About this Event
Applied Hacking for AI Systems is a practical, one-day AI security training in Austin, TX, on finding and fixing the security flaws in AI and LLM applications, taught by the team that tests AI agents for a living.
Wednesday, October 21, 2026, 10:00 AM to 4:00 PM CDT.
In person in Austin, TX. Intermediate level. Certificate of completion and hands-on labs included. Seats are limited to 25 to keep it hands-on.
Who it is for
- Developers shipping LLM or agent features who want to find the flaws themselves before they reach production.
- AppSec and security engineers who test applications for a living and need AI and LLM attacks in their toolkit.
- Technical leads who own AI risk and want to see the attacks first-hand so they can guide their team.
The day, module by module
You attack a real, deliberately vulnerable AI application through the day, then learn to defend it. Each module pairs a short briefing with a hands-on lab.
- The AI attack surface. How LLM and AI features get built and shipped, where that pipeline breaks, and the two maps you use all day: the OWASP Top 10 for LLM applications and MITRE ATLAS.
- Threat-modeling an AI system. Where the trust boundaries sit in a real LLM or multimodal deployment, which inputs the model actually trusts, and where one crossed boundary becomes a breach.
- Prompt injection, hands-on. Direct and indirect injection, and how hidden text in inputs, documents, and tool output takes over a model's behavior. You run the attacks against public and custom endpoints.
- Jailbreaking production models. The bypass patterns that keep working, why they work, and where a jailbreak actually matters once it is wired into an application.
- RAG and data leakage. Poisoning what a retrieval system feeds the model, and pulling out the data the app was never meant to reveal.
- Agents, tools, and MCP. Excessive agency, tool and connector abuse, and the moment an agent starts doing the attacker's work with its own access. Lab against an agent wired to real tools and an MCP server.
- AI supply-chain risk. Unsafe model formats that run code the moment they load, malicious packages posing as AI SDKs, and the open-source models and datasets you inherit without reading.
- Red-team it, then harden it. A repeatable way to red-team your own AI features, scored against the OWASP LLM Top 10 and MITRE ATLAS, then the defenses that hold. Capstone lab: attack the full application, then harden it.
What you walk away with
- An eye for AI and LLM vulnerabilities in a codebase or a running app, not just their names.
- A repeatable method to red-team the AI features your team ships.
- A full day of real attacks in a safe lab, against an app built to break the way production apps do.
- A certificate of completion.
Your trainer
Sandeep Kamble, Founder and CTO of SecureLayer7, with fourteen years in offensive security. Under his leadership the team has delivered hundreds of LLM and AI application pentests. His own findings include a remote code execution in n8n, a SQL injection in Spring AI, and fuzzing work against the V8 JavaScript engine. The training comes straight from that work.
Full syllabus and details: securelayer7.net/training/ai-security-course-austin
Event venue & nearby stays
ACC HighLand, 5910 Wilhelmina Delco Drive, Austin, United States