강의

멘토링

로드맵

AI Red Teaming 1 - Introduction to LLM Security and Hands-on Environment

For security practitioners new to LLM security, deploy a hands-on backend directly in your AWS account, witness a real model being breached, and build a foundation in AI red teaming. No installation is required, and the hands-on exercise costs no more than 1 dollar.

3 learners are taking this course

Level Beginner

Course period Unlimited

Penetration Testing
Penetration Testing
AWS
AWS
AI
AI
prompt engineering
prompt engineering
LLM
LLM
Penetration Testing
Penetration Testing
AWS
AWS
AI
AI
prompt engineering
prompt engineering
LLM
LLM

What you will gain after the course

  • The reasons AI is not assessed using existing web security methods can be explained through the structure of three real-world incidents.

  • Distinguish what hackers, penetration testers, red teams, and bug bounty hunters each do as professions.

  • I know when to use each of the four frameworks: OWASP LLM Top 10, OWASP Agentic Top 10, the AI Basic Act, and ISMS-P.

  • Deploy and delete a hands-on API Gateway + Lambda + Amazon Bedrock backend in your own AWS account with a single command.

  • Open three HTML files in the browser, submit the first natural-language query to the actual model, and capture the response.

  • Set up a cost alert and monitor your usage to keep the hands-on practice costs below $1.

Why This Course?

An in-house AI assistant read an email and sent company documents outside the organization, a coding agent deleted the production database, and a chatbot conversation sharing link was indexed by search engines. These were all real incidents that occurred in 2025, and none of them happened because the models made a mistake.

However, when tasked with assessing systems like these, you run into roadblocks in similar areas. Web diagnostic tools aren’t suited to LLMs, there are plenty of papers and news articles but no clear idea where to start, and you get exhausted setting up a practice environment.

This course starts at those three points. We cover only as much theory as needed to make judgments, and spend the rest of the time deploying a hands-on backend to your AWS account with a single command, sending questions to a real model, and seeing the same question get blocked once and slip through once.

What You’ll Be Able to Do After Completing This Course

  • The reasons AI is not assessed using existing web security methods can be explained through the structure of three real-world incidents.

  • Distinguish what hackers, penetration testers, red teams, and bug bounty hunters each do as professions.

  • You will know when and which of the four standards—OWASP LLM Top 10, OWASP Agentic Top 10, the AI Basic Act, and ISMS-P—to use.

  • Deploy an API Gateway + Lambda + Amazon Bedrock hands-on backend to your own AWS account with a single command, set up a cost alert, and delete it.

  • Send your first natural-language query to the actual model in the browser, capture the response, and submit Mission 0.

Recommended for the following people

  • Developers, security professionals, and students hearing about AI security for the first time

  • Security practitioners who have performed web vulnerability assessments but don’t know where to start with LLM assessments

  • Planners and PMs who lack a clear understanding of what risks are involved when developing or adopting AI services

  • Job seekers preparing for employment who need AI security hands-on project results to include on their resumes

▶ Visual placeholder · basic1-02-path.png - Learning paths and deliverables by target audience

This may not be suitable for the following people

  • Those looking to learn machine learning mathematics or model training methods — no mathematics is covered, and we do not build models.

  • Those looking for a list of attack payloads or bypass techniques—this series covers the basis for making determinations and does not include payloads.

  • Those who cannot create an AWS account — the practice backend will be deployed to your own account, and anyone under 18 needs a guardian’s account.

  • Those who want to complete everything from the basics to hands-on prompt injection practice in this one course — the hands-on exploitation practice begins in Lesson 4 (Intermediate 1).

Course flow — Concepts → Environment setup → First query → The moment it gets breached

15 sessions in total · 89 minutes. The section order is the learning order.

  • Section 1 · Course Introduction (1 lesson · 3 minutes · 1 preview lesson)

  • Section 2 · Part 1 · AI Security and Red Teaming: Why Now (7 lessons · 40 minutes)

  • Section 3 · Part 2 · Deploying the Practice Backend to My AWS Account (7 lessons · 46 minutes · 3 previews)

Things to Check Before Taking the Course

  • The hands-on exercises require your own AWS account and a registered payment method. A free account is sufficient, and registering a card will not result in any charges.

  • Only those aged 18 or older can create an AWS account. Middle and high school students should use a guardian’s account for the exercises.

  • Even if you complete the entire exercise, the cost will not exceed one dollar. With the default model (Amazon Nova 2 Lite), each question costs approximately 2 won, and the course covers budget alerts and the deletion procedure. The cost may vary depending on usage.

  • Nothing is installed on your PC. We only use the Chrome or Edge browser and the AWS console. Safari is not supported.

  • Some of the AWS Console scenes in Lessons 2-3, 2-4, and 2-6 are diagrams representing the procedures rather than actual screens. The menu names and order are the same.

  • The narration is a TTS voice.

▶ Visual placeholder · basic1-03-cost.png - Why running the entire exercise costs less than one dollar

Detailed Lecture Content

Part 1 · AI Security and Red Teaming: Why Now?

In Part 1, we’ll examine what it actually means for AI to be breached by looking at the structure of three real-world incidents, where the term “red team” came from, how hackers, penetration testers, red teams, and bug bounties differ from one another, and why AI security has now become a new field. We’ll also organize in one place the OWASP LLM Top 10 and Agentic Top 10, the AI Basic Act, and the four ISMS-P standards that will serve as the basis for our assessments. These four will continue to be referenced throughout the later lectures.

▶ Visual aid placeholder · basic1-01-stack.png - Four blocks from the browser to the model - one CloudFormation stack creates the two middle blocks

Part 2 · Deploying the Practice Backend in Your AWS Account

Part 2 is the hands-on environment. First, read the unfamiliar names—CloudShell, Lambda, API Gateway, and Bedrock—by comparing them to an on-premises server setup, then deploy the hands-on backend to your AWS account with a single command. The interface consists of three HTML pages opened in a browser, while the model is Amazon Bedrock in your account, so the environment remains after the course ends and all subsequent lessons run on top of it.

Mission 0 is to submit your first natural-language query and capture the screen showing the actual model’s response; the hands-on exercise is complete once you check the cost and delete the stack. In the final session, we’ll show you how the same question entered into the same document gets blocked once but slips through the next time. You’ll find out why by breaking through it yourself in Intermediate 1.

Course Structure and Learning Method

The course consists of 15 lessons totaling 89 minutes, with each lesson lasting between 5 and 7 minutes, making it ideal for watching one lesson at a time during your commute. The eight lessons in Part 1 cover concepts and can be listened to anywhere, while the seven lessons in Part 2 involve following along with the AWS Console open, so you’ll want to set aside about 20 minutes in front of a PC. Each lesson is labeled beginner, basic, or advanced, so you can choose which sections to skip. Mission 0 is designed so that simply filling out the checklist template from the resource room completes your submission.

Points where you may get stuck during the exercises have been organized by error message in the troubleshooting table in Lesson 2-6. If your issue isn’t listed there, please paste the original error message on the Q&A board.

▶ Visual placeholder · basic1-04-outcome.png - Three things you’ll take away after completing Basic 1

Next lecture

This course is the first in a seven-lesson series. In Foundations 2, you’ll learn just enough about how AI works for an attacker to know; in Foundations 3, you’ll map out a threat model using the way red teams work; and starting at the intermediate level, you’ll actually break into systems. You can choose how far to go in the learning path table in Lesson 1-1.

Course Features

  • Instead of mock screens, we use actual models in your accounts. From the very beginning, you’ll experience the nondeterminism where the answers to the same question vary.

  • Across the entire series from Mission 0 through Mission 8, the deliverables follow a single continuous numbering system.

  • The practice environment is a single CloudFormation stack, so you can deploy it with one line using deploy.sh and remove it with one line using destroy.sh.

  • We present two OWASP lists alongside domestic laws and certification standards as the basis for assessment.

  • Topics covered — An introduction to artificial intelligence (AI) security from a penetration testing and offensive security perspective, the basics of LLM operation and prompt engineering, and an AWS hands-on environment

After completing the course

By the end of the course, you’ll have three things in hand: one hands-on backend deployed in your account, a screenshot of the first query answered by a real model, and the perspective gained from seeing it get breached firsthand. There’s nothing to install; you’ll need an AWS account and a payment method, and the hands-on exercises cost no more than 1 dollar even if you run through the entire course.

Series “AI Red Teaming by Breaking In Yourself,” Lesson 7

  • AI Red Teaming 1 - Introduction to LLM Security and Hands-On Environment ← This lecture

  • AI Red Teaming 2 - How LLMs Work and the Attack Surface

  • AI Red Teaming 3 - Red Team Tasks and Threat Modeling

  • AI Red Teaming 4 - Directly Breaking Through Prompt Injection

  • AI Red Teaming 5 - The Attack Opened by One Missing Setting

  • AI Red Teaming 6 - Breaching Agents and RAG

  • AI Red Teaming 7 - Control Design and Red Team Report

The mission deliverables from the preceding lecture become the materials for the following lecture, so they are released in numerical order, and unreleased lectures will be released sequentially.

Recommended for
these people

Who is this course right for?

  • Developers, security professionals, and students hearing about AI security for the first time

  • Security practitioners who have performed web vulnerability assessments but don’t know where to start with LLM assessments

  • Planners and PMs who lack a clear understanding of what risks are involved when developing or adopting AI services

  • Job seekers preparing for employment who need AI security hands-on project results to include on their resumes

Need to know before starting?

  • No. We only use a browser and the AWS Console; there are no sessions involving reading or writing code. If you don’t have an AWS account, the course also guides you through the steps to create one.

Hello
This is rmsxodxod1289

Career Verified

I am a practitioner who started with penetration testing and builds information security management systems.

I handle annual security assessments of infrastructure, web, and applications for automotive manufacturers and energy companies.

I assessed them layer by layer and handled the same client’s ISMS-P certification through three rounds: initial, follow-up, and renewal.

I responded by independently carrying out the technical safeguards component.

Currently, as the information security officer in a one-person team, I am preparing for initial certification while establishing AI security governance.

I am designing the framework. Since this is an area where standards are still being established, starting with defining the scope of controls themselves,

It is a position where I must establish them myself.

I hold certifications as an Engineer Information Security, CPPG, and ISO/IEC 27001 Auditor, and at Dongguk University’s International Information Security Department,

I am researching leakage paths in AI environments and comparing them against authentication criteria in the Graduate School’s Department of Artificial Intelligence Security.

5 years and 9 months of experience. Client names and vulnerabilities actually discovered are subject to confidentiality, so in lectures

do not cover them in lectures.

Curriculum

All

15 lectures

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

Not enough reviews.
Please write a valuable review that helps everyone!

Similar courses

Explore other courses in the same field!