AAIA Course #15: Threats and Vulnerabilities Specific to AI
StackLessons
0:00 / 0:00
AAIA Course #15: Threats and Vulnerabilities Specific to AI
10 просмотров · 12 дней назад
StackLessons
109 подписчиков
10 просмотров · 12 дней назад
Master the AI threat landscape for Domain 2 of the ISACA AAIA exam. This deep-dive covers adversarial inputs, prompt injection, data poisoning, model extraction, and privacy attacks—the attack surfaces traditional security audits never reach.
You'll learn to recognize each AI-specific attack from a scenario, distinguish between model inversion, membership inference, and extraction, and identify the testable controls an auditor can deploy. The video maps every threat to its lifecycle stage (training, inference, query) and pairs it with a defense framework, including MITRE ATLAS for AI and differential privacy.
Key Topics:
• Adversarial inputs, evasion attacks, and prompt injection (direct and indirect)
• Data poisoning, backdoors, and model poisoning—the training-time attacks
• Model extraction, inversion, and membership inference—the privacy attack trio
• Supply-chain risks and model provenance (Hugging Face trust_remote_code)
• RAG infrastructure vulnerabilities and the trusted-archive fallacy
• MITRE ATLAS framework and threat-to-control mapping
Chapters:
0:00 Introduction
1:31 Key Terms and Definitions
2:22 The Blind Spot in Traditional Security
3:59 AI Lifecycle and Attack Stages
5:28 Adversarial Inputs and Evasion
7:31 Prompt Injection Attacks
11:02 Data Poisoning and Backdoors
14:36 Privacy Attack Trio: Inversion, Inference, Extraction
20:14 Supply Chain and Model Provenance
22:09 MITRE ATLAS Framework
23:27 RAG Attack Surfaces
25:59 Threats to Testable Controls
28:14 Decision Rules and Takeaways
🔗 ISACA AAIA Exam: https://www.isaca.org/credentialing/aaia
📋 Full Playlist: https://www.youtube.com/@StackLessons...
StackLessons creates hands-on exam prep content for cloud & AI certifications. Like & Subscribe for more content!
Need more practice questions? Visit https://certcompanion.com/exams
#ISACA #AAIA #AIAudit
📌 Chapters
0:00 Introduction
1:31 Key Terms and Definitions
2:22 The Blind Spot in Traditional Security
3:59 AI Lifecycle and Attack Stages
5:28 Adversarial Inputs and Evasion
7:31 Prompt Injection Attacks
11:02 Data Poisoning and Backdoors
14:36 Privacy Attack Trio: Inversion, Inference, Extraction
20:14 Supply Chain and Model Provenance
22:09 MITRE ATLAS Framework
23:27 RAG Attack Surfaces
25:59 Threats to Testable Controls
28:14 Decision Rules and Takeaways
#ISACA #AAIA #AIThreats