|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/generative-ai-cybersecurity-solutions/
课程评论:没有评论
课程名称:生成性人工智能网络安全解决方案 课程概述:随着生成性人工智能(GenAI)在现代商业系统中的重要性不断增加,确保其安全部署已成为首要任务。本课程“生成性人工智能网络安全解决方案”深入探讨了大型语言模型(LLMs)、代理框架、RAG管道和AI驱动API的威胁、安全控制和安全架构。与传统的网络安全方法(主要围绕静态系统和确定性逻辑构建)不同,GenAI引入了新的攻击面,包括提示注入、对抗向量回忆、插件滥用、幻觉和记忆中毒,因此需要重新构想防御策略。 课程首先概述了GenAI应用程序面临的基础威胁,说明传统安全框架的不足,并介绍OWASP LLM前10名、NIST人工智能风险管理框架、OWASP MAS和ISO 42001。学习者将探讨GenAI特定风险,如提示滥用、嵌入漂移和数据外泄,同时了解包括GDPR、HIPAA和DORA在内的监管环境。深入探讨AI防火墙和人工智能安全态势管理(AI-SPM),让学生掌握部署令牌过滤器、响应审核、政策执行和态势发现的知识。 课程的后续模块则专注于提示注入防御、向量存储加固和运行时沙箱化,重点介绍实用工具和设计模式,示例包括Lakera Guard、ProtectAI的Guardian、LlamaIndex和Azure AI Studio。高级模块则侧重于保护代理系统,如LangChain、AutoGen和CrewAI,同时探讨身份欺骗、签名任务链和红队策略,使用工具如PyRIT和PromptBench。 最后一模块对当前的安全生态系统进行概述,包括开源和商业产品,强调如何将MLOps与SecOps融合,以构建稳健、可审计和可扩展的GenAI系统。到课程结束时,学习者将具备评估、防御和部署企业环境中安全GenAI管道的能力。
As Generative AI becomes integral to modern business systems, ensuring its secure deployment has become a top priority. The "Generative AI Cybersecurity Solutions" course provides a comprehensive and structured deep dive into the evolving landscape of threats, controls, and security architectures specific to large language models (LLMs), agent frameworks, RAG pipelines, and AI-powered APIs. Unlike traditional cybersecurity approaches, which were built around static systems and deterministic logic, GenAI introduces new attack surfaces-including prompt injection, adversarial vector recall, plugin misuse, hallucinations, and memory poisoning-that demand a reimagined defense strategy.This course begins with an overview of foundational threats to GenAI applications, covering why traditional security frameworks fall short and introducing learners to OWASP LLM Top 10, NIST AI Risk Management Framework, OWASP MAS, and ISO 42001. Learners then explore GenAI-specific risks such as prompt abuse, embedding drift, and data exfiltration, alongside the regulatory landscape including GDPR, HIPAA, and DORA. A deep dive into AI Firewalls and AI Security Posture Management (AI-SPM) equips students with the knowledge to deploy token filters, response moderation, policy enforcement, and posture discovery. Modules on Prompt Injection Defense, Vector Store Hardening, and Runtime Sandboxing bring practical tools and design patterns into focus, using examples like Lakera Guard, ProtectAI's Guardian, LlamaIndex, and Azure AI Studio.Advanced modules focus on securing agentic systems such as LangChain, AutoGen, and CrewAI, while exploring identity spoofing, signed task chains, and red teaming strategies with tools like PyRIT and PromptBench. The final module surveys the current security ecosystem-both open-source and commercial-highlighting how MLOps and SecOps can be unified to build robust, auditable, and scalable GenAI systems. By the end, learners will be equipped to assess, defend, and deploy secure GenAI pipelines across enterprise settings.