Securing AI systems: the threat landscape
What actually changes when a model joins a system, the attacks that follow from it, and how to threat model an AI feature before you ship it.
Access control across a retrieval index, the confused deputy problem in tool use, and keeping an agent inside its blast radius.
Retrieval and tool use are where language models stop being a text box and start being part of the system — and where the interesting failures live.
This course covers the attack surface of a retrieval pipeline, carrying permissions into the index, the confused deputy problem that tool calling creates, and how to bound what an autonomous agent can do when something in its context goes wrong.
4 lessons · 1 hr 3 min
Every stage of a RAG pipeline is somewhere an attacker can write, read or hide.
Filter in the query, not in the answer, and keep permissions attached to chunks.
When the model acts with the application's authority instead of the user's.
Budgets, sandboxes, checkpoints and the question of what one bad turn can cost.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
1 min read
1 min read
1 min read
1 min read
What actually changes when a model joins a system, the attacks that follow from it, and how to threat model an AI feature before you ship it.
How injection works, why filtering fails, and the design patterns that actually contain it.
Attacks on models themselves: evasion, poisoning and backdoors, model theft, and what the data remembers.