Prompt injection and LLM application security
How injection works, why filtering fails, and the design patterns that actually contain it.
What actually changes when a model joins a system, the attacks that follow from it, and how to threat model an AI feature before you ship it.
Security for AI systems is not a new discipline so much as an old one meeting a component that behaves unlike any other: non-deterministic, persuadable, and happy to treat data as instructions.
This course sets out the landscape — what is genuinely new, what is the same as it ever was, and how to reason about an AI feature before you build it. No code; it is for anyone who has to decide whether a system is safe to ship.
4 lessons · 58 min
Instructions and data stop being separable, and the system stops being deterministic.
A shared vocabulary for the risks, and what each one actually costs when it goes wrong.
Draw the boundaries, list what crosses them, and decide what the model is allowed to reach.
Prompts, logs, providers, retrieval indexes and the fine-tune nobody audited.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
1 min read
1 min read
1 min read
1 min read
How injection works, why filtering fails, and the design patterns that actually contain it.
Access control across a retrieval index, the confused deputy problem in tool use, and keeping an agent inside its blast radius.
Attacks on models themselves: evasion, poisoning and backdoors, model theft, and what the data remembers.