Visão Geral
Este curso apresenta os fundamentos de segurança de Large Language Models, abordando arquitetura, riscos, proteção de dados, ataques contra modelos, segurança de aplicações e controles defensivos.
Conteúdo Programatico
Module 1: LLM Security Fundamentals
- Large Language Models
- LLM architecture
- Training and inference
- Tokens
- Context windows
- Model interfaces
- LLM application architecture
- Security attack surface
- LLM threat landscape
- LLM security principles
Module 2: LLM Threats
- Prompt Injection
- Jailbreaking
- Data leakage
- Sensitive information disclosure
- Model manipulation
- Insecure output handling
- Excessive agency
- Supply chain risks
- Model availability attacks
- LLM threat modeling
Module 3: Application Security
- LLM application architecture
- System prompts
- User prompts
- Context management
- Retrieval-Augmented Generation
- Tool calling
- External integrations
- Application permissions
- Output validation
- Secure LLM application design
Module 4: Data Security
- Training data
- Context data
- Sensitive information
- Data leakage
- Privacy
- Data minimization
- Access controls
- Data isolation
- Logging and monitoring
- Data security controls
Module 5: LLM Access and Authorization
- User authentication
- Application authentication
- API security
- Tool permissions
- Role-based access
- Least privilege
- Service identities
- Authorization boundaries
- Privileged operations
- Access security
Module 6: LLM Security Monitoring
- Prompt monitoring
- Output monitoring
- Tool usage monitoring
- Anomaly detection
- Security logging
- Abuse detection
- Incident response
- Security metrics
- LLM security testing
- Monitoring architecture
Module 7: LLM Security Governance
- AI governance
- Security policies
- Risk management
- Threat modeling
- Security assessments
- Model evaluation
- Third-party model risks
- Supply chain security
- Compliance considerations
- LLM security governance
Module 8: Practical LLM Security Assessment
- LLM threat modeling
- Application security assessment
- Prompt security assessment
- Data security assessment
- Access control review
- Tool security assessment
- Monitoring validation
- Risk assessment
- Security recommendations
- LLM security case studies