AI Under Attack: A Practical Guide to Threats, Defenses, and Governance for AI Systems (Paperback)
暫譯: 《AI 受到攻擊:人工智慧系統的威脅、防禦與治理實用指南(平裝本)》

Kimmerle, Kris, Okeyode, David

  • 出版商: Packt Publishing
  • 出版日期: 2026-06-30
  • 售價: $1,890
  • 貴賓價: 9.5$1,795
  • 語言: 英文
  • 頁數: 478
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1806119935
  • ISBN-13: 9781806119936
  • 相關分類: AI Coding
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Built on Fortune 500 experience, this guide delivers hands-on methods to secure generative AI with extensive coverage of RAG, agents, prompt injection, data pipelines, Zero Trust, and sustainable programs.

Includes the AI Under Attack Practitioner Toolkit, featuring chapter-specific Field Artifacts for real-world AI security practice.

Key Features:

- Defend LLMs, RAG, and autonomous agents against prompt injection, jailbreaks, and tool abuse

- Apply Zero Trust architecture to AI agents with tool access, memory, and goal-directed reasoning

- Run AI governance and red teaming programs aligned to NIST AI RMF, ISO 42001, and OWASP for LLMs

- Purchase of the print or Kindle book includes a free PDF eBook

Book Description:

Contrary to general AI texts or cybersecurity books with limited AI coverage, this guide offers a comprehensive dive into securing the generative AI ecosystem.

It moves through four parts: Foundations establishes why AI security is fundamentally different, covering threat modeling, attack surfaces, and core defense principles. Attacks provides deep technical examination of prompt injection, memory and context abuse, RAG system vulnerabilities, agent exploitation techniques, training data poisoning, and AI red teaming methodology. Building Secure AI Systems covers infrastructure and MLOps hardening, secure application and API design, defensive prompt engineering, guardrails with human oversight, supply chain integrity, and Zero Trust architecture for agents. Running AI Security Programs addresses governance, risk and compliance frameworks, security engineering practices, security operations, and building sustainable organizational capabilities. Throughout, you will gain access to practical insights and structured approaches applicable to real-world scenarios.

By the end, you will be able to design, implement, and maintain security programs for generative AI, defend against advanced threats, communicate risks to stakeholders, and establish governance ensuring secure, compliant operations across the lifecycle.

What You Will Learn:

- Identify AI-specific risks and clearly communicate them to business teams

- Defend models, data, RAG, and agents from threats like poisoning, prompt injection, jailbreaking, and data exfiltration

- Design resilient cloud/MLOps with Zero Trust, supply chain security, and isolation

- Build secure APIs, apps, and agents with strong auth, validation, and safe tool use

- Apply AI-focused GRC, alignment checks, bias mitigation, monitoring, and incident response

- Translate complex concepts into actionable steps, using threat intel and collaboration for lasting security

Who this book is for:

This book is for mid- to senior-level cybersecurity professionals, security architects, and tech leaders managing risks in generative AI deployments. It's also valuable for early-career practitioners, AI/ML engineers, red teamers, DevSecOps, governance specialists, compliance officers, and product stakeholders with foundational cybersecurity knowledge. Readers should have basic familiarity with security concepts, some exposure to cloud platforms (AWS, Azure, or GCP), and a fundamental grasp of AI/ML, though no prior AI security expertise is required.

Table of Contents

- Why AI Security Is Different

- Threat Modeling AI Systems

- The AI Attack Surface

- Foundations of AI Defense

- Anatomy of an AI System

- Prompt Injection and Jailbreaking

- Memory, Context, and State Abuse

- Attacks on RAG Systems

- Agent Architecture and Vulnerabilities

- Agent Exploitation Techniques

- Attacks on Training Data and Model Integrity

(N.B. Please use the Read Sample option to see further chapters)

商品描述(中文翻譯)

基於《財富500強》經驗,本指南提供實用方法以確保生成式 AI 的安全,廣泛涵蓋 RAG、代理、提示注入、數據管道、零信任及可持續計劃。

包括 AI 受攻擊實務工具包,提供針對特定章節的實地文物,以便於實際的 AI 安全實踐。

主要特點:

- 防禦 LLM、RAG 和自主代理免受提示注入、越獄和工具濫用的攻擊

- 對具有工具訪問、記憶和目標導向推理的 AI 代理應用零信任架構

- 運行與 NIST AI RMF、ISO 42001 和 OWASP 對 LLM 的紅隊計劃和 AI 治理

- 購買印刷版或 Kindle 書籍可獲得免費 PDF 電子書

書籍描述:

與一般的 AI 文章或有限 AI 涵蓋的網絡安全書籍不同,本指南深入探討生成式 AI 生態系統的安全性。

本書分為四個部分:基礎部分說明為何 AI 安全本質上不同,涵蓋威脅建模、攻擊面和核心防禦原則。攻擊部分深入技術分析提示注入、記憶和上下文濫用、RAG 系統漏洞、代理利用技術、訓練數據中毒及 AI 紅隊方法論。構建安全 AI 系統涵蓋基礎設施和 MLOps 加固、安全應用和 API 設計、防禦性提示工程、具有人類監督的護欄、供應鏈完整性及代理的零信任架構。運行 AI 安全計劃則涉及治理、風險和合規框架、安全工程實踐、安全運營及建立可持續的組織能力。在整個過程中,您將獲得適用於現實場景的實用見解和結構化方法。

到最後,您將能夠設計、實施和維護生成式 AI 的安全計劃,防禦高級威脅,向利益相關者傳達風險,並建立治理以確保在整個生命週期中安全、合規的運作。

您將學到的內容:

- 識別 AI 特定風險並清晰地向業務團隊傳達

- 防禦模型、數據、RAG 和代理免受如中毒、提示注入、越獄和數據外洩等威脅

- 設計具有零信任、供應鏈安全和隔離的彈性雲/MLOps

- 構建具有強身份驗證、驗證和安全工具使用的安全 API、應用和代理

- 應用以 AI 為中心的 GRC、對齊檢查、偏見緩解、監控和事件響應

- 將複雜概念轉化為可行步驟,利用威脅情報和協作實現持久安全

本書適合誰:

本書適合中高級網絡安全專業人士、安全架構師及管理生成式 AI 部署風險的技術領導者。對於早期職業的從業者、AI/ML 工程師、紅隊成員、DevSecOps、治理專家、合規官及具備基礎網絡安全知識的產品利益相關者也非常有價值。讀者應對安全概念有基本了解,對雲平台(AWS、Azure 或 GCP)有一定接觸,並對 AI/ML 有基本認識,但不需要具備先前的 AI 安全專業知識。

目錄

- 為何 AI 安全不同

- AI 系統的威脅建模

- AI 攻擊面

- AI 防禦的基礎

- AI 系統的解剖

- 提示注入和越獄

- 記憶、上下文和狀態濫用

- 對 RAG 系統的攻擊

- 代理架構和漏洞

- 代理利用技術

- 對訓練數據和模型完整性的攻擊

(注意:請使用閱讀範本選項查看後續章節)