AI Red Teaming Foundations
By Wanderson Leandro de Oliveira
AI Red Teaming Foundations is the on-ramp to offensive security testing of AI systems — not a collection of exploits, but the mental model you need before a single exploit makes sense. You will learn what actually happens inside a large language model (tokens, context windows, sampling), why the line between "instructions" and "data" is the root cause of almost every prompt injection attack, and how to map the real attack surface around a modern AI application: the chatbot itself, the RAG pipeline, the agents and tools it calls, the MCP servers it talks to, the vector database behind it, and the infrastructure underneath all of it. From there, the course teaches formal threat modeling with STRIDE, attack trees and data flow diagrams, and situates two frameworks you will use constantly in this field — the OWASP Top 10 for LLM Applications and MITRE ATLAS. Every technique is framed around authorization: written scope, rules of engagement, and responsible disclosure, exactly as in traditional penetration testing, but adapted to the unique failure modes of AI systems. The final modules set up your local lab (Docker and Ollama) and introduce the DARE Vulnerable AI Suite — the hands-on target you will use in the next courses — and close with writing your first vulnerability finding and scoping a full mock assessment of a corporate chatbot. By the end, you will think like an AI red teamer even before you run your first attack.
Course content
Welcome to AI Red Teaming
- 🔒 What is (and isn't) AI red teaming text
- 🔒 Scope, rules of engagement and authorization text
- 🔒 Responsible disclosure and ethical boundaries text
How LLMs Actually Work
- 🔒 Tokens, embeddings and the context window text
- 🔒 System, developer and user prompts text
- 🔒 Temperature, sampling and non-determinism text
Where Trust Boundaries Live
- 🔒 Instructions vs. data: the confusion that breaks everything text
- 🔒 Mapping the architecture around a chatbot text
- 🔒 The attack surface checklist text
Threat Modeling for AI Systems
- 🔒 STRIDE and attack trees for LLM apps text
- 🔒 Data flow diagrams and trust boundaries text
- 🔒 OWASP LLM Top 10 and MITRE ATLAS overview text
Setting Up Your Lab
- 🔒 Docker and Ollama basics for AI red teaming text
- 🔒 Introducing the DARE Vulnerable AI Suite text
- 🔒 Your first scoped assessment text
Writing Your First Finding
- 🔒 Anatomy of a vulnerability finding text
- 🔒 Severity, impact and reproducibility text
- 🔒 Capstone: scope a corporate chatbot assessment text