|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/owasp-genai-red-teaming-complete-guide/
课程评论:没有评论
课程名称:OWASP GenAI红队完全指南 概述:本课程全面教授OWASP GenAI红队的测试与安全知识,旨在让学习者掌握实践与战略技能,以确保生成式人工智能系统的安全性。课程从基础概念入手,介绍生成式人工智能生态系统、大型语言模型(LLM)以及红队的重要性,帮助识别安全性、可靠性和信任问题。课程将GenAI红队与传统方法进行对比,强调不同模型架构、用户界面和实际应用中风险的演变。 通过深入的风险分类,学生将探索OWASP和NIST风险类别、STRIDE建模、MITRE ATLAS战术以及社会技术框架RAG三元组。课程映射了大型语言模型、智能体和多模态输入的关键攻击面,并关联到新兴威胁向量。接着,课程提出了一个结构化的红队蓝图,引导学习者开展范围确定、评估生命周期,并定义成功与脆弱性的衡量标准。 高级模块深入探讨提示注入、越狱攻击、对抗性提示设计、多轮利用和偏见评估技术。学生还将评估模型的脆弱性,诸如幻觉现象、文化不敏感性和对齐绕过等问题。实施级别风险通过内容过滤器、提示防火墙、RAG向量操控和访问控制滥用等测试进行分析。 系统级模块审查沙箱逃逸、API攻击、日志缺陷和供应链完整性。学习者还会接触到运行时和智能体风险,如过度信任、社会工程、多智能体操控和可追溯性崩溃。实践工具课程包括使用PyRIT、PromptBench进行红队行动、自动化工作流和行动手册设计。 最后,课程探讨运营成熟度,展示如何建立跨职能红队,将角色与RACI矩阵对齐,并在合规和文化界限内应用红队理念。通过案例驱动的教学和安全设计思维,本课程为学习者在技术和治理层面实施GenAI红队提供了充分的准备。
This comprehensive course on OWASP GenAI Red Teaming Complete Guide equips learners with practical and strategic expertise to test and secure generative AI systems. The curriculum begins with foundational concepts, introducing learners to the generative AI ecosystem, large language models (LLMs), and the importance of red teaming to uncover security, safety, and trust failures. It contrasts GenAI red teaming with traditional methods, highlighting how risks evolve across model architectures, human interfaces, and real-world deployments. Through in-depth risk taxonomy, students explore OWASP and NIST risk categories, STRIDE modeling, MITRE ATLAS tactics, and socio-technical frameworks like the RAG Triad. Key attack surfaces across LLMs, agents, and multi-modal inputs are mapped to emerging threat vectors. The course then presents a structured red teaming blueprint-guiding learners through scoping engagements, evaluation lifecycles, and defining metrics for success and brittleness. Advanced modules dive into prompt injection, jailbreaks, adversarial prompt design, multi-turn exploits, and bias evaluation techniques. Students also assess model vulnerabilities such as hallucinations, cultural insensitivity, and alignment bypasses. Implementation-level risks are analyzed through tests on content filters, prompt firewalls, RAG vector manipulation, and access control abuse. System-level modules examine sandbox escapes, API attacks, logging gaps, and supply chain integrity. Learners are also introduced to runtime and agentic risks like overtrust, social engineering, multi-agent manipulation, and traceability breakdowns. Practical tooling sessions feature hands-on red teaming with PyRIT, PromptBench, automation workflows, and playbook design. Finally, the course addresses operational maturity-showing how to build cross-functional red teams, align roles with RACI matrices, and apply red teaming within regulatory and cultural boundaries. With case-driven instruction and security-by-design thinking, this course prepares learners to operationalize GenAI red teaming at both the technical and governance levels.