|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/owasp-top-10-for-llm-applications-2025/
课程评论:没有评论
课程名称:OWASP 2025年大语言模型应用安全十大风险 课程概述:大语言模型(LLMs),如GPT-4、Claude、Mistral及开源替代品,正在改变我们构建应用程序的方式。它们为聊天机器人、辅助工具、检索系统、自主代理和企业搜索提供动力,迅速成为生产力工具和客户平台的核心部分。然而,这一创新伴随着新一代风险——在传统软件架构中不存在的微妙而高影响的漏洞。我们正进入一个输入看似语言、攻击隐藏在文档中的世界,攻击者无需访问代码就可以危害您的系统。 本课程围绕2025年OWASP大语言模型应用安全十大风险构建,提供当前针对生成性人工智能系统最全面的社区验证安全框架。无论您是使用OpenAI的API、Anthropic的Claude、通过Hugging Face的开源LLM,还是在内部构建专有模型,本课程将教您如何从设计到部署保障基于LLM的架构安全。 课程内容将深入探讨最重要的漏洞,包括: - 如何通过少量恰当措辞实施提示注入攻击,从而劫持模型行为。 - 数据和模型污染如何在微调管道或向量存储中潜滋暗长。 - 敏感信息如何通过预测泄露,而不是通过代码错误。 - 模型如何被误导使用工具、调用API或消耗超出您预期的资源。 - LLM系统如何在不接触后端的情况下被抓取、克隆或操纵。 更重要的是,您将学习如何在问题发生之前预防这些风险。本课程并不是一个高层概述或枯燥的威胁列表,而是一个实用的、故事驱动的、安全聚焦的深入探讨,讲述现代LLM应用是如何失败的,以及如何构建不会失败的应用。
Large Language Models (LLMs) like GPT-4, Claude, Mistral, and open-source alternatives are transforming the way we build applications. They're powering chatbots, copilots, retrieval systems, autonomous agents, and enterprise search - quickly becoming central to everything from productivity tools to customer-facing platforms.But with that innovation comes a new generation of risks - subtle, high-impact vulnerabilities that don't exist in traditional software architectures. We're entering a world where inputs look like language, exploits hide inside documents, and attackers don't need code access to compromise your system.This course is built around the OWASP Top 10 for LLM Applications (2025) - the most comprehensive and community-vetted security framework for generative AI systems available today.Whether you're working with OpenAI's APIs, Anthropic's Claude, open-source LLMs via Hugging Face, or building proprietary models in-house, this course will teach you how to secure your LLM-based architecture from design through deployment.You'll go deep into the vulnerabilities that matter most:How prompt injection attacks hijack model behavior with just a few well-placed words.How data and model poisoning slip through fine-tuning pipelines or vector stores.How sensitive information leaks, not through bugs, but through prediction.How models can be tricked into using tools, calling APIs, or consuming resources far beyond what you intended.And how LLM systems can be scraped, cloned, or manipulated without ever touching your backend.But more importantly - you'll learn how to stop these risks before they start.This isn't a high-level overview or a dry list of threats. It's a practical, story-driven, security-focused deep dive into how modern LLM apps fail - and how to build ones that don't.