Course · Pro

LLM & RAG Red Teaming

By Wanderson Leandro de Oliveira

This course takes you from theory straight into exploitation: red teaming large language models and retrieval-augmented generation (RAG) pipelines, entirely against the DARE Vulnerable AI Suite running on your own machine. You will start with direct prompt injection — breaking a chatbot's system prompt with instruction override and extraction techniques — and then move into more advanced territory: indirect injection via documents and tool output, multi-turn payload splitting, encoding tricks, and why textual jailbreak guardrails are inherently fragile. From there the course turns to the model and data layer: training data extraction and memorization, data poisoning and backdoor concepts, and denial-of-wallet attacks that drain a target's token budget. The second half is dedicated to RAG: how ingestion, chunking, embeddings, retrieval and re-ranking actually work, where metadata filtering and tenant isolation break down, and how a poisoned document can leak a competitor tenant's secrets straight into an answer. Two lessons are fully hands-on against real, intentionally vulnerable challenges in the DARE Vulnerable AI Suite — an instruction-override chat endpoint and a multi-tenant RAG pipeline with no metadata filter — where you will capture real flags with curl and then read the exact fix. The course closes by teaching you to measure and communicate what you found: Attack Success Rate and other AI red teaming metrics, mapping findings to the OWASP LLM Top 10 and MITRE ATLAS, and writing an executive summary a non-technical stakeholder can act on.

Course content

Direct Prompt Injection

Advanced Prompt Attacks

Model and Data Vulnerabilities

RAG Architecture and Attack Surface

Exploiting a Vulnerable RAG Pipeline

Measuring and Reporting Findings