OneRange

AI Security & Privacy: Advanced

This course helps technical staff recognize and defend against AI-specific security and privacy threats. It covers prompt injection and jailbreaks, data leakage, model and supply-chain risk, and secure deployment. Learners finish able to identify and mitigate the threats unique to AI systems.

What this course covers

The course runs across 10 topics, each one a short adaptive session rather than a recorded lecture. The tutor explains the idea, works an example, checks understanding, and adjusts the next step to the answer given.

  • Threat Modeling for AI Systems — Understand the unique attack surface of LLMs and machine learning pipelines compared to traditional software.
  • Prompt Injection: Mechanisms and Exploits — Analyze how direct and indirect prompt injections bypass system instructions to hijack model behavior.
  • Defending Against Prompt Injection — Implement robust defense-in-depth strategies, including LLM guardrails, input sanitization, and structural formatting.
  • Jailbreaking and Adversarial Robustness — Explore advanced jailbreak techniques (e.g., base64 encoding, roleplay attacks) and how to evaluate model resilience.
  • Data Leakage and Privacy Risks in LLMs — Identify how sensitive training data, system prompts, and user PII can be exfiltrated through model outputs.
  • Mitigating Data Leakage in Production — Configure PII scrubbing, differential privacy techniques, and output filtering mechanisms within the application layer.
  • Model & Supply-Chain Security — Assess risks related to malicious base models, poisoned training data, insecure Hugging Face repositories, and vulnerable third-party APIs.
  • Secure Model Deployment & Sandboxing — Configure secure runtimes, restrict container network access, and apply the principle of least privilege to model execution environments.
  • API Gateway Security & Rate Limiting — Implement request throttling, API key rotation, and abuse detection to prevent denial-of-wallet and scraping attacks.
  • Continuous Monitoring and Incident Response for AI — Set up logging, anomaly detection, and automated containment strategies tailored for dynamic AI application behaviors.

Skills you build

Results are measured against named skills in the OneRange taxonomy of more than 10,000 skills, so a manager sees proficiency per skill rather than a completion tick. This course maps to Privacy in Artificial Intelligence (AI), AI Safety, Threat Modeling, Model Security, AI Risk Management.

  • Privacy in Artificial Intelligence (AI)
  • AI Safety
  • Threat Modeling
  • Model Security
  • AI Risk Management

Who it is for

IT, security, builders. The material is pitched at advanced level, and takes roughly 150 minutes at a typical pace. Because every session adapts, someone who already knows a topic moves through it quickly instead of sitting through an explanation they do not need.

It sits in the Category: Security track of the Vero AI Catalog, and can be assigned to one person, a team, or the whole company.

How it is delivered and assessed

Delivery is conversational and interactive, including code lab, branching scenario, guided lab exercises. There is no video to sit through and no slide deck to click past.

Understanding is checked with a lab assessment of 5 items, with a pass mark of 70%.

Administrators can copy this course into their own library and adapt it — edit the outline, change the duration, swap the assessment format, or ground it in internal documentation so answers cite the company's own source material.

Also in this track

Related

Frequently asked questions

How long does this course take?

It runs roughly 150 minutes at a typical pace. Because every session adapts, someone who already knows a topic moves through it quickly instead of sitting through an explanation they do not need.

How is it assigned to a team?

An administrator assigns it from the Vero dashboard to one person, a team, a department or the whole company, and sees progress and results per person and per skill.

Can we customise it with our own documents and terminology?

Yes. Administrators can copy this course into their own library and adapt it — edit the outline, change the duration, swap the assessment format, or ground it in internal documentation so answers cite the company's own source material.

Course code CAT-SEC.