Core
Adversarial AI: Penetration Testing AI Systems
Testing an AI system is not like testing a web application, and this adversarial AI training in Toronto teaches the difference. You will learn a repeatable methodology for penetration testing models and the applications around them.
The work covers prompt injection and jailbreaks, training data extraction, and model theft, all inside the academy's isolated lab against systems you are authorized to test. You also learn to report findings that are probabilistic rather than a clean pass or fail.
- Duration
- 6 weeks
- Format
- Live online, instructor-led
- Prerequisites
- AI Security Principles and Practices: GenAI and LLM Defence
- Class size
- Capped at 12 learners

What you will be able to do
- Scope and plan a penetration test of an AI system
- Run direct and indirect prompt injection methodically
- Attempt training data extraction and model theft in the lab
- Test guardrails and measure how reliably they hold
- Rate findings that are probabilistic rather than binary
- Write an AI penetration test report a developer can act on
Course outline
5 modules
- Non-determinism and why one test is not enough
- The AI attack surface: model, prompt, data, tools
- Scoping and authorization for AI targets
- Setting up a safe testing harness
What you need before you start
- You have completed AI Security Principles and Practices or equivalent
- You have some penetration testing or application security background
- You can use an API and read simple scripts
- You accept that all testing is authorized and lab-confined
Who this course is for
- Penetration testers extending into AI systems
- Application security engineers whose products now include AI
- AI and ML engineers who want to test their own systems
- Security consultants asked to assess AI features
Questions about this course
More in ai security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



