Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Strategies in Secure AI Systems: From GenAI and Agentic AI
Highest Rated
Rating: 4.9 out of 5(10 ratings)
123 students

Strategies in Secure AI Systems: From GenAI and Agentic AI

Mastering Security's Semantic Shift
Created byDerek Fisher
Last updated 12/2025
English
English [Auto],

What you'll learn

  • Explain the fundamental semantic shift in AI security and why traditional security tools and approaches have critical gaps when applied to AI systems.
  • Recognize and categorize the types of GenAI architectures and assess their relative security risk levels.
  • Apply the NIST AI Risk Management Framework to structure AI risk management activities
  • Compare and contrast major AI security frameworks including and determine when to apply each framework.
  • Identify novel attack surfaces unique to AI systems including prompt injection, model poisoning, data exfiltration through reasoning, and agent exploitation
  • Evaluate AI systems against regulatory frameworks including the EU AI Act risk classifications and US federal/state requirements
  • Incorporate AI-specific security considerations into existing cybersecurity programs

Course content

4 sections30 lectures5h 28m total length
  • Introduction1:03
  • The State of AI Adoption15:53

    This section examines the current landscape of AI adoption, exploring both the explosive growth and inherent limitations shaping how organizations deploy these systems. We analyze concrete data showing massive investment ($1.6 trillion since 2013), accelerating adoption across industries, and the economic drivers making AI attractive—particularly the dramatic cost advantages over human labor. However, we balance this enthusiasm with a critical look at AI's current limitations: reliability issues that prevent full automation, significant performance gaps compared to human capabilities (illustrated by the WebArena benchmark showing 14.41% AI success vs. 78.24% human success), and the substantial cost and security complexities that organizations must navigate.

    The section then establishes a foundational understanding of key AI distinctions—differentiating Generative AI (content creation), Agentic AI (autonomous action-taking), and theoretical General AI—before diving into the four primary GenAI architectures organizations deploy today. We explore how each architecture introduces unique security challenges, from simple prompt injection vulnerabilities in static implementations to the complex autonomous exploitation risks in agentic applications. This sets up the critical concept of the "semantic shift"—explaining why traditional security tools designed to catch syntactic attacks like SQL injection fundamentally fail against AI threats that exploit meaning and context. We conclude with practical exercises helping learners identify these architectures in real systems and transition into examining the security frameworks designed specifically to address these novel challenges.

  • OWASP LLMSecOps7:06

    This section introduces the OWASP GenAI Security Project and its comprehensive LLMSecOps Framework, which provides practical guidance for implementing security throughout the AI application lifecycle. The OWASP GenAI Security Project achieved flagship status in March 2025, representing contributions from over 600 experts across 18 countries and 130+ companies. It evolved from the OWASP Top 10 for LLMs into a comprehensive resource that collaborates directly with NIST, MITRE, and other global entities, covering threat intelligence, governance guidance, secure adoption practices, data security, and agentic application security. Version 2025, released in November 2024, represents the definitive industry standard for LLM security.

    The LLMSecOps Framework structures security as a continuous loop with several key phases. It begins with Plan and Scope, covering access control planning, compliance assessment, data privacy protection, security posture planning, and third-party assessment. The Augment and Fine Tune Data phase addresses data source validation, secure data handling, data quality testing, model integrity validation, and vulnerability assessment. Dev and Experiment includes authentication, experiment tracking, vulnerability scanning, and secure coding practices. The Test and Evaluation phase encompasses adversarial testing, application security orchestration, bias and fairness testing, benchmarking, and penetration testing. Release focuses on AI/ML bill of materials, digital signing, model security posture evaluation, secure CI/CD pipelines, and supply chain verification. Deploy covers compliance verification, deployment validation, encryption, MFA, network security, secure API access, and privacy protections. Finally, Operate includes adversarial attack protection, automated alerting, data integrity, LLM guardrails, incident detection and response, patch management, and runtime self-protection.

    Throughout all these phases, continuous monitoring spans the entire framework, including adversarial input detection, model behavior analysis, AI/LLM posture management, patch and update alerts, regulatory compliance tracking, security alerting, metrics collection, user activity monitoring, observability, and data privacy protection. A governance layer overlays everything, covering bias and fairness oversight, compliance management, data security posture management, incident governance, risk assessment and management, and user/machine access audits. This comprehensive framework ensures that security is integrated at every stage of the AI lifecycle rather than treated as a single checkpoint or afterthought.

  • Guidance from NIST3:06

    This section explores the NIST AI Risk Management Framework (AI RMF), which provides a comprehensive, risk-based approach to managing AI systems throughout their lifecycle. The framework consists of four key elements: the AI RMF Core (providing four key functions: Govern, Map, Measure, and Manage), the AI RMF Playbook (offering actionable guidance for implementation), the AI RMF Roadmap (outlining NIST's strategy for keeping the framework current), and Crosswalks (mapping relationships to other frameworks like ISO standards). The four core functions work together in a continuous cycle, with Govern sitting at the center cultivating a risk-aware culture and establishing the foundation, while Map, Measure, and Manage operate in a continuous loop—Map establishes context and identifies risks, Measure employs tools and metrics to analyze and track those risks, and Manage allocates resources to prioritize and respond to risks based on their projected impact.

    We examine each function in depth, understanding their specific purposes and key actions. Govern establishes the foundation by defining roles and responsibilities, creating AI inventories, and instituting impact assessments to enable systematic risk articulation and "go/no-go" deployment decisions. Map focuses on understanding context by forming diverse teams to anticipate socio-technical risks, documenting system boundaries and operational contexts including cultural factors, and engaging external stakeholders and affected communities throughout the AI lifecycle. Measure emphasizes selecting valid and reliable metrics for trustworthiness characteristics, testing under realistic conditions that simulate actual deployment environments rather than sanitized lab data, and conducting adversarial testing and red-teaming to proactively probe for vulnerabilities and failure modes. Manage prioritizes risk responses based on impact and likelihood, implements continuous post-deployment monitoring to track performance drift and detect incidents in real time, and establishes protocols for safe decommissioning when systems exceed risk tolerances. The AI RMF Playbook translates these functions into specific, voluntary sub-actions that organizations can adapt to their context, while NIST's seven characteristics of trustworthy AI—valid/reliable, safe, secure/resilient, accountable/transparent, explainable/interpretable, privacy-enhanced, and fair with managed bias—provide the targets that the framework helps organizations achieve.

  • The AI RMF Core2:52

    The Map function establishes and understands the comprehensive context of an AI system, including its intended purpose, potential impacts, and the specific socio-technical setting in which it will be deployed. Key actions include forming diverse interdisciplinary teams with varied demographic backgrounds and lived experiences to better anticipate a wider range of risks and avoid blind spots, documenting system boundaries and context including the AI system's intended purpose, expected users, knowledge limits, assumptions, and operational context with attention to social norms and cultural factors, and engaging external stakeholders through regular, meaningful engagement with affected communities, civil society, and external experts to integrate feedback on positive, negative, and unanticipated impacts throughout the lifecycle. The Measure function then employs appropriate, ongoing methods and metrics to analyze, track, and document AI system performance and risks across trustworthiness characteristics based on the context established in Map. This involves selecting valid and reliable qualitative and quantitative metrics for each mapped risk while documenting risks that cannot be measured, testing in realistic conditions that closely simulate the actual deployment environment rather than sanitized test data to understand how the system functions in its intended socio-technical context, and conducting adversarial testing and red-teaming to proactively probe for vulnerabilities, biases, and unexpected failure modes under stress conditions.

  • The AI RMF Playbook11:35

    Apply the AI RMF playbook to govern, map, measure, and manage risk in a continuous cycle. Build a risk-aware culture, diverse sociotechnical contexts, and trustworthy AI with seven characteristics.

  • MITRE ATLAS1:24

    MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) applies the proven MITRE ATT&CK methodology specifically to AI and machine learning systems, providing a comprehensive knowledge base of adversary tactics and techniques based on real-world attacks. The framework includes 15 tactics representing high-level adversary goals (such as reconnaissance, ML model access, execution, persistence, and impact), over 130 techniques describing specific methods attackers use against AI systems, 26 mitigations offering defensive strategies mapped to techniques, and 33 case studies documenting real-world examples from red teams and security researchers. The ATLAS matrix organizes these elements to support threat modeling for AI/ML systems, adversarial testing and red teaming, risk assessment, assurance activities, and establishing a common language for discussing AI threats across the industry. Organizations can systematically walk through the matrix during security design or assessment, asking whether adversaries could use each technique against their system, what attackers would need to succeed, and what controls are in place to prevent or detect such attacks, making ATLAS a practical resource available at atlas.mitre.org for understanding and defending against AI-specific threat vectors.

  • NIST Cybersecurity Framework Profile for AI10:30

    The NIST Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), currently in initial preliminary draft form as NIST Interagency Report 8596, helps organizations integrate AI-specific considerations into their existing cybersecurity programs by building upon the established CSF 2.0 framework with its six functions (Govern, Identify, Protect, Detect, Respond, Recover). The Profile organizes AI security into three critical focus areas that capture the dual nature of AI from a cybersecurity perspective: SECURE (managing cybersecurity challenges when integrating AI into organizational ecosystems, protecting new assets like models, training data, prompts, embeddings, algorithms, agents, and the AI supply chain), DEFEND (using AI to enhance cybersecurity processes through predictive analysis, advanced threat and anomaly detection, automated incident response, and Zero Trust modeling while being aware of AI-enabled defense failure modes), and THWART (building resilience against AI-enabled threats including hyper-realistic spear-phishing with deepfakes, novel malware generation that evades signature-based detection, and autonomous attack orchestration where AI agents independently execute attack phases from reconnaissance to exfiltration). The Profile works in practice by taking existing CSF subcategories and adding AI-specific considerations across all three focus areas—for example, extending identity and credential management (PR.AA-01) to address how AI systems receive unique traceable identities (SECURE), how AI can flag anomalous credential use (DEFEND), and how to protect credentials from AI-powered brute-force attacks (THWART). This approach provides a consistent bridge between existing cybersecurity programs and the AI-integrated future, allowing organizations to leverage their established frameworks rather than building separate AI security programs from scratch, moving from the duality of AI as both opportunity and risk toward disciplined, systematic AI security management.

  • From Duality to Discipline5:00
  • Global AI Regulation and EU Risk Classification8:37

    The international regulatory landscape for AI reflects diverse regional approaches shaped by different cultural values, political systems, and regulatory philosophies. The EU focuses heavily on ethics and rights-based regulation prioritizing fairness, transparency, and human dignity, while the US takes a more decentralized approach with sector-specific regulations emphasizing innovation and competitiveness, and China implements strong state control with emphasis on social stability and government alignment. Countries like Canada, Japan, and India seek frameworks that balance innovation promotion with public trust. A major challenge is maintaining regulatory relevance amid rapid AI advancements, requiring adaptive and enforceable governance models, along with global cooperation for harmonized standards to address cross-border issues like bias and privacy. The EU AI Act classifies AI systems into four risk levels: unacceptable risk (banned), high risk (strict compliance requirements including extensive documentation, conformity assessments, and CE marking), limited risk (transparency requirements with user disclosures and AI-generated content labeling), and minimal risk (minimal or no requirements), with enforcement penalties up to €35 million or 7% of global turnover enforced between 2025-2027. In the United States, federal regulation includes OMB M-24-10 mandating Chief AI Officers and AI use case inventories for federal agencies, Executive Order 14110 calling for pre-deployment testing, continuous monitoring, and AI content labeling, and planned infrastructure orders to strengthen AI infrastructure while ensuring national security and removing innovation barriers, along with transparency and collaboration requirements encouraging public engagement and inter-agency coordination. At the state level, Colorado targets high-risk AI systems with risk management and transparency rules effective February 2026, Illinois regulates AI use in employment with mandatory notices prohibiting discrimination starting January 2026, and states like California (most AI laws), Texas (eight laws on deepfakes and transparency), Montana (six laws on election deepfakes), and Utah (five laws on disclosure and government AI) create a patchwork of regulations that companies must navigate across different jurisdictions.

  • Quiz - Introduction to AI Security

Requirements

  • An understanding of core cybersecurity concepts
  • Familiarity with Application Security concepts and software development lifecycle
  • Exposure to AI concepts and an understanding of how AI systems operate

Description

Master AI Security in the Age of Autonomous Systems: The Complete GenAI & Agentic AI Defense Strategy

Are you ready to defend against the next generation of AI threats? The attack surface has fundamentally changed—and traditional security is no longer enough.

In an era where AI systems autonomously make decisions, generate content, and interact with critical infrastructure, a new paradigm of vulnerabilities has emerged. Welcome to the "Semantic Shift"—where attackers no longer exploit code syntax but manipulate meaning and intent itself.

Why This Course Is Essential for Your Career

For Security Professionals: Traditional application security focused on SQL injection and buffer overflows. Today's threats? Prompt injection attacks that hijack AI reasoning, data poisoning that corrupts model behavior, and cascading failures across multi-agent systems. This course bridges the gap between classic AppSec and the emerging AI threat landscape.

For AI/ML Engineers: Building cutting-edge AI systems means nothing if they can be compromised through semantic manipulation. Learn to architect secure-by-design AI applications that withstand real-world adversarial tactics documented in MITRE ATLAS™.

For Compliance & Risk Leaders: Navigate the complex web of AI regulations—from the EU AI Act's risk tiers to US Executive Order 14110 and FDA Predetermined Change Control Plans. Transform regulatory requirements into actionable security controls.

What Makes This Course Different

Industry-Leading Frameworks Integrated:

  • OWASP Top 10 for LLM Applications (2025) – Master the latest vulnerabilities from Prompt Injection to Supply Chain attacks

  • OWASP Top 10 for Agentic AI (ASI) – Learn unique risks in autonomous systems: Agent Goal Hijacking, Tool Misuse, Identity Abuse

  • NIST AI RMF – Implement GOVERN, MAP, MEASURE, MANAGE functions for enterprise-scale AI risk management

  • MITRE ATLAS™ – Understand real-world ML attack tactics and techniques used by adversaries

Hands-On with the LLMSecOps Infinity Loop: Go beyond theory with a complete 9-stage secure lifecycle framework covering everything from initial scoping through continuous monitoring—specifically designed for AI systems.

Quantify Risk Like Never Before: Learn the groundbreaking AIVSS Scoring System that combines traditional CVSS metrics with the Agentic AI Risk Score (AARS), giving you a standardized way to communicate AI-specific risks to stakeholders and calculate security ROI.

Privacy-Enhancing Technologies (PETs) Mastery: Implement cutting-edge protection with Differential Privacy, Federated Learning, Homomorphic Encryption, and Trusted Execution Environments—securing sensitive training data without sacrificing model performance.

Who Should Enroll

Application Security Engineers transitioning to AI security
DevSecOps professionals implementing AI/ML pipelines
AI/ML Engineers responsible for production systems
Security Architects designing AI-powered applications
Compliance Officers navigating AI regulations
Risk Managers quantifying AI system vulnerabilities
Technical Leaders building AI security programs

Course Outcomes: What You'll Master

By completion, you will:

  • Identify and mitigate the OWASP Top 10 for both LLM and Agentic AI applications

  • Implement comprehensive AI red teaming across Model, Implementation, System, and Runtime layers

  • Navigate global AI regulations (EU AI Act, US EO 14110, sector-specific mandates)

  • Build an AI Governance structure with CAIO appointment and risk tolerance frameworks

  • Deploy LLMSecOps practices for secure AI development lifecycles

  • Quantify AI-specific risks using AIVSS and communicate ROI to leadership

  • Architect secure multi-agent systems resistant to cascading failures

  • Protect multimodal systems (VLM, deepfakes) from cross-modal attacks

  • Maintain audit-ready documentation with AIBOM, SBOM, and Model Cards

The Bottom Line

Traditional cybersecurity prepared you to defend code. This course prepares you to defend intelligence, autonomy, and meaning—the new attack surface of the AI era.

The semantic shift is here. Are you prepared?

Enroll now and become the AI security expert your organization desperately needs.

Who this course is for:

  • Application security professionals expanding into AI security
  • Software developers working with or integrating AI systems
  • Security engineers and architects responsible for AI deployments
  • IT risk and compliance professionals overseeing AI initiatives
  • Product managers and technical leaders implementing AI solutions