AI Security — Protecting GenAI/LLM Pipelines
A two-day technical training on securing GenAI and LLM pipelines: prompt injection, training data/model poisoning, data leakage through models, and AI model supply chain security, aligned with the CAISP methodology.
AI security is not application security with a new label
Classic OWASP Top 10 principles are not enough to secure a system built on a large language model — the boundary between code and input data blurs, and the model itself can be manipulated by the very text it processes. The training starts by explaining why a GenAI/LLM pipeline needs a distinct category of threat thinking before moving into concrete defensive techniques.
From prompt injection to the model supply chain
The programme covers the full lifecycle of an AI system: training and fine-tuning data vulnerable to poisoning, a RAG knowledge base vulnerable to malicious content injection, the model itself vulnerable to prompt injection and jailbreaking, and the supply chain — libraries, model weights, and external providers whose provenance must be verifiable.
Layered defense instead of false certainty
There is no single control that eliminates prompt injection risk entirely. The workshop teaches you to build a layered defense — input and output validation, least-privilege model permissions for function calling, anomaly monitoring, and human-in-the-loop mechanisms for high-risk actions — instead of chasing a single solution that doesn’t exist.
Benefits
- Identify and secure a GenAI/LLM pipeline against prompt injection attacks (direct and indirect)
- Build defenses against training data and model poisoning
- Design controls that prevent sensitive data leakage through model outputs
- Implement AI supply chain security: verifying the provenance of models and libraries (model supply chain security)
Who is this training for?
Prerequisites
- Basic understanding of LLM-based application architecture (API, RAG, fine-tuning)
- Familiarity with fundamental application security principles (OWASP Top 10 for web applications)
Training program
The GenAI/LLM-specific threat landscape
- OWASP Top 10 for LLM Applications — an overview of key risk categories
- How security for LLM-based systems differs from traditional application security
- The CAISP (Certified AI Security Professional) methodology as a reference framework
- Mapping AI risks onto existing security risk management processes
Prompt injection and model manipulation
- Direct prompt injection — attack techniques and detection
- Indirect prompt injection via external data sources (documents, web pages, search results)
- Jailbreaking and guardrail bypass techniques
- Designing an input/output validation and filtering layer
Data and model poisoning
- Attacks on training and fine-tuning data — vectors and anomaly detection
- Backdoors in open-source models and verifying model weight integrity
- RAG pipeline security — protecting the knowledge base from malicious content injection
- Monitoring model drift as a signal of a potential attack
Data leakage and model output security
- Preventing exposure of sensitive data from training data (membership inference, data extraction)
- Controlling leakage of company data through interactions with external model providers (API providers)
- Anonymizing and redacting personal data in prompts and responses
- Auditability and logging of model interactions for compliance purposes
AI supply chain security
- Verifying the provenance of models, datasets, and libraries (model cards, SBOM for AI)
- Risks associated with models hosted by external providers
- Securely deploying AI agents with access to external tools (function calling, MCP)
- An incident response plan specific to GenAI/LLM systems
Delivery Methods
Online
- Convenience of participating from anywhere
- Interactive live sessions with trainer
- Materials available for 30 days
- No travel costs
On-site
- Direct contact with trainer and group
- Intensive hands-on workshops
- Networking with other participants
- Full focus on learning
Frequently asked questions
How does this training differ from OWASP Top 10 for Agentic AI Applications in our catalog?
That existing training focuses on threats specific to autonomous, multi-step AI agents. This training covers a broader scope — the entire GenAI/LLM pipeline, from training data through fine-tuning and RAG to production deployment — including threats not limited to agents: data poisoning, leakage through the model, and model supply chain security.
Can prompt injection be eliminated entirely?
There is no single method that eliminates prompt injection 100%, because the boundary between system instructions and user input is inherently blurry in LLMs. In the training we build a layered defense: input validation and sanitization, least-privilege model permissions for function calling, output monitoring, and human-in-the-loop review for high-risk actions — reducing risk to an acceptable level rather than eliminating it entirely.
How do we secure a RAG system against malicious content being injected into the knowledge base?
The key controls are: validating and sanitizing documents before indexing, restricting data sources to trusted repositories, monitoring vector search results for anomalies, and separating permissions between the indexing process and model responses. In the workshop we walk through a concrete architecture for a secured RAG pipeline.
Is using external models (OpenAI, Anthropic, Google) via API safe for company data?
It depends on the contract configuration and data privacy settings — most commercial API providers offer options to opt out of using data for model training, but that doesn't eliminate the risk associated with transmitting sensitive data in prompts. In the training we cover both technical controls (anonymization before sending, DLP for prompts) and contractual ones (data processing agreements) that minimize this risk.
What is the CAISP certification, and does this training prepare for it?
CAISP (Certified AI Security Professional) is a fast-growing certification specializing in AI system security, associated with a 15-20% salary premium according to industry data. The training uses the CAISP methodology as its content framework and covers most of its key areas, but it is not a formal exam-prep course for the certification.
Request a quote
Funding Options
Check funding options for your company
Development Services Database
Up to 80% funding for SMEs from EU funds
Check availabilityNational Training Fund
Up to 100% funding for employers
Learn moreTrusted by
We train teams at Poland's largest companies
Interested in this training?
Contact us - we'll prepare an offer tailored to your organization's needs.