Ihr Partner für IT-Infrastruktur- und Securityschulungen seit über 20 Jahren.

Hacking AI: Attacks and Defenses for AI Systems and Infrastructure - Online Workshop

Beginn:
1. Okt 2026
Ende:
2. Okt 2026
Kurs-Nr.:
M71-26-10
Preis:
2690,00 EUR (zzgl. MwSt.)
Ort:
online
Diesen Kurs buchen
Freie Plätze:
12 von 12
Trainer:
Herr Ahmad Abolhadid
Herr Matthias Ortmann

Beschreibung

M71 - ONLINE WORKSHOP

A new two-day workshop in English.

Hacking AI: Attacks and Defenses for AI Systems and Infrastructure

Learn from the experts – Your trainers are Ahmad Abolhadid and Matthias Ortmann.

 

You can take part in the workshop from any PC, laptop or tablet with a stable internet connection. No additional software is required, a modern browser is sufficient (the latest version of Microsoft Edge, Google Chrome or Firefox). Access to the training lab is also via the browser. Exercises can therefore also be carried out without the need for additional software. The training session will, of course, be broadcast live from the ERNW studio. The workshop materials, any demos and, of course, the trainers are always visible and will be displayed or highlighted as required. We will also provide you with the training materials electronically in advance. Questions will be answered directly by the trainers. A microphone and/or camera are optional; you can also ask questions via the chat function.

 

Abstract

This training is a hands-on introduction to attacking and defending agentic AI systems and Large Language Model (LLM) applications. The training introduces various techniques of prompt injection attacks to manipulate AI behavior. As the training progresses, participants are introduced to new concepts and components, such as Guardrails and MCPs. The participants learn how to attack them, as well as how to implement them securely. The course incorporates elements of gamification, making the learning experience interactive, interesting and fun.

In addition to the offensive and defensive techniques of LLM applications, the training covers the infrastructure side of LLM systems. Using selected components from the platform powering this workshop — including model serving, chat interfaces, RAG pipelines, and API gateways — participants learn how common default configurations can be exploited and how to harden them.

The lab environment can be easily accessed from your browser. Therefore, no prior setup is needed and no previous experience in hacking is required.

 

In this workshop, you learn

Attack and defending LLM applications:

  • How LLMs work and why their architecture is inherently insecure
  • OWASP Top 10 vulnerabilities of LLM applications and AI agents
  • Direct and indirect prompt injection techniques
  • Capturing confidential data from AI applications
  • Understanding, capturing, and hardening of system prompts
  • Implementation of Guardrails to protect AI systems, as well as techniques to bypass them
  • The Model Context Protocol (MCP) and its trust model assumptions
  • Traditional vulnerabilities like SQLi and RCE in AI systems
  • Defensive patterns for LLM pipelines and MCP servers

 

Building and securing self-hosted LLM infrastructure:

  • The landscape of self-hosted LLM components
    • Model serving
    • Chat interfaces
    • RAG pipelines
    • API gateways
  •  When and why to self-host
    • Data sovereignty
    • Cost
    • Customization
    • Offline
    • Air-gapped scenarios
  • Why reproducible, declarative infrastructure matters when building on inherently non-deterministic AI systems
  • Practical self-hosting trade-offs: from single-GPU development setups to multi-node platforms
  • Securing LLM infrastructure components
    • Inference endpoints
    • Vector databases
    • Agent tools
    • Code interpreters

 

In-House Presentations

All HM Training Solutions seminars are available as in-house presentations tailored to meet the specific requirements of your organisation.

For more information please call + +49 (0) 6022 508 200.

 

What we prepared for you

  • A full AI platform, showcasing the infrastructure patterns discussed in the workshop
  • A personal lab workspace per participant with Open WebUI, a live Open WebUI Pipelines server, and more. All in the browser
  • Many hands-on exercises to practice the attack and defense techniques explained in the training
  • Deploy-Break-Harden infrastructure scenarios: real misconfigurations from self-hosted LLM components

 

Who can attend this workshop

No prior experience with LLMs or AI security is required. The workshop is practical and starts from first principles. It is a good fit for:

  • Penetration testers and red teamers who encounter LLM-integrated systems in assessments
  • Application security engineers working on AI or agentic products
  • Developers building on the OpenWebUI API or similar backends who want to understand the risks
  • Engineers and architects looking to self-host LLM infrastructure for their team or organization
  • Anyone curious about the offensive side of AI securit

 

Requirements

  • A laptop with a modern browser
  • Basic Python reading skills
  • Willingness to break thing

 

About the speakers

Ihr Trainer Friedwart KuhnYour trainer, Ahmad Abolhadid is a senior security analyst at ERNW. He has deep experience in pentesting mobile and web applications, infrastructure, and AI systems. He develops purpose-built security testing tools and enjoys creating technical trainings to share hands-on knowledge with the community. He holds a Master‘s degree in Computer and Media Engineering from Hochschule Offenburg, Germany.

 

 

 

 

 

Your trainer, Matthias Ortmann s a security consultant at ERNW, focusing on web application security, network protection, and the security of LLM-integrated systems. He holds a Master‘s degree in IT Security from TU Darmstadt. At ERNW, he performs penetration tests, develops security tooling, and architects reproducible infrastructure for AI security research and training environments — including the self-hosted LLM platform powering this workshop.

Dateien zum herunterladen


Diesen Kurs buchen: Hacking AI: Attacks and Defenses for AI Systems and Infrastructure - Online Workshop

Wenn Sie bereits registriert sind, bitte hier direkt einloggen

Einzelpreis

Teilnehmerdaten

Teilnehmeradresse

weitere Teilnehmer

Rechnungsadresse

* notwendige Angaben

Tags

Die legendäre IT-Sicherheitskonferenz „Troopers26“ findet vom 22.-26. Juni 2026 in Heidelberg statt.

Bis 30. Januar 2026 erhalten Sie Early-Bird-Tickets über den folgenden Link:

 https://troopers.de/

 

Kontakt

+49 6022 508-200
E-mail: info@hm-ts.de

HM Training Solutions
Falkenstraße 6
63820 Elsenfeld

Newsletter

Wenn Sie unsere Newsletter erhalten möchten, tragen Sie hier Ihren Daten ein.
Ich akzeptiere die Allgemeinen Geschäftsbedingungen und die Datenschutzerklärung