# Applied AI Security Certificate Program (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/certificates/applied-ai-security-certificate-program-self-paced>

## Overview

An AI system fails in ways an ordinary system cannot. It can be poisoned before it is ever trained, fooled after it is deployed, or talked into leaking its own data. This self-paced path treats AI as engineering rather than policy, working across the data, the model, the pipeline and the application. It starts by separating traditional cybersecurity risk from risk that is genuinely specific to AI, then follows the lifecycle from design through retirement with security gates along the way. Adversarial machine learning is the technical core — poisoning against training data, evasion against deployed models, privacy attacks aimed at training information, and model extraction — anchored to the NIST adversarial machine learning taxonomy. Generative AI is treated in its own right rather than as a footnote, covering direct and indirect prompt injection, insecure output handling, and what retrieval-augmented generation, plugins and external data sources introduce.

From there the path answers a harder question: how would you know? An AI system can be compromised without anyone touching the server it runs on, which means monitoring has to shift from whether the system is up to whether it is behaving as intended, on data it was meant to see, for purposes it was approved for. You work the four categories of AI monitoring and learn to read the signals apart — a sustained run of near-identical odd inputs looks like adversarial probing, a gradual accuracy decline looks like drift, an unexplained query spike from a single credential looks like extraction — and you learn what responders habitually lose: the model version in use, the surrounding prompt and response logs, training data lineage, the guardrail configuration in force. Severity is judged by impact on safety, rights and mission rather than by technical difficulty, on the reasoning that a wrong benefits determination caused by a data integrity failure is severe even though nothing broke. The path then pulls apart two ideas agencies routinely merge: red teaming is deliberately trying to break, mislead or misuse a system, while assurance is the documented evidence that it is trustworthy enough for its purpose. You run the engagement lifecycle, write rules of engagement — the thing that separates an exercise from an incident — and build an assurance case as claim, argument and evidence, in a shape an oversight body can audit, closing on foundation models and agentic AI, where the attack surface widens from what a system says to what a system does.

## What you'll learn

- Identify the components of an AI/ML system and distinguish models, datasets, pipelines, applications and infrastructure; Distinguish traditional cybersecurity risk from genuinely AI-specific risk; Map security considerations across the AI lifecycle from design through retirement
- Explain poisoning, evasion, privacy and model-extraction attacks, and apply defenses that increase robustness; Treat models, weights and checkpoints as protected assets, and verify provenance before deployment; Evaluate third-party models, datasets, libraries and frameworks as supply-chain dependencies
- Identify direct and indirect prompt injection, insecure output handling, and retrieval-augmented generation risk; Distinguish the four categories of AI monitoring and select the technique that fits each; Read monitoring signals and tell adversarial probing from model drift from an extraction attempt
- Preserve the evidence unique to AI incidents, including model version, prompt and response logs, and training data lineage; Classify incident severity by impact on safety, rights, mission and data rather than technical complexity
- Select containment actions specific to AI, including model rollback and disabling automated decisioning; Run a red-team engagement lifecycle from planning through reporting
- Write rules of engagement, and handle team composition and deconfliction; Weigh manual expert-driven testing against automated and tool-assisted approaches
- Tell a genuine red-team finding apart from an ordinary software bug; Build Test, Evaluation, Verification and Validation records that support a risk decision
- Construct an assurance case as claim, argument and evidence an oversight body can audit; Extend adversarial testing to foundation models and to agentic AI

## Curriculum
1. **Securing AI/ML Systems: Protecting the Intelligent Attack Surface Course (Self-Paced)**
2. **AI Red Teaming and Assurance Course (Self-Paced)**
3. **AI Security Monitoring and Incident Response Course (Self-Paced)**

## Pricing

**Tuition:** $2299
