2-Day Course
Intermediate · 2-Day

AI Threat Modeling and Secure Architecture

Design AI systems that are secure before a line ships. Threat model agents, RAG and pipelines against AISVS.

Code ARCH-531 2-Day course Level Intermediate
Threat Modeling Reference Architecture
You will be able to

What you can do after the course

ARCH-531. The syllabus

AI Threat Modeling and Secure Architecture

Two-day instructor-led course. Module order and grouping can be adjusted for private deliveries.

AI Threat Modeling Fundamentals

Why AI needs its own threat model

160-00 Why Traditional Threat Modeling Misses AI Threats 1.5 hr

Why STRIDE, PASTA and other traditional threat modeling methods miss the threats that are unique to AI systems. You study the categories of AI-specific threat that do not map cleanly to spoofing, tampering or information disclosure, and you learn where the traditional methods need to be extended or replaced.

160-01 The AI Threat Surface 1.5 hr

Mapping the full AI threat surface across data, model, inference, tools, agents and memory. You draw the threat surface for a representative AI system and identify every component that an attacker can reach, from training data through the model weights to the tools the model calls and the memory it reads from.

160-02 Building an AI-Specific Threat Model 1 hr

Building a threat model that covers AI-specific threats from scratch. You work through scope definition, asset identification, threat enumeration and risk ranking for an AI system, producing a threat model that addresses prompt injection, model poisoning, tool abuse and data leakage alongside traditional application threats.

160-03 MITRE ATLAS as a Threat Library 1 hr

Using MITRE ATLAS as a structured library of adversary tactics and techniques for AI systems. You navigate the ATLAS matrix, map its techniques to your threat model and use it to identify threats you might have missed during your own enumeration.

Threat Modeling AI Components

Component-level threat models

161-00 Threat Modeling LLM Integrations 1 hr

Threat modeling an application that integrates an LLM. You identify the trust boundaries between your application code and the model, enumerate the threats at each boundary and document the controls needed to keep prompt injection, data leakage and unsafe output from reaching the user.

161-01 Threat Modeling RAG Pipelines 1 hr

Threat modeling a retrieval-augmented generation pipeline. You trace the path from document ingestion through embedding and retrieval to context assembly, identify the poisoning, injection and leakage threats at each stage and map the controls that defend each one.

161-02 Threat Modeling Agent Systems 1 hr

Threat modeling a system where the model can call tools and take actions. You identify the threats introduced by tool use, including confused deputy, parameter injection and excessive authority, and you design the controls that keep each tool call within its intended scope.

161-03 Threat Modeling MCP Deployments 1 hr

Threat modeling a deployment that uses the Model Context Protocol. You identify the MCP-specific attack surface including server impersonation, tool poisoning and context injection, and you map the controls from MCPS that address each threat.

161-04 Threat Modeling Multi-Agent Architectures 1 hr

Threat modeling a multi-agent system where multiple agents communicate, delegate and share state. You identify the threats that multiply with every agent you add, including trust propagation, authority laundering and injection that cascades across agents, and you design the controls that contain each one.

AISVS Reference Architectures

Secure patterns mapped to controls

162-00 Reference Architecture for a Secure LLM Application 1.5 hr

A reference architecture for building a secure LLM application with controls already placed on the diagram. You study the architecture, understand where each control sits and why, and learn how to adapt the pattern for your own application while keeping the security properties intact.

162-01 Reference Architecture for a Secure RAG Pipeline 1 hr

A reference architecture for a secure RAG pipeline covering ingestion, embedding, retrieval and generation. You study how tenant isolation, provenance tracking and retrieval filtering are built into the architecture from the start rather than added as afterthoughts.

162-02 Reference Architecture for a Secure Agent Estate 1 hr

A reference architecture for running a secure agent estate with per-agent identity, scoped delegation and kill switches. You study how agent-to-agent trust, tool authorisation and blast radius containment are designed into the architecture.

162-03 Mapping Architectures to AISVS Controls 1 hr

Mapping each reference architecture to the AISVS control families it satisfies. You produce a control mapping for each architecture that shows which AISVS requirements are met, which are partially met and which need additional work, so you can demonstrate compliance to an auditor.

Secure Design Patterns

The patterns that prevent common mistakes

163-00 Defence in Depth for AI 1 hr

Applying defence in depth to AI systems so no single control is a single point of failure. You layer training-time alignment, input validation, output encoding, tool authorisation and monitoring so an attacker who bypasses one layer still faces the next.

163-01 Least Privilege for Agents 1 hr

Giving each agent only the permissions it needs and revoking them the moment they are no longer required. You design permission models that scope each agent's access to the minimum required for its current task and prevent authority from accumulating across tasks.

163-02 Fail-Closed Design 1 hr

Designing AI systems that fail closed when something goes wrong. You study the failure modes that lead to open-fail conditions where the model, the guardrail or the tool authorisation defaults to permissive, and you redesign each one so the system stops rather than proceeding unsafely.

163-03 Secure Defaults 1 hr

Setting secure defaults that prevent the common architectural mistakes teams make when they build AI systems quickly. You review the most frequent insecure defaults in LLM integrations, RAG pipelines and agent systems, and you set the configuration that makes the safe choice the easy choice.

Labs

Hands-on threat modeling and architecture labs

164-00 Threat Model Lab 2.5 hr

A structured lab where you build a complete AI threat model for a provided system. You identify assets, draw trust boundaries, enumerate threats using MITRE ATLAS, rank risks and produce a threat model document that you can take back to your organisation and apply to your own systems.

164-01 Architecture Review Lab 2 hr

A hands-on lab where you review a provided AI architecture against the threat model and the AISVS controls. You identify gaps, propose mitigations and produce an architecture review report with findings and recommendations.

164-02 Design Patterns Lab 1.5 hr

A lab focused on applying secure design patterns to a flawed architecture. You take a system that was built without security controls, apply defence in depth, least privilege, fail-closed and secure defaults, and test that each pattern holds against the threats identified in the threat model.

~28 hrs
Total instructional hours
22
Individual modules
1-3 days
Flexible delivery
Tools and labs you will use

The tooling you work with, not slideware

Hands-on with the CyberSecAI tooling, not slideware.

ThreatForge

Generates an AI threat-model diagram and an AISVS control checklist from a system description.

AI-DAST

Validates the design once it is built and running.

Claw

Checks the implemented architecture against the OWASP standards.

AgentPass Ledger

Records the design-review decisions and control acceptance.

Who it is for

Built for the people designing AI systems

Security architects

Design AI systems you can secure and defend by design.

Senior engineers & tech leads

Set the controls before the first line of code ships.

AppSec

Bring threat modeling discipline to LLMs, agents and RAG.

Platform & AI teams

Design new systems on AISVS-aligned reference patterns.

The certification

Part of the AISVS assurance track

This course counts toward the CyberSecAI AISVS assurance track. You leave with a threat model, a set of reference patterns, and a concrete control set your engineers can build against, all mapped to AISVS control families.

Reserve a place

Design AI systems that are secure before a line ships.

Two days, hands-on, taught by the former OWASP-AISVS Co-Leader (v1.0). You threat model agents, RAG and pipelines, map the controls that matter, and hand engineering a reference architecture they can build. Places are limited.

2 days intensive, hands-on Intermediate level Private corporate cohorts available
Reserve a Place

Corporate & sovereign cohorts, and bespoke on-site delivery, on request.