Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

Bare Metal Cyber · Free, ad-free audio course

AI Security

A focused course on the risks, controls, governance questions, and defensive practices that surround modern AI systems.

Every Bare Metal Cyber audio course is free and 100% ad-free.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

50 lessons available

S01E01Transcript

Architecture, Trust Boundaries and Data Security

Course Overview & How to Use This Prepcast

This opening episode provides a structured orientation to the AI Security and Threats Audio course series, helping listeners understand what the program covers and how to best engage with the material.…

Transcript availableSeptember 15, 2025
S01E02Transcript

Architecture, Trust Boundaries and Data Security

The AI Security Landscape

This episode defines the AI security landscape by mapping the assets, attack surfaces, and emerging threats that distinguish AI from classical application security.…

Transcript availableSeptember 15, 2025
S01E03Transcript

Architecture, Trust Boundaries and Data Security

System Architecture & Trust Boundaries

This episode explains the architecture of AI systems, breaking down their stages and components to show how trust boundaries shift across the lifecycle.…

Transcript availableSeptember 15, 2025
S01E04Transcript

Architecture, Trust Boundaries and Data Security

Data Lifecycle Security

This episode examines data lifecycle security, covering the journey of data from collection and labeling through storage, retention, deletion, and provenance management.…

Transcript availableSeptember 15, 2025
S01E05Transcript

AI Attacks, Privacy, RAG and Agent Controls

Prompt Security I: Injection & Jailbreaks

This episode introduces prompt injection and jailbreaks as fundamental AI-specific security risks. It defines prompt injection as malicious manipulation of model inputs to alter behavior and describes jailbreaks as methods for bypassing built-in safeguards.…

Transcript availableSeptember 15, 2025
S01E06Transcript

AI Attacks, Privacy, RAG and Agent Controls

Prompt Security II: Indirect & Cross-Domain Injections

This episode examines indirect and cross-domain prompt injections, which expand the attack surface by embedding malicious instructions in external sources such as documents, websites, or email content.…

Transcript availableSeptember 15, 2025
S01E07Transcript

AI Attacks, Privacy, RAG and Agent Controls

Content Safety vs. Security

This episode explains the distinction and overlap between content safety and security in AI systems, a concept often emphasized in both professional practice and certification exams.…

Transcript availableSeptember 15, 2025
S01E08Transcript

AI Attacks, Privacy, RAG and Agent Controls

Data Poisoning Attacks

This episode introduces data poisoning as a high-priority threat in AI security, where adversaries deliberately insert malicious samples into training or fine-tuning datasets.…

Transcript availableSeptember 15, 2025
S01E09Transcript

AI Attacks, Privacy, RAG and Agent Controls

Training-Time Integrity

This episode covers training-time integrity, focusing on the assurance that data, processes, and infrastructure used in model development remain uncompromised.…

Transcript availableSeptember 15, 2025
S01E10Transcript

AI Attacks, Privacy, RAG and Agent Controls

Privacy Attacks

This episode introduces privacy attacks in AI systems, focusing on techniques that reveal sensitive or personal information from training data or model behavior.…

Transcript availableSeptember 15, 2025
S01E11Transcript

AI Attacks, Privacy, RAG and Agent Controls

Privacy-Preserving Techniques

This episode explores privacy-preserving techniques designed to reduce the risk of sensitive information exposure in AI systems while maintaining utility of the models.…

Transcript availableSeptember 15, 2025
S01E12Transcript

AI Attacks, Privacy, RAG and Agent Controls

Model Theft & Extraction

This episode addresses model theft and extraction, highlighting how adversaries can replicate or steal valuable AI models.…

Transcript availableSeptember 15, 2025
S01E13Transcript

AI Attacks, Privacy, RAG and Agent Controls

Adversarial Evasion

This episode introduces adversarial evasion, a class of attacks in which maliciously crafted inputs cause AI systems to misclassify or behave incorrectly.…

Transcript availableSeptember 15, 2025
S01E14Transcript

AI Attacks, Privacy, RAG and Agent Controls

RAG Security I: Retrieval & Index Hardening

This episode explores retrieval-augmented generation (RAG) security, focusing on retrieval and index hardening as foundational defenses. RAG combines language models with external document retrieval, which improves factual grounding but introduces risks.…

Transcript availableSeptember 15, 2025
S01E15Transcript

AI Attacks, Privacy, RAG and Agent Controls

RAG Security II: Context Filtering & Grounding

This episode continues exploration of RAG security by examining context filtering and grounding as defenses for reliable outputs.…

Transcript availableSeptember 15, 2025
S01E16Transcript

AI Attacks, Privacy, RAG and Agent Controls

Agents as an Attack Surface

This episode introduces AI agents as a new and growing attack surface, highlighting how their autonomy and tool integration create unique risks.…

Transcript availableSeptember 15, 2025
S01E17Transcript

AI Attacks, Privacy, RAG and Agent Controls

Secrets & Credential Hygiene

This episode addresses secrets and credential hygiene, emphasizing their critical role in preventing leaks and privilege misuse in AI systems. Secrets include API keys, tokens, passwords, and configuration values embedded in prompts or environments.…

Transcript availableSeptember 15, 2025
S01E18Transcript

AI Attacks, Privacy, RAG and Agent Controls

AuthN/Z for LLM Apps

This episode explores authentication (AuthN) and authorization (AuthZ) for large language model (LLM) applications, highlighting their importance in managing identities and permissions.…

Transcript availableSeptember 15, 2025
S01E19Transcript

AI Attacks, Privacy, RAG and Agent Controls

Output Validation & Policy Enforcement

This episode examines output validation and policy enforcement as mechanisms for controlling what AI systems produce before results are delivered to users or downstream processes.…

Transcript availableSeptember 15, 2025
S01E20Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Red Teaming Strategy for GenAI

This episode introduces red teaming as a structured method for probing generative AI systems for vulnerabilities, emphasizing its importance for both exam preparation and real-world resilience.…

Transcript availableSeptember 15, 2025
S01E21Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Evals & Test Pipelines

This episode examines evaluations and test pipelines as essential processes for maintaining AI system security and reliability.…

Transcript availableSeptember 15, 2025
S01E22Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Telemetry & Observability

This episode explores telemetry and observability, emphasizing their importance in detecting anomalies, intrusions, and misuse in AI systems.…

Transcript availableSeptember 15, 2025
S01E23Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Abuse & Fraud Detection

This episode addresses abuse and fraud detection in AI applications, focusing on how adversaries exploit systems for spam, phishing, or marketplace manipulation.…

Transcript availableSeptember 15, 2025
S01E24Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Cost & Resource Abuse

This episode examines cost and resource abuse, where adversaries or careless users exploit AI systems to drive up compute expenses or deny service to legitimate customers.…

Transcript availableSeptember 15, 2025
S01E25Transcript

Testing, Monitoring, Infrastructure and Supply Chain

MLOps & Serving Security

This episode introduces MLOps and serving security, focusing on practices that protect the deployment, operation, and continuous delivery of AI models. MLOps extends DevOps principles to AI, requiring controls for model registries, CI/CD pipelines, and serving infrastructure.…

Transcript availableSeptember 15, 2025
S01E26Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Supply Chain & Artifacts

This episode examines supply chain and artifact security, focusing on how external dependencies and stored components create systemic risks in AI systems.…

Transcript availableSeptember 15, 2025
S01E27Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Secure Fine-Tuning & Adaptation

This episode introduces secure fine-tuning and adaptation, explaining how customization of pre-trained models introduces both benefits and new risks.…

Transcript availableSeptember 15, 2025
S01E28Transcript

Testing, Monitoring, Infrastructure and Supply Chain

API Gateways & Proxies for AI

This episode focuses on API gateways and proxies, emphasizing their role as critical control points for AI applications. An API gateway manages traffic to model endpoints, providing authentication, authorization, rate limiting, and policy enforcement.…

Transcript availableSeptember 15, 2025
S01E29Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Code Execution & Sandboxing

This episode examines the risks of code execution in AI systems and the security benefits of sandboxing. Many AI applications incorporate features allowing generated or user-provided code to run, enabling advanced analysis, automation, or integration with development environments.…

Transcript availableSeptember 15, 2025
S01E30Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Connector/Plugin Security

This episode addresses connector and plugin security, focusing on how third-party integrations expand the attack surface of AI applications. Connectors link systems to external data or services, while plugins extend model functionality by calling APIs or executing tasks.…

Transcript availableSeptember 15, 2025
S01E31Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Cloud & Infra for AI

This episode explores cloud and infrastructure security in the context of AI, focusing on GPU clusters, multitenancy, storage, and network isolation.…

Transcript availableSeptember 15, 2025
S01E32Transcript

Testing, Monitoring, Infrastructure and Supply Chain

Keys, Encryption & Attestation

This episode examines keys, encryption, and attestation as core mechanisms for ensuring confidentiality, integrity, and trust in AI systems.…

Transcript availableSeptember 15, 2025
S01E33Transcript

Governance, Frameworks and Program Operations

Governance & Acceptable Use

This episode introduces governance and acceptable use policies as organizational frameworks that guide secure and ethical AI adoption.…

Transcript availableSeptember 15, 2025
S01E34Transcript

Governance, Frameworks and Program Operations

Risk Frameworks in Practice

This episode examines risk frameworks for AI security, focusing on the NIST AI Risk Management Framework and ISO/IEC 42001. These frameworks provide structured approaches to identify, assess, mitigate, and monitor AI-specific risks across technical and organizational domains.…

Transcript availableSeptember 15, 2025
S01E35Transcript

Governance, Frameworks and Program Operations

Threat Modeling for AI

This episode covers threat modeling as a structured method for identifying and prioritizing risks in AI systems.…

Transcript availableSeptember 15, 2025
S01E36Transcript

Governance, Frameworks and Program Operations

OWASP GenAI/LLM Top 10

This episode introduces the OWASP GenAI/LLM Top 10, a structured list of the most critical risks associated with generative AI and large language models.…

Transcript availableSeptember 15, 2025
S01E37Transcript

Governance, Frameworks and Program Operations

Secure SDLC for AI

This episode examines the secure software development lifecycle (SDLC) for AI, emphasizing integration of security at each stage of system creation.…

Transcript availableSeptember 15, 2025
S01E38Transcript

Governance, Frameworks and Program Operations

Incident Response for AI Events

This episode addresses incident response for AI-specific security events, focusing on structured detection, containment, and remediation.…

Transcript availableSeptember 15, 2025
S01E39Transcript

Governance, Frameworks and Program Operations

Deepfakes & Synthetic Media Risk

This episode explores the risks of deepfakes and synthetic media, examining how generative AI enables the creation of realistic but deceptive audio, video, and images.…

Transcript availableSeptember 15, 2025
S01E40Transcript

Governance, Frameworks and Program Operations

Content Provenance & Watermarking

This episode examines content provenance and watermarking as methods to authenticate AI-generated or human-created content, providing assurance of originality and integrity.…

Transcript availableSeptember 15, 2025
S01E41Transcript

Governance, Frameworks and Program Operations

Legal & Compliance Horizon (High-Level)

This episode introduces the legal and compliance horizon for AI security, giving learners a high-level view of regulatory landscapes without overwhelming them with acronyms.…

Transcript availableSeptember 15, 2025
S01E42Transcript

Governance, Frameworks and Program Operations

Third-Party & Vendor Risk

This episode explores third-party and vendor risk management in AI security, focusing on the challenges of relying on external providers for models, datasets, APIs, and infrastructure.…

Transcript availableSeptember 15, 2025
S01E43Transcript

Governance, Frameworks and Program Operations

Enterprise Architecture Patterns

This episode examines enterprise architecture patterns for secure AI deployments, focusing on how organizations structure systems to balance scalability, performance, and resilience.…

Transcript availableSeptember 15, 2025
S01E44Transcript

Governance, Frameworks and Program Operations

People & Process

This episode focuses on people and process as integral elements of AI security, highlighting how organizational culture and defined responsibilities reinforce technical defenses.…

Transcript availableSeptember 15, 2025
S01E45Transcript

Governance, Frameworks and Program Operations

Program Management Patterns (30/60/90)

This episode introduces program management patterns for phased AI security adoption, with emphasis on the 30/60/90-day framework.…

Transcript availableSeptember 15, 2025
S01E46Transcript

Emerging AI Security Engineering

Multimodal & Cross-Modal Security

This episode introduces multimodal and cross-modal security, focusing on AI systems that process images, audio, video, and text simultaneously.…

Transcript availableSeptember 15, 2025
S01E47Transcript

Emerging AI Security Engineering

On-Device & Edge AI Security

This episode examines on-device and edge AI security, focusing on models deployed in mobile, IoT, or embedded systems where resources are constrained and connectivity may be intermittent.…

Transcript availableSeptember 15, 2025
S01E48Transcript

Emerging AI Security Engineering

Guardrails Engineering

This episode covers guardrails engineering, emphasizing the design of policy-driven controls that prevent unsafe or unauthorized AI outputs. Guardrails include policy domain-specific languages (DSLs), prompt filters, allow/deny lists, and rejection tuning mechanisms.…

Transcript availableSeptember 15, 2025
S01E49Transcript

Emerging AI Security Engineering

Confidential Computing for AI

This episode introduces confidential computing as an advanced safeguard for AI workloads, focusing on hardware-based protections such as trusted execution environments (TEEs), secure enclaves, and encrypted inference.…

Transcript availableSeptember 15, 2025
S01E50Transcript

Emerging AI Security Engineering

Automated Adversarial Generation

This episode examines automated adversarial generation, where AI systems are used to create adversarial examples, fuzz prompts, and continuously probe defenses.…

Transcript availableSeptember 15, 2025

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Follow the course with your own notes and use the related Cyber Wiki entries for additional context.

03

Review

Return to difficult lessons and search the site for related concepts, examples, and explanations.