NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

Academy/Reading Materials

AIPSA Learning Library

Reading Materials

Chapter-level PDFs across three publications — the AIPSA Handbook, Field Guide, and Mythos Report. Each chapter maps to one or more lab domains. Use them before, during, or after labs.

15 Handbook chapters
14 Field Guide chapters
8 Mythos selections

15 Chapters · Practice-oriented

AIPSA Handbook

Deep-dive reference for practitioners. Each chapter covers a specific skill area with methodology, worked examples, and templates — aligned directly with lab exercises.

Ch 12.2 MB

Chapter 1 — AI System Inventory

Map your AI assets, establish component boundaries, classify data flows, and build the inventory foundation that all downstream security controls depend on.

Open PDF ↗
Ch 23.7 MB

Chapter 2 — Architecture and Trust Boundaries

Design secure AI system architectures with enforced trust boundaries, identity controls, data isolation, and defense-in-depth across the full AI stack.

Open PDF ↗
Ch 34.6 MB

Chapter 3 — Threat Modeling

Apply STRIDE to AI product surfaces, enumerate trust boundaries, map threats to mitigations, and produce architecture decision records.

Open PDF ↗
Ch 44.7 MB

Chapter 4 — Prompt Injection

Direct and indirect injection attack patterns, instruction hierarchy exploitation, context poisoning, and realistic mitigations beyond prompt wording.

Open PDF ↗
Ch 53.4 MB

Chapter 5 — RAG Authorization

Authorization across ingest and query layers, tenant isolation, cross-tenant leakage vectors, document poisoning, and retrieval auditability.

Open PDF ↗
Ch 64.9 MB

Chapter 6 — Agentic Permissions

Tool-call security, delegated authority, approval gates, side-effect containment, MCP surface analysis, sandboxing, and action logging for AI agents.

Open PDF ↗
Ch 72.2 MB

Chapter 7 — Data Exposure and Privacy

PII in prompt and retrieval context, cross-tenant data leakage, training data exposure, prompt log privacy, data minimization, and retention controls.

Open PDF ↗
Ch 82.2 MB

Chapter 8 — Model and Provider Risk

Evaluating model providers, subprocessors, data processing terms, trust center claims, security questionnaires, and procurement decision criteria.

Open PDF ↗
Ch 93.0 MB

Chapter 9 — AI Supply Chain

Model artifact risks, unsafe deserialization, model hub provenance, dependency trust, artifact signing, AI BOM concepts, and third-party model integration risk.

Open PDF ↗
Ch 102.2 MB

Chapter 10 — Logging and Telemetry

Prompt/response/tool-call log requirements, trace correlation, PII-safe telemetry, abuse monitoring signal design, and the minimum log surface for AI forensics.

Open PDF ↗
Ch 112.3 MB

Chapter 11 — Detection Engineering

Building detectors for prompt injection, jailbreaks, credential exposure, anomalous tool calls, and AI-specific abuse patterns using telemetry pipelines.

Open PDF ↗
Ch 122.3 MB

Chapter 12 — Incident Response

AI incident classification, containment playbooks, prompt/tool-call forensics, rollback procedures, customer notification, and post-incident control improvements.

Open PDF ↗
Ch 132.9 MB

Chapter 13 — Evaluation and Regression Testing

Eval harness design, jailbreak regression suites, abuse-case test coverage, model/application boundary testing, and how eval output becomes security evidence.

Open PDF ↗
Ch 144.3 MB

Chapter 14 — Governance, Evidence, and Customer Trust

AI governance operating model, risk registers, control evidence collection, NIST AI RMF and ISO 42001 mapping, and producing audit-ready customer trust artifacts.

Open PDF ↗
Ch 152.6 MB

Chapter 15 — Field Kit and Templates

Reference templates for AI system inventory, threat models, control matrices, evidence collection, vendor questionnaires, and incident response playbooks.

Open PDF ↗

14 Chapters · Domain-mapped

AIPSA Field Guide

One chapter per AIPSA domain — concise, field-ready reference covering the concepts, vocabulary, and decision frameworks you need for each competency area.

Ch 1~2 MB

AI Security Foundations

Core concepts for reasoning about AI systems as software, data, model, platform, and governance systems — and why AI security is not only model safety.

Open PDF ↗
Ch 2~2 MB

LLM Application Security

Security of applications that call, wrap, orchestrate, or expose LLMs — input/output boundaries, model provider APIs, prompt construction, tool access, and output handling.

Open PDF ↗
Ch 3~2 MB

Prompt Injection and Context Security

Direct and indirect prompt injection, instruction hierarchy, context poisoning, system prompt exposure, and mitigations beyond prompt wording.

Open PDF ↗
Ch 4~2 MB

RAG Security

RAG authorization, cross-tenant leakage, vector database exposure, document poisoning, citation trust, and retrieval auditability.

Open PDF ↗
Ch 5~2 MB

Agent Security

Delegated authority, tool calls, MCP-style tool surfaces, approvals, side effects, action logging, sandboxing, and agentic workflow governance.

Open PDF ↗
Ch 6~2 MB

Model Supply Chain Security

Model artifacts, unsafe deserialization, model hub provenance, dependency trust, model scanning, artifact signing, and third-party model risk.

Open PDF ↗
Ch 7~2 MB

MLOps Platform Security

Security of notebooks, experiment tracking, model registries, pipelines, GPUs, containers, inference services, cloud IAM, secrets, and CI/CD for AI platforms.

Open PDF ↗
Ch 8~2 MB

AI-Aware Secure SDLC

Secure lifecycle practices for AI-enabled products: intake, threat modeling, design review, eval gates, release criteria, logging requirements, and control evidence.

Open PDF ↗
Ch 9~2 MB

Privacy and Data Protection in AI Systems

Customer data usage, training policy, retention, prompt/log privacy, PII redaction, data minimization, data residency, and privacy controls for AI systems.

Open PDF ↗
Ch 10~2 MB

AI Governance, Risk, and Compliance

AI governance operating model, risk registers, control mapping, NIST AI RMF, ISO 42001, policy, accountability, approvals, evidence collection, and audit-ready reporting.

Open PDF ↗
Ch 11~2 MB

Red Teaming and Adversarial Evaluations

AI red teaming, eval harnesses, jailbreak testing, prompt injection test design, abuse-case testing, regression testing, and interpreting eval limits.

Open PDF ↗
Ch 12~2 MB

Incident Response and AI Observability

AI incident detection, prompt/response/tool-call logs, traceability, abuse monitoring, alerting, forensics, containment, rollback, and post-incident learning.

Open PDF ↗
Ch 13~2 MB

Vendor Risk and AI Procurement

Evaluating AI vendors, model providers, subprocessors, data processing terms, security questionnaires, contract controls, trust center claims, and procurement decisions.

Open PDF ↗
Ch 14~2 MB

Secure AI Architecture Design

End-to-end design of secure AI systems: trust boundaries, identity, data flows, isolation, runtime controls, safe defaults, defense-in-depth, and tradeoff reasoning.

Open PDF ↗

Strategic context · Not curriculum-aligned

Mythos Report — Selected Chapters

Eight chapters from the Mythos threat intelligence report with direct relevance to specific domains. Strategic framing for why the technical controls matter.

Ch 6~1 MB

Inventory Is the First Control

Why you cannot defend what you have not mapped — the argument for AI system inventory as the prerequisite for every other control.

Open PDF ↗
Ch 7~1 MB

Threat Modeling Becomes Continuous

The case for continuous threat modeling in AI products: why static annual reviews fail and how to build threat modeling into engineering velocity.

Open PDF ↗
Ch 8~1 MB

Prompt Injection Is a Product Security Bug

Reframing prompt injection from a model safety problem to a product security control-boundary failure — with ownership, remediation, and release criteria implications.

Open PDF ↗
Ch 9~1 MB

Excessive Agency Is the New Overprivileged Service Account

Drawing the direct line from classic least-privilege failures to agentic AI: why scope, approval gates, and blast radius matter more as agents gain capabilities.

Open PDF ↗
Ch 11~1 MB

RAG and Context Systems Are Data Security Systems

The argument that retrieval systems must be governed as data access control systems — not just prompt augmentation layers — with all the authorization implications that follow.

Open PDF ↗
Ch 12~1 MB

Model, Code, and AI Supply Chain Security

How supply chain risk expands when the artifact is not just code but model weights, serialized configs, and datasets — and what AI BOM and provenance checks require.

Open PDF ↗
Ch 13~1 MB

The New AppSec Metric Is Time to Evidence

Why the most important AI security KPI is how quickly your team can produce control evidence — and what that means for tooling, process, and team structure.

Open PDF ↗
Ch 14~1 MB

Governance Without Velocity Is Theater

The argument that AI governance programs that slow down engineering without improving risk posture are actively counterproductive — and what high-velocity governance looks like.

Open PDF ↗