system thinking, controlled labs, current terminology, and evidence-led practice.
Data, retrieval, identity, tools, application logic, people, and operations determine the real risk.
Models generate hypotheses. Reproduction, logs, tests, and source evidence turn them into findings.
Prioritize data exposure, authorization failure, and side effects over clever prompt demonstrations.
Every important control needs an owner, signal, stop path, retest, and rollback.
Choose your route
Build the vocabulary, lab discipline, Python confidence, and model-evaluation habits needed for every later module.
5 modulesThreat-model an AI application, test prompt boundaries, review code, and run repeatable evaluations inside a documented scope.
5 modulesDesign detection, constrain agents, secure the model supply chain, harden cloud deployment, and prepare response evidence.
4 modulesFoundation
Learn the difference between using AI for security, securing an AI application, and protecting the model lifecycle.
Create an isolated workspace, a written scope, synthetic data, and a stop procedure before running security experiments.
Learn the small set of Python and data-handling patterns needed to explore logs, build features, and preserve an audit trail.
Build a practical mental model of supervised learning, anomaly detection, thresholds, drift, and the cost of false decisions.
Follow a request through instructions, retrieval, tools, memory, output parsing, and the final business action.
Test safely
Turn a system map into abuse cases, control hypotheses, and a risk-based test plan.
Move beyond jailbreak tricks and test whether untrusted content can cross an authorization or action boundary.
Combine model-assisted review with static analysis, tests, dependency evidence, and developer context.
Use the NIST taxonomy to reason about adversarial machine learning across training, deployment, and inference.
Combine human creativity, automated probes, deterministic checks, and regression suites without mistaking volume for coverage.
Defend and operate
Build anomaly and AI-system monitoring that produces actionable investigation paths instead of unexplained scores.
Design an agent runtime where untrusted instructions cannot silently become broad authority.
Protect models, datasets, notebooks, registries, pipelines, endpoints, secrets, and observability across the deployment lifecycle.
Connect technical controls to incident handling, responsible disclosure, risk ownership, and the EU operating context.
Non-negotiable
Every practical exercise in this section assumes these boundaries. If a lab cannot meet them, stop and redesign the lab.
Source and adaptation
The user-provided 2026 PDF supplied the initial topic map. This field guide is an original rewrite with a defensive-first structure, current sources, safer labs, corrected terminology, and enterprise operating context.
Visit Codelivly