{"product_id":"applied-ai-security-attacking-and-defending-llms","title":"Applied AI Security: Attacking and Defending LLMs","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Applied AI Security: Attacking and Defending LLMs\u003cbr\u003e\u003cstrong\u003eTrainer(s): \u003c\/strong\u003eDrinor Selmanaj, \u003cspan\u003eIva Amos\u003c\/span\u003e\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 800 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eApplied AI Security: Breaking and Defending LLMs training focuses on how AI systems fail in practice, how those failures can be abused, and how to stop them. Learners exploit LLMs the way attackers do, then flip sides and build defenses that work. All exercises run on a professional cyber range purpose-built for hands-on skill development.\u003c\/p\u003e\n\u003cp\u003eApplied AI Security: Breaking and Defending LLMs is an in-depth, hands-on training that examines the security of systems built on large language models (LLMs) as they are deployed in real-world environments. As organizations increasingly integrate LLMs into applications, services, and operational workflows, these systems introduce new security risks that extend beyond traditional application and infrastructure security models.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThis course focuses on how LLM-based systems fail in practice, how those failures can be abused, and how they can be mitigated through sound security engineering and operational controls.\u003c\/p\u003e\n\u003cp\u003eParticipants will explore common design patterns used in LLM-enabled applications, including prompt-based interfaces, retrieval-augmented systems, tool-using agents, and automated workflows. Through guided exercises, attendees will analyze how trust boundaries shift in these systems and how misuse, manipulation, or unsafe behavior can lead to data exposure, unauthorized actions, or downstream system impact.\u003c\/p\u003e\n\u003cp\u003eThe training takes a balanced approach between offense and defense. On the offensive side, participants will examine techniques used to manipulate model behavior, influence decision-making, and abuse integrations between LLMs and external systems.\u003c\/p\u003e\n\u003cp\u003eOn the defensive side, the course emphasizes secure design principles, input and output controls, monitoring strategies, and response mechanisms tailored to AI-enabled systems. Rather than focusing on isolated model weaknesses, the course treats AI security as a system-level problem involving architecture, configuration, and operational context.\u003c\/p\u003e\n\u003cp\u003eAll concepts are reinforced through hands-on labs conducted in realistic environments designed to reflect how LLMs are used in production. Participants will practice assessing risk, testing AI-enabled features, and applying mitigations that are practical and maintainable.\u003c\/p\u003e\n\u003cp\u003eThe course also addresses operational considerations, including how to evaluate AI-related security incidents, how to integrate AI security into existing security workflows, and how to reason about risk when deploying or managing LLM-based systems.\u003c\/p\u003e\n\u003cp\u003eBy the end of the training, participants will have a practical understanding of how to evaluate the security posture of LLM-powered systems, how to identify and test meaningful failure modes, and how to design and operate defenses that reduce risk while allowing AI systems to remain useful and effective.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 AI Systems Security Foundations\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e How LLM-based systems are built and deployed in practice\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Trust boundaries in AI-enabled workflows\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Why traditional AppSec assumptions fail for LLMs\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Exploring an LLM-enabled application\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Identifying components, data flows, and trust boundaries\u003c\/p\u003e\n\u003ch3\u003e3.2 LLM Architecture and Integration Patterns\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Prompt-driven applications and system prompts\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Retrieval-augmented generation (RAG)\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Tool use, plugins, and agent-based workflows\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Where attackers gain leverage in real deployments\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Architecture mapping of an LLM-based system\u003cbr\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Identifying attacker-controlled inputs and integration risks\u003c\/p\u003e\n\u003ch3\u003e3.3 AI Red Teaming Concepts and Methodology\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e What AI red teaming is (and what it is not)\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Red teaming LLM systems vs traditional applications\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Adversarial thinking for language-driven systems\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Using structured frameworks to guide testing\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eFrameworks discussed\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.5\u003c\/strong\u003e OWASP guidance for AI and LLM risk categorization\u003cbr\u003e\u003cstrong\u003e3.3.6\u003c\/strong\u003e MITRE ATLAS for adversary behavior modeling\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.7\u003c\/strong\u003e Mapping AI system behaviors to structured red-team categories\u003cbr\u003e\u003cstrong\u003e3.3.8\u003c\/strong\u003e Identifying realistic abuse goals and success criteria\u003c\/p\u003e\n\u003ch3\u003e3.4 Threat Modeling for AI Systems\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Threat modeling LLM systems end-to-end\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Assets, actors, and abuse paths\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Differentiating misuse, abuse, and unintended behavior\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Prioritizing attacks based on real-world impact\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Threat modeling an AI-enabled workflow\u003cbr\u003e\u003cstrong\u003e3.4.6\u003c\/strong\u003e Selecting high-impact red-team test scenarios\u003c\/p\u003e\n\u003ch3\u003e3.5 Breaking LLM-Based Systems (Red Team Execution)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Prompt manipulation and behavioral influence\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Indirect input abuse through documents, data sources, or tools\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Unsafe agent behavior and excessive autonomy\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Chaining weaknesses across system components\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Executing controlled red-team scenarios against an LLM system\u003cbr\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Demonstrating unintended actions or data exposure\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.6 Defensive Engineering, and Operations Defensive Design for LLM-Based Systems\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Secure design principles for AI-enabled applications\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Reducing attack surface in prompts, tools, and agents\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Managing permissions, autonomy, and scope\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Hardening an LLM system against identified red-team techniques\u003cbr\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Applying guardrails and constraints\u003c\/p\u003e\n\u003ch3\u003e3.7 Monitoring and Detection for AI Abuse\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Observability challenges in AI workflows\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e Logging, tracing, and behavior monitoring\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Detecting prompt manipulation, misuse, and abnormal behavior\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e Turning red-team findings into detection logic\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.5\u003c\/strong\u003e Instrumenting an LLM system for visibility\u003cbr\u003e\u003cstrong\u003e3.7.6\u003c\/strong\u003e Detecting simulated red-team activity\u003c\/p\u003e\n\u003ch3\u003e3.8 AI Blue Teaming and Incident Response\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e Responding to AI-specific security incidents\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Containment and remediation for AI misuse\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Assessing downstream and organizational impact\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Coordinating technical and non-technical response\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Handling a simulated AI security incident\u003cbr\u003e\u003cstrong\u003e3.8.6\u003c\/strong\u003e Analysis, containment, and response decisions\u003c\/p\u003e\n\u003ch3\u003e3.9 Operationalizing AI Security and Red Team Feedback\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e Feeding red-team findings into secure development\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e Continuous testing of AI-enabled features\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e Aligning AI security with organizational risk management\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Using red teaming to improve system design over time\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.5\u003c\/strong\u003e Creating an AI red-team test plan for a real deployment\u003cbr\u003e\u003cstrong\u003e3.9.6\u003c\/strong\u003e Defining testing scope, goals, and reporting outputs\u003c\/p\u003e\n\u003ch3\u003e3.10 Capstone: End-to-End AI Security Assessment\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTopics\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Applying red and blue team concepts together\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Evaluating risk, controls, and residual exposure\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Communicating findings clearly to stakeholders\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eLabs (Capstone \/ Certification)\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.4\u003c\/strong\u003e Full assessment of an LLM-enabled system\u003cbr\u003e\u003cstrong\u003e3.10.5\u003c\/strong\u003e Identify risks, execute red-team tests, and propose defenses\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents should have:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBasic familiarity with using popular AI or chat-based tools\u003c\/li\u003e\n\u003cli\u003eAbility to read and modify basic Python code\u003c\/li\u003e\n\u003cli\u003eComfort using command-line tools and working in a lab environment\u003c\/li\u003e\n\u003cli\u003eBasic understanding of how APIs and modern web applications are structured\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLaptop with Wi-Fi\u003c\/li\u003e\n\u003cli\u003eModern web browser\u003c\/li\u003e\n\u003cli\u003eAbility to follow guided, hands-on lab instructions\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ePre-configured adversary and target infrastructure\u003c\/li\u003e\n\u003cli\u003eCustom tooling and scripts\u003c\/li\u003e\n\u003cli\u003eDigital course workbook and reference materials\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eDrinor Selmanaj\u003c\/h3\u003e\n\u003cp\u003eDrinor Selmanaj is a cybersecurity practitioner, researcher, and instructor specializing in adversary emulation, threat-informed defense, and offensive security operations. He is the author of the O’Reilly book Adversary Emulation with MITRE ATT\u0026amp;CK, which provides a structured methodology for translating real-world threat intelligence into realistic, measurable adversary campaigns.\u003c\/p\u003e\n\u003cp\u003eWith over a decade of experience across penetration testing, red teaming, and national-level cybersecurity consulting, Drinor has worked with multinational enterprises, critical infrastructure operators, and government-aligned stakeholders. He is the founder of Cyber Academy, where he designs and delivers advanced cybersecurity training programs and develops cyber ranges focused on realistic offensive and defensive scenarios.\u003c\/p\u003e\n\u003ch3\u003eIva Amos\u003c\/h3\u003e\n\u003cp\u003eIva Amos is a cybersecurity professional and practitioner researcher specializing in AI security, prompt injection, and agentic AI risk. She leads a multimillion CISA federal contract for upskilling government employees and architects training programs for over 70% of the Fortune 500 at Infosec.\u003c\/p\u003e\n\u003cp\u003eThe scope of her work spans a professional cyber range platform with 600+ labs, training 10K+ security professionals annually. She also teaches cybersecurity and AI\/ML at two universities. She presents breakout sessions and workshops at Gartner, EDUCAUSE, ISACA, NICE, Infosec World, and Hack Space Con, and brings 19+ years in technology with deep focus on cybersecurity and AI security training.\u003c\/p\u003e\n\u003cp\u003eIva and Drinor have worked together for over a year, architecting hands-on lab exercises for multiple training programs. Their most recent collaboration produced the labs for Infosec's \"Generative and Agentic AI for Cybersecurity Professionals\" course.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e \u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e \u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942328180979,"sku":null,"price":800.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/Iva_headshot.jpg?v=1786895364","url":"https:\/\/me.shop.defcon.org\/products\/applied-ai-security-attacking-and-defending-llms","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}