AI & Data - AI Security Professional (AISP) Certification, EXIN
A practical course focused on AI Security Professional (AISP) Certification, EXIN. Participants build skills across three priorities: Securing AI within an organization, AI-specific threats, Security Controls for AI.
Detailed programme
Securing AI within an organization
- Implementation of G.U.A.R.D. steps to organize AI security.
- Responsible and trustworthy use of AI in the organization.
- Differences between conventional cybersecurity and AI security.
- Identification of specific AI assets and their key threats.
- Approach to Threat Modelling with AI Security Controls.
- Typical risks associated with AI agent.
AI-specific threats
- Types of escape according to attacker's access: zero-knowledge, partial-knowledge, perfect-knowledge, transfer attack, escape after poisoning.
- Injection of direct and indirect prompt.
- 7 layers of protection against quick injections.
- Disclosure of sensitive data in model outputs.
- Model inversion, membership inference and model exfiltration.
- Risks of resource depletion driven by inputs.
- Data poisoning and model poisoning during development.
- Direct poisoning of the model and via the supply chain (supply chain).
- Sensitive data leaks in the development phase: data, model, source code and configuration.
- Impact of conventional security threats on AI components in production.
- Direct poisoning of the model at execution and associated leaks.
- Injection integrated into AI outputs and data leak input.
- Escape and manipulation of augmentation data.
Security Controls for AI
- General governance controls for AI security oversight.
- Coverage and scope of governance controls.
- Distribution of responsibilities between the third-party model provider and the user organization (ready-to-use model).
- Implementation of controls to limit sensitive data and enhance confidentiality and integrity.
- Understanding how limiting sensitive data reduces risks.
- Controls to limit effects.
- Improved performance and reduced risk of undesirable behaviour of the business model.
Security Tests for AI
- Importance and scope of AI security tests.
- Differences with conventional security tests.
- Threats to be tested specifically for predictive and generative systems.
- General testing strategies applied to AI safety.
Privacy, Compliance, and Regulation
- Confidentiality principles applied to AI systems.
- Privacy Concerns in AI Uses.
- Contribution of ISO/IEC 23894, ISO/IEC 27005, ISO/IEC 42001 and ISO/IEC 5338 to AI regulatory compliance.
- Compliance issues related to the AI Act and the GDPR.
- Risks of copyright infringement and mitigation strategies.
Tell us about your project
Our offices
- Exceev Consulting
61 Rue de Lyon
75012, Paris, France - Exceev Technology
332 Bd Brahim Roudani
20330, Casablanca, Morocco