GenAI Cybersecurity: OWASP Top 10, MITRE ATLAS & API Attacks

所在平台: Udemy

课程主页: https://www.udemy.com/course/genai-cybersecurity-owasp-top-10-mitre-atlas-api-attacks/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:GenAI 网络安全:OWASP 前 10 名、MITRE ATLAS 和 API 攻击 概述:本课程是一个适合初学者的深度课程,旨在揭开 GenAI 网络安全的奥秘。不论您是网络安全爱好者、人工智能开发者,还是 IT 学生,本课程都提供了全面的理论和实践知识,帮助您保护大型语言模型 (LLMs)——当今生成性人工智能生态系统中的关键组成部分。 课程内容从深入的理论探讨开始,介绍 LLMs 的构建方法,基于 Transformer 架构,并探索神经网络从 RNN 向 Transformers 的演变。您将掌握诸如位置编码、 自注意力机制和多头注意力机制等创新。 接下来,我们将解析 LLM 系统的结构,包括: - 应用层 - AI 模型层 - 集成层 然后,我们将转向 GenAI 网络安全中的 LLM 攻击面,从两个方面进行分析: - 消费者方面的风险(例如,提示注入、数据泄露) - 提供者方面的漏洞(例如,模型盗窃、不安全的端点) 您将探讨 OWASP 针对 LLMs 的前 10 大风险以及如何使用 MITRE ATLAS 框架映射威胁。 课程还包含与实际攻击演示及解释: - OLLAMA API 配置错误及缓解演示(结合 NGINX 反向代理) - PortSwigger 实验室:利用 LLM APIs 的过度代理 此外,我们还将通过真实案例研究使学习更具相关性和实用性,案例包括: - OpenAI vs. DeepSeek - 蒸馏和模型盗窃风险 - Microsoft Tay - 输出污染与缺乏审核 - Wiz 的暴露日志 - 提示和数据泄露 - Chevrolet AI 聊天机器人 - 聊天机器人产生的意外现实代理 - Ollama API - 暴露端点且未进行身份验证 最后,我们将为有志于成为 GenAI 网络安全和 LLM 网络安全专业人士的学员提供职业建议和指导,包括: - 如何在 AI/ML 领域建立基础 - 网络安全与 GenAI 的交汇点 - 动手实践策略 - 通过信誉提升您的在线存在感 主题涵盖: - GenAI 网络安全 - 大型语言模型 (LLMs) - 生成性人工智能 - Transformer 架构 - 自注意力机制、多头注意力机制 - LLM 系统结构 - LLM 攻击面 - 针对 LLMs 的 OWASP 前 10 大风险 - MITRE ATLAS 框架 - 实际演示 - OpenAI 与 DeepSeek - LLM APIs 与过度代理 这种结构使得本课程不仅理论知识丰富,同时也具备实践操作,旨在为学员提供全面的 GenAI 网络安全教育。

课程评论(0条)

课程详情

Unlock the world of GenAI Cybersecurity with this beginner-friendly yet in-depth course. Whether you're a cybersecurity enthusiast, AI developer, or IT student, this course provides comprehensive theoretical and practical knowledge to secure Large Language Models (LLMs) - a critical component of today's Generative AI ecosystem.We start with a deep theoretical dive into how LLMs are built using the Transformer architecture, and explore the evolution of neural networks from RNNs to Transformers. You'll gain a solid grasp of innovations like: • Positional Encoding • Self-Attention • Multi-Head AttentionNext, we break down the Anatomy of an LLM System, covering: • Application Layer • AI Model Layer • Integration LayerThen we shift to GenAI Cybersecurity LLM Attack Surfaces, viewed from both: • Consumer-side risks (e.g., prompt injection, data leakage) • Provider-side vulnerabilities (e.g., model theft, insecure endpoints)You'll explore OWASP Top 10 Risks for LLMs and how to map threats using the MITRE ATLAS framework.This course includes Practical attack demos with explanations: • OLLAMA API Misconfiguration and Mitigation Demo (with NGINX reverse proxy) • PortSwigger Lab: Exploiting LLM APIs with Excessive AgencyWe'll also explore real-world case studies to make learning relatable and practical: • OpenAI vs. DeepSeek - Distillation & model theft risks • Microsoft Tay - Output poisoning and lack of moderation • Wiz's exposed logs - Prompt and data leakage • Chevrolet AI Chatbot - Unexpected real-world agency from chatbots • Ollama API - Exposed endpoints with no authenticationFinally, we conclude with career tips and guidance for aspiring GenAI Cybersecurity & LLM cybersecurity professionals, including: • How to build your foundation in AI/ML • Where cybersecurity meets GenAI • Hands-on practice strategies • Growing your online presence with credibilityTopics • GenAI Cybersecurity • Large Language Models (LLMs) • Generative AI • Transformer architecture • Self-Attention, Multi-Head Attention • Anatomy of an LLM System • LLM Attack Surfaces • OWASP Top 10 Risks for LLMs • MITRE ATLAS framework • Practical Demos • OpenAI vs. DeepSeek • LLM APIs with Excessive Agency

课程标签

0人关注该课程

主题相关的课程